Lab · scanner-test
WackoPicko
Vulnerable app from the paper 'Why Johnny Can't Pentest', with known XSS, SQLi, traversal, file inclusion and command injection for scanner evaluation.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsscanner-test
More labs & practice targets
- Damn Vulnerable Application Scanner (DVAS)scanner-testIntentionally vulnerable web application scanner target.
- OWASP VulnerableApp-facadescanner-testGateway that routes to a distributed farm of vulnerable apps (tech-stack agnostic), integrating VulnerableApp, -jsp and -php.
- WAVSEPscanner-testWeb Application Vulnerability Scanner Evaluation Project — vulnerable app for assessing scanner accuracy and coverage.
- AI-GoatllmVulnerable-LLM CTF challenges aligned to the OWASP Top 10 for LLM Applications, running a local Vicuna model (no cloud fees).
- Altoro Mutual (AltoroJ)web-appClassic sample banking J2EE web app demonstrating real-world application security issues; also self-hostable.
- AuthLab (digininja)authSelection of authentication and authorization challenges drawn from real-world examples, written in Go.