Bug Bounty Practice Labs
✅ Bug Bounty Practice Labs & Platforms
🔹 Web & API Labs (Core Bug Classes)
PortSwigger Web Security Academy
✅ Best free, structured web vuln platform
Hack The Box – Bug Bounty Path
🧠 Simulates real bounty-style boxes
TryHackMe – Bug Bounty Labs Collection
🧪 Includes XSS, SSRF, IDOR, logic flaws
OWASP Juice Shop
💥 Full OWASP Top 10, plus bonus hidden bugs
DVWA (Damn Vulnerable Web App)
🐛 Great for beginners
bWAPP (Buggy Web App)
🧱 100+ vulnerabilities across categories
WebGoat (OWASP)
🧠 Lesson-based training in Java stack
NodeGoat
📦 Node.js + MongoDB — common stack in real-world apps
Vulnerable Flask App
🐍 Python-based app with known flaws
OWASP RailsGoat
🔴 Ruby on Rails focused
🔹 API / GraphQL Labs
crAPI (Completely Ridiculous API)
🔌 Designed for OWASP API Top 10
VAmPI (Vulnerable API)
⚙️ Insecure endpoints, broken auth, injections
GraphQL-GOAT
🧬 GraphQL-specific vulnerabilities
APIsec University Labs
🔒 Free guided API hacking labs
Postman API Security Labs
📬 Learn API testing with built-in walkthroughs
🔹 Cloud / Serverless Labs
CloudGoat (AWS)
☁️ Privilege escalation, S3 misconfig, SSRF
flaws.cloud
🎯 Legendary AWS challenge site
GOATStack (Multi-cloud)
🛠️ Vulnerable AWS, Azure, GCP resources
🔹 Mobile Labs
DVIA-v2 (Damn Vulnerable iOS App)
🍎 iOS vulnerabilities in Swift/Obj-C
InsecureBankv2 (Android)
📱 Client-side & API flaws
Mobile Security Testing Guide + Test Apps
🧪 MSTG-aligned APKs for hands-on learning
🔹 Source Code Review & CTF-Style
PentesterLab (Pro & Free)
🔍 Vulnerabilities shown in source, replayable with curl
HackTheBox Machines (Retired)
💻 Many include real web + app logic bugs
XSS Game by Google
🔥 Real browser-based XSS puzzles
Buggy Banking App (OWASP BBA)
💸 Simulates banking app with logic bugs
PortSwigger Web Security Academy
Multi
Realistic web bugs with hints
PentesterLab (Pro)
Multi
Web + API + mobile with source code
HackTheBox “Bug Bounty Path”
Multi
CTF-like bounty challenges
TryHackMe “Bug Bounty” Rooms
Multi
Recon, web, SSRF, IDOR, XSS, etc.
OWASP Juice Shop
Node.js
OWASP Top 10 in one app
Hackademic
PHP/MySQL
Educational web bugs
Web Security Dojo
VM with multiple buggy apps + tools preinstalled
Last updated
Was this helpful?