Labs & practice targets
Lab · scanner-test

WackoPicko

Vulnerable app from the paper 'Why Johnny Can't Pentest', with known XSS, SQLi, traversal, file inclusion and command injection for scanner evaluation.

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

More labs & practice targets