Lab · sqli
SQLI-labs
Progressive PHP labs to learn SQL injection: error-based, blind (boolean/time), update/insert, header and second-order injection, and WAF bypass.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagssqli
More labs & practice targets
- SQL injection test environment (sqlmap testenv)sqliCollection of pages vulnerable to SQL injection across multiple DBMSs, with a deployment script for a full test machine.
- SQLolsqliSQL injection test application, now part of the Magical Code Injection Rainbow (MCIR) framework.
- AI-GoatllmVulnerable-LLM CTF challenges aligned to the OWASP Top 10 for LLM Applications, running a local Vicuna model (no cloud fees).
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- AuthLab (digininja)authSelection of authentication and authorization challenges drawn from real-world examples, written in Go.
- BodgeIt Storeweb-appSelf-contained Java/JSP vulnerable app aimed at pentest beginners, covering XSS, SQLi and hidden content.