This is the VM for the Open Web Application Security Project (OWASP) Broken Web Applications project. It contains many, very vulnerable web applications, which are listed below. More information about this project can be found in the project User Guide and Home Page.

For details about the known vulnerabilities in these applications, see https://sourceforge.net/p/owaspbwa/tickets/?limit=999&sort=_severity+asc.

!!! This VM has many serious security issues. We strongly recommend that you run it only on the "host only" or "NAT" network in the virtual machine settings !!!

بیس

OWASP WebGoat OWASP WebGoat.NET
OWASP ESAPI Java SwingSet Interactive OWASP Mutillidae II
OWASP RailsGoat OWASP Bricks
OWASP Security Shepherd Ghost
Magical Code Injection Rainbow bWAPP
Damn Vulnerable Web Application

ETHEREUM FOUNDATION UNDER INVESTIGATION

OWASP Vicnum OWASP 1-Liner
Google Gruyere Hackxor
WackoPicko BodgeIt
Cyclone Peruggia

TXID

gate.io login OrangeHRM
GetBoo GTD-PHP
Yazd WebCalendar
Gallery2 Tiki Wiki
Joomla AWStats

IS UNISWAP SAFE

OWASP ZAP-WAVE WAVSEP
WIVET

СИБА ИНК

OWASP CSRFGuard Test Application Mandiant Struts Forms
Simple ASP.NET Forms Simple Form with DOM Cross Site Scripting

CRYPTO ESPORTS BETTING

OWASP AppSensor Demo Application

WEISS CRYPTO RATINGS

For information about the known vulnerabilities in these applications (or to submit some), visit https://sourceforge.net/p/owaspbwa/tickets/?limit=999&sort=_severity+asc.

BITCOIN CONTAINER CROSSWORD

For more information about the specific versions of applications running and how to adminsiter this VM, see http://code.google.com/p/owaspbwa/wiki/UserGuide.

HOW MANY BITCOINS ARE THERE IN THE WORLD

If you encounter a problem with this VM (including with any of the installed applications), please submit an issue report on Google Code at http://code.google.com/p/owaspbwa/issues/list.

This project is sponsored by Mandiant, a FireEye Company