Bug Bounty Practice Labs

Bug Bounty Practice Labs & Platforms

🔹 Web & API Labs (Core Bug Classes)

  1. PortSwigger Web Security Academy

  2. Hack The Box – Bug Bounty Path

  3. TryHackMe – Bug Bounty Labs Collection

  4. OWASP Juice Shop

  5. DVWA (Damn Vulnerable Web App)

  6. bWAPP (Buggy Web App)

  7. WebGoat (OWASP)

  8. NodeGoat

  9. Vulnerable Flask App

  10. OWASP RailsGoat


🔹 API / GraphQL Labs

  1. crAPI (Completely Ridiculous API)

  1. VAmPI (Vulnerable API)

  1. GraphQL-GOAT

  1. APIsec University Labs

  1. Postman API Security Labs


🔹 Cloud / Serverless Labs

  1. CloudGoat (AWS)

  1. flaws.cloud

  1. GOATStack (Multi-cloud)


🔹 Mobile Labs

  1. DVIA-v2 (Damn Vulnerable iOS App)

  1. InsecureBankv2 (Android)

  1. Mobile Security Testing Guide + Test Apps


🔹 Source Code Review & CTF-Style

  1. PentesterLab (Pro & Free)

  1. HackTheBox Machines (Retired)

  1. XSS Game by Google

  1. Buggy Banking App (OWASP BBA)


Name
Stack
Focus

PortSwigger Web Security Academy

Multi

Realistic web bugs with hints

PentesterLab (Pro)

Multi

Web + API + mobile with source code

HackTheBox “Bug Bounty Path”

Multi

CTF-like bounty challenges

TryHackMe “Bug Bounty” Rooms

Multi

Recon, web, SSRF, IDOR, XSS, etc.

OWASP Juice Shop

Node.js

OWASP Top 10 in one app

Hackademic

PHP/MySQL

Educational web bugs

Web Security Dojo

VM with multiple buggy apps + tools preinstalled

Last updated

Was this helpful?