How to Practice Your Web Application Testing Skills

Source: Internet
Author: User

Translation: how to practice your web application testing skills

For those who are learning web application security testing (or just trying to stay sharp) it's often difficult to find quality websites to test one's skills. there are a few scattered around the Internet (see the link in the notes section below) but it wocould be nice to have a solid collection of test sites all in one place.

 

Aside from finding them all, another problem with most of these sites is that you can download them for free but they often require some fairly significant configuration. there shoshould be a counter somewhere that shows how much time has been wasted trying to get Webgoat to run, for example.

 

There is a project that solves both of these problems simultaneously: The OWASP Broken Web Applications Project. It collects a ton of broken web apps into a single project and accomplishes a few major ings th:

 

  1. Aggregation:There are over a dozen broken apps -- some on purpose and some old versions of real software. www.2cto.com
  2. Preconfiguration: They all work the way they're supposed to -- every time.
  3. Virtualization: They run from a virtual machine so you simply run the VM and go.
The project hosts des the following apps (screenshot from the homescreen ):

 

That is a ton of apps, and as I said, they actually work. you click the link as you see it abve in the screenshot and you 've landed on the start URL for your target. fire up your browser, your proxy tool of choice, your favorite web scanners, etc. and you're on your way. it's projects like these that make me happy to contribute to OWASP every year.

 

Enjoy!

 

Notes

1 Be sure to run this VM in a secure environment to avoid introduction of vulnerability to a sensitive network. Running the VM in a NAT configuration is one option.

2I 've also compiled a list on my own site that has des a collection of the web-facing vulnerable web apps provided by vendors, as well as a number of webappsec tools and suites

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.