hatchmoment. scored by care · not by stars

WebGoat

WebGoat – a deliberately insecure web app for hands‑on security training

WebGoat provides a fully functional, intentionally flawed web application that lets security learners practice exploitation techniques in a safe environment. It runs as a Docker container or standalone Java jar, exposing common vulnerabilities like SQL injection, XSS, and broken authentication. The project is aimed at students, trainers, and professionals who want practical, hands‑on experience with web security. Because it’s maintained by OWASP and includes comprehensive lesson guides, it offers a more structured and up‑to‑date learning platform than ad‑hoc vulnerable demos.

View on GitHub →

ctf-in-a-box-test/WebGoat