Lab · serverlesshosted
Damn Vulnerable Functions as a Service (DVFaaS)
Intentionally insecure AWS Lambda functions mapped to the OWASP Serverless Top 10 for learning FaaS security.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
A shared, hosted instance — for practice only, within the platform's own rules.
Tagsserverless
More labs & practice targets
- Damn Vulnerable Serverless App (DVSA)serverlessDeliberately vulnerable serverless (Node on AWS/Azure) application for learning serverless security.
- AI-GoatllmVulnerable-LLM CTF challenges aligned to the OWASP Top 10 for LLM Applications, running a local Vicuna model (no cloud fees).
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- AuthLab (digininja)authSelection of authentication and authorization challenges drawn from real-world examples, written in Go.
- BodgeIt Storeweb-appSelf-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Broken CrystalsspaModern React/Node application with REST and GraphQL for modern SPA testing.