Lab · web-app
OWASP Security Shepherd
Web and mobile app security training platform with lessons and challenges based on the OWASP Top Ten.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsweb-app
More labs & practice targets
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- BodgeIt Storeweb-appSelf-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.
- Butterfly Security Projectweb-appEducational PHP/MySQL environment teaching common web/PHP vulnerabilities alongside their mitigations.
- bWAPPweb-appFree open-source 'buggy web app' with 100+ vulnerabilities for practicing web security and preparing for pentests.
- CVWA (Conviso Vulnerable Web Application)web-appPurposely insecure PHP blog simulating a novice's code, used to teach manual and automated vulnerability detection and remediation.
- Cyclone Transfersweb-appRuby on Rails application from the Broken Web Applications (BWA) project for local security testing.