Web Application Pentesting Lab with over 40 plus vulnerability, which covers all the owasp top 10 issues.
-
Updated
Apr 5, 2026 - JavaScript
Web Application Pentesting Lab with over 40 plus vulnerability, which covers all the owasp top 10 issues.
Compromise a web application and delve deeper into the network to access hosts that you cannot directly reach from your attack host using different approaches.
Deploy GOAD labs to ESXi
🍪 Cookie Security Lab - A comprehensive CTF challenge demonstrating 6 cookie vulnerabilities with hands-on exploitation exercises, hashed flags, and secure patterns for learning.
DVWAS-Lite is an intentionally vulnerable web application built for learning web security, penetration testing, and vulnerability exploitation. Includes SQLi, XSS, CSRF, weak JWT, and file upload vulnerabilities.
Reproducer labs for vulnerabilities and artifacts analyzed by Binautopsy Labs. Each lab is paired with the published analysis at binautopsy.com/research/.
Learn SOC With Me Lab 05: OAuth consent phishing, token abuse, and cloud data exfiltration SOC investigation lab.
Public sanitized defensive AI lab for threat modeling, Codex-assisted remediation, patch validation, and initial Codex Security evidence with human approval.
Hands-on web attack lab: phishing → stored XSS → session theft → SQL injection → exfiltration, with an attacker server and a hardened twin. Node.js/Express, education/CTF only.
Vulnerable-by-design MCP server for learning object-level / cross-tenant authorization (BOLA/IDOR) bugs + a hunt checklist.
Hands-on cybersecurity lab — containerized vulnerable targets and guided challenges for web, network, and detection practice (authorized use only).
Add a description, image, and links to the security-lab topic page so that developers can more easily learn about it.
To associate your repository with the security-lab topic, visit your repo's landing page and select "manage topics."