Lab · web-app
Cyclone Transfers
Ruby on Rails application from the Broken Web Applications (BWA) project for local security testing.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsweb-app
More labs & practice targets
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- BodgeIt Storeweb-appSelf-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Butterfly Security Projectweb-appEducational PHP/MySQL environment teaching common web/PHP vulnerabilities alongside their mitigations.
- bWAPPweb-appFree open-source 'buggy web app' with 100+ vulnerabilities for practicing web security and preparing for pentests.
- CVWA (Conviso Vulnerable Web Application)web-appPurposely insecure PHP blog simulating a novice's code, used to teach manual and automated vulnerability detection and remediation.
- Damn Small Vulnerable Web (DSVW)web-appSingle-file Python vulnerable web app (<100 lines) supporting most popular web vulnerability classes for education.