+ Reply to Thread
Page 1 of 3 123 LastLast
Results 1 to 10 of 22
Like Tree4Likes

Thread: Vulnerable Web Applications To learn Web Application Testing Skills Share/Save - My123World.Com!

  1. #1
    Administrator Punter has disabled reputation Punter's Avatar
    Join Date
    Jul 2010
    Location
    Above Sea level
    Posts
    163
    Blog Entries
    1
    Thanks
    8
    Thanked 71 Times in 31 Posts

    Red face Vulnerable Web Applications To learn Web Application Testing Skills



    I have Often seen Beginners who will pursue their carrier in Application Security always have less Hands on experience in testing Web Applications below are the links Would help them to learn and Improve their skills in Application Security Testing.

    Vulnerable Webapplications

    1) Jarlsberg App
    http://jarlsberg.appspot.com/start
    2) OWASP Broken Web Applications project
    http://code.google.com/p/owaspbwa/wiki/ProjectSummary
    Intentionally Vulnerable Applications:
    •OWASP WebGoat version 5.3-SNAPSHOT (Java)
    •OWASP Vicnum version 1.4 (PHP/Perl)
    •Mutillidae version 1.3 (PHP)
    •Damn Vulnerable Web Application version 1.06 (PHP)
    •Ghost (PHP)
    •Peruggia version 1.2 (PHP)
    •OWASP CSRFGuard Test Application version 2.2 (Java)
    •OWASP AppSensor Demo Application (Java)
    •Mandiant Struts Forms (Java/Struts)
    •Simple ASP.NET Forms (ASP.NET/C#)
    •Simple Form with DOM Cross Site Scripting (HTML/JavaScript)
    Old Versions of Real Applications:
    •WordPress 2.0.0 (PHP, released December 31, 2005, downloaded from www.oldapps.com)
    •phpBB 2.0.0 (PHP, released April 4, 2002, downloaded from www.oldapps.com)
    •Yazd version 1.0 (Java, released February 20, 2002)
    3)Web Security Dojo
    http://www.mavensecurity.com/web_security_dojo/
    Targets include:
    •OWASP’s WebGoat
    •Damn Vulnerable Web App
    •Hacme Casino
    •OWASP InsecureWebApp
    •simple training targets by Maven Security (including REST and JSON)
    Tools:
    •Burp Suite (free version)
    •w3af
    •OWASP Skavenger
    •OWASP Dirbuster
    •Paros
    •Webscarab
    •Ratproxy
    •sqlmap
    •helpful Firefox add-ons
    4)SPI Dynamics (live) – http://zero.webappsecurity.com/
    5)Cenzic (live) – http://crackme.cenzic.com/
    6)Watchfire (live) – http://demo.testfire.net/
    7)Acunetix (live) – http://testphp.acunetix.com/ http://testasp.acunetix.com http://testaspnet.acunetix.com
    8)PCTechtips Challenge (live) – http://pctechtips.org/hacker-challenge-pwn3d-the-login-form/
    9)The Butterfly Security Project – http://sourceforge.net/projects/thebutterflytmp/files/ButterFly%20Project
    10)Hacme Casino – http://www.foundstone.com/us/resources/proddesc/hacmecasino.htm
    11)Hacme Bank 2.0 – http://www.foundstone.com/us/resources/proddesc/hacmebank.htm
    12)Updated HackmeBank – http://www.o2-ounceopen.com/technical-info/2008/12/8/updated-version-of-hacmebank.html
    14)Hacme Books – http://www.foundstone.com/us/resources/proddesc/hacmebooks.htm
    15)Hacme Travel – http://www.foundstone.com/us/resources/proddesc/hacmetravel.htm
    16)Hacme Shipping – http://www.foundstone.com/us/resources/proddesc/hacmeshipping.htm
    17)OWASP SiteGenerator – http://www.owasp.org/index.php/Owasp_SiteGenerator
    18)Moth – http://www.bonsai-sec.com/en/research/moth.php
    19)Stanford SecuriBench – http://suif.stanford.edu/~livshits/securibench/
    20)SecuriBench Micro – http://suif.stanford.edu/~livshits/work/securibench-micro/
    21)BadStore – http://www.badstore.net/
    22)WebMaven/Buggy Bank – http://www.mavensecurity.com/webmaven

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


    Hire a Hacker by the Night and Hire a Chief Security Officer (CSO) by the Day.

  2. The Following 6 Users Say Thank You to Punter For This Useful Post:

    b0nd (10-05-2011), Deepak Rathore (10-06-2011), fb1h2s (02-11-2011), ht2ht (08-18-2011), k427h1k (01-27-2012), [s] (02-11-2011)

  3. #2
    InfoSec Consultant that's_all is on a distinguished road
    Join Date
    Aug 2010
    Posts
    56
    Thanks
    1
    Thanked 7 Times in 3 Posts
    and a list of trainings - http://yehg.net/lab/#training

  4. The Following 2 Users Say Thank You to that's_all For This Useful Post:

    fb1h2s (02-11-2011), ht2ht (08-18-2011)

  5. #3
    Super Commando Dhruv abhaythehero has a spectacular aura aboutabhaythehero has a spectacular aura aboutabhaythehero has a spectacular aura about abhaythehero's Avatar
    Join Date
    Sep 2010
    Location
    Lucknow/Pune,India
    Posts
    469
    Blog Entries
    2
    Thanks
    169
    Thanked 144 Times in 83 Posts
    wow .. seen this thread first time .. was looking for such apps after 41.warrior told me
    to refrain from practicing SQL injection on live targets

    anyways just here is another one to practice XSS,XSRF etc. Have not tried it yet though[exams ahead ]

    This codelab shows how web application vulnerabilities can be exploited and how to defend against these attacks. The best way to learn things is by doing, so you'll get a chance to do some real penetration testing, actually exploiting a real application. Specifically, you'll learn the following:

    * How an application can be attacked using common web security vulnerabilities, like cross-site scripting vulnerabilities (XSS) and cross-site request forgery (XSRF).
    * How to find, fix, and avoid these common vulnerabilities and other bugs that have a security impact, such as denial-of-service, information disclosure, or remote code execution.

    To get the most out of this lab, you should have some familiarity with how a web application works (e.g., general knowledge of HTML, templates, cookies, AJAX, etc.).
    http://google-gruyere.appspot.com/
    In the world of 0s and 1s, are you a zero or The One !

  6. The Following 2 Users Say Thank You to abhaythehero For This Useful Post:

    fb1h2s (02-11-2011), ht2ht (08-18-2011)

  7. #4
    Garage Newcomer Hocker is on a distinguished road
    Join Date
    Dec 2010
    Posts
    2
    Thanks
    0
    Thanked 0 Times in 0 Posts
    hi thank for your sharing information...nice help about to Web Applications To learn Web Application Testing Skills
    Last edited by abhaythehero; 09-13-2012 at 12:52 PM.

  8. #5
    Garage Newcomer ht2ht is on a distinguished road
    Join Date
    Aug 2011
    Posts
    1
    Thanks
    3
    Thanked 0 Times in 0 Posts
    Very useful.
    My big thanks to all here.

  9. #6
    Web Security Consultant amolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really nice amolnaik4's Avatar
    Join Date
    Jul 2011
    Location
    webr00t
    Posts
    269
    Blog Entries
    3
    Thanks
    24
    Thanked 179 Times in 100 Posts
    2 more apps:

    1. WackoPicko - used to test multiple web application scanners
    2. The BodgeIt Store

  10. #7
    Garage Newcomer Snypter is on a distinguished road
    Join Date
    May 2011
    Location
    Localhost@mumbai
    Posts
    32
    Thanks
    1
    Thanked 9 Times in 4 Posts
    thanx for this share .. i am starting with WEBGOAT !

  11. #8
    Garage Newcomer Anthrax is on a distinguished road
    Join Date
    Oct 2011
    Posts
    2
    Thanks
    0
    Thanked 0 Times in 0 Posts
    woah this one is really good! i'll read and try this one after i get 10 post lol

  12. #9
    Garage Hyper Addict b0nd is a jewel in the roughb0nd is a jewel in the roughb0nd is a jewel in the rough b0nd's Avatar
    Join Date
    Jul 2010
    Location
    irc.freenode.net #g4h
    Posts
    644
    Thanks
    140
    Thanked 270 Times in 109 Posts
    Quote Originally Posted by Anthrax View Post
    woah this one is really good! i'll read and try this one after i get 10 post lol
    Hi Anthrax,
    Is there any boundation you are facing with '10' posts count? I don't remember if we have intentionally put any such restriction.

    Cheers!
    [*] To follow the path: look to the master, follow the master, walk with the master, see through the master,
    ------> become the master!!! <------
    [*] Everyone has a will to WIN but very few have the will to prepare to WIN
    [*] Invest yourself in everything you do, there's fun in being serious

  13. #10
    Web Security Consultant amolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really nice amolnaik4's Avatar
    Join Date
    Jul 2011
    Location
    webr00t
    Posts
    269
    Blog Entries
    3
    Thanks
    24
    Thanked 179 Times in 100 Posts
    Holynix Level1 & Level2:

    Similar to the de-ice pentest CDs and pWnOS, Holynix is an Linux vmware image that was deliberately built to have security holes for the purposes of penetration testing.

    Link:Holynix - Browse Files at SourceForge.net

    Just completed Level1...now on level2.

    PS: Level1 is complete web based, level2 is having multiple services.

    Cheers,
    AMol NAik
    Last edited by amolnaik4; 11-03-2011 at 12:25 PM.


Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts