sudoninja book
  • sudoninja book
  • About us
  • Security Area
    • Penetration Testing Methodologies
      • 7 Layer
    • How to Find CVE
      • TOP All bugbounty pentesting CVE
      • What is CVE
      • Where I try to find vulnerability and exploit
      • How to find vulnerability (approach).
      • How to Request CVE
      • My CVE
      • My submission on exploit DB
      • Write up and CVE
      • Published CVE on website
    • DAST/SAST
    • Penetration-Testing
      • Offensive-Resources
      • pentest tool
      • Mind map
    • Web Application Penetration Testing
      • Web Pentesting Methodology
      • Video
      • Cheat sheet
      • Book
      • Lab
      • Mind Map
      • Check list
      • Blog
      • Payload
      • Report
      • Tool
    • Network Penetration Testing
      • Checklist
    • Mobile Penetration testing
      • Mobile PT methology
      • APK Penetration Testing
      • Android PT
        • Methology
        • Github
        • video
        • Report
        • Tool
        • Mind Map
        • Payload
        • Cheat sheet
        • Check list
        • Lab
        • Book
        • Blog
      • iOS PT
        • Methology
        • Check list
        • Github
        • Lab
        • Book
        • Payload
        • Report
        • Mind Map
        • Blog
        • Tool
        • Video
      • Cheatsheet
      • Mind Map
    • Active Directory penetration testing
      • Methodology
      • Note
      • Checklist
      • Mind map
      • Cheatsheet
      • Tool
      • Note
      • Lab
      • Payload
    • API Penetration Testing
      • Methodology
      • Video
      • Book
      • Mind map
      • Lab
      • Checklist
      • Blog
      • Payload
      • Report
      • Tool
    • Source Code Review
      • Mindmap
      • Link
      • Blog
    • CTF
      • Practice
        • Youtube
        • CTF
    • IOT Penetration Testing
      • Methodology
      • Cheat sheet
      • Book
      • Mind Map
      • Check list
      • Blog
      • Video
      • Report
      • Tool
    • Red Teaming
      • Mind map
      • OSINT
      • Configure your own vulnerable CTF machine
    • Cloud Security
      • Google Cloud Platform
      • Azure
      • Report
      • AWS
      • Lab
    • Bug Bounty Hunting
      • Learning Engine for Bug Hunter
      • bug bounty tips
        • Book
        • Guide
      • Cheat sheet
      • Bugbounty writeup - medium / others
      • Hackerone Report
      • Recon map
      • Writeups
      • Bug bounty Platform
      • Tool
    • Thick Client Pentesting
    • Malware Analysis
    • DevSecOps
    • Wireless Penetration Testing
      • Note
      • Cheatsheet
  • Practice and improve skills
  • list of Vulnerabilities-1
    • 2FA/OTP Bypass
    • Account Takeover
    • Apache Log Poisoning through LFI
    • Broken Links
    • Bruteforcing
    • Business Logic Flaws
    • Broken Authentication & Session Management
    • Cross Site Scripting
    • Crawl/Fuzz
    • Content Security Policy (CSP)
    • CORS
    • CSRF
    • Clickjacking
    • CRLF
    • Command Injection
    • Client Side Template Injection (CSTI)
    • cookie
    • Cookies Hacking
    • Captcha Bypass
    • Dangling Markup - HTML scriptless injection
    • Deserialization
    • Directory Browsing
    • DNS Rebinding
    • Email Header Injection
    • Email attacks
    • File Inclusion/Path traversal
    • File Upload
    • Github Recon
    • Header injections
    • HTTP Request Smuggling
    • HTTP Parameter pollution
    • HTML Injection
    • HTTP Authentication
    • HTTP Protocol
    • IDOR
    • JWT Vulnerabilities (Json Web Tokens)
    • LDAP Injection
    • NoSQL injection
    • Open Redirect
    • Online hashes cracked
    • Race Condition
    • Ruby on Rails
    • Rate Limit Bypass
    • Pastejacking
    • Path Traversal
    • Password Reset
    • Prototype Pollution
    • SQL Injection
    • SSRF (Server Side Request Forgery)
    • SSTI (Server Side Template Injection)
    • Session fixation
    • Subdomain Takeover
    • S3 Bucket
    • Unicode Normalization vulnerability
    • XPATH injection
    • XSLT Server Side Injection
    • XXE - XML External Entity
    • XS-Search
    • Web Cache Deception
    • Web Sockets
    • Webshells
  • list of Vulnerabilities-2
    • Web Application Vulnerability 2022
  • Tool
    • sqlmap
      • Sql login bypass
    • Extra
    • Github
    • Search Engine for Hackers
    • Burp Extensions
    • Dorks
    • Python
    • one line script
      • more
  • Note
  • AWAE/OSWE
    • Cherry Tree
  • Burp Suite Certified Practitioner
    • Sql Injection
  • Pentesting Bible
  • Free Certification
  • Hack The Box
  • Bookmark
  • Report
  • Lab
    • MY Machine
  • Framework
    • OWASP guide
      • Map
      • OWASP Cheatsheet
  • CheatSheet
  • Mind Map
  • Certifications
  • Research Tool
  • Learn for Fun
    • Email spoofing
  • POST
    • Here are 24 websites to learn Linux for free:
    • 39 cybersecurity news resources
    • 30 cybersecurity search engines
    • 27 ways to learn ethical hacking for free
Powered by GitBook
On this page
  • Online Hacking Demonstration Sites
  • Practice

Was this helpful?

  1. Security Area
  2. Web Application Penetration Testing

Lab

PreviousBookNextMind Map

Last updated 3 years ago

Was this helpful?

  1. - OWASP TOP 10

  2. CMS

  3. -XSS

  4. -XSS

  5. - GraphQL

Online Hacking Demonstration Sites

Practice

Best websites to test your hacking skills

https://pwnable.kr/
https://hack.me/
https://ctflearn.com/
https://google-gruyere.appspot.com/ 
https://www.root-me.org/en/
https://www.hackthebox.eu/
https://www.hacking-lab.com/
http://www.gameofhacks.com/
https://overthewire.org/
https://microcorruption.com/
https://xss-game.appspot.com/?utm_source...dium=email
https://www.hackthissite.org/pages/index/index.php
https://crackmes.one/
https://pentest.training/
https://www.hellboundhackers.org/
http://hax.tor.hu/
https://thisislegal.com/
https://tryhackme.com/

- Acunetix ASP test and demonstration site

- Acunetix ASP.Net test and demonstration site

- Acunetix PHP test and demonstration site

- Crack Me Bank

- Zero Bank

- Altoro Mutual

- PentestIT labs (2 free labs per year)

- Free Basic Excersices (also Premium)

- Hack The Box is an online platform allowing you to test and advance your skills in cyber security (You need to hack a test resource to get an invitation :))

- Virtual Machines for Localhost Penetration Testing

- This web application is a learning platform about common web security flaws

- Damn Vulnerable Web Application (DVWA)

- Similar to DVWA, but with some added attacks

- LAMPSecurity Training

- SQLI labs to test error based, Blind boolean based, Time based.

- small set of PHP scripts to practice exploiting LFI, RFI and CMD injection vulns

- Build, host and share vulnerable web apps in a sandboxed environment for free

- Free live fire Capture the Flag, blue team, red team Cyber Warfare Range for beginners through advanced users. Must use a cell phone to send a text message requesting access to the range.

- WackoPicko is a vulnerable web application used to test web application vulnerability scanners.

- Hackazon is a free, vulnerable test site that is an online storefront built with the same technologies used in today’s rich client and mobile applications.

- Hack This Site is a free training ground for users to test and expand their hacking skills.

https://www.vulnhub.com/
https://pentesterlab.com/exercises/web_for_pentester/course
https://portswigger.net/users?returnurl=%2fusers%2fyouraccount
https://application.security/free/owasp-top-10
https://thexssrat.podia.com/ratatatata
https://github.com/Ignitetechnologies/Web-Application-Cheatsheet?s=08#nano
https://brutelogic.com.br/blog/xss101/
https://pentesterlab.com/exercises
https://hacklido.com/d/8-web-app-pentesting/4
https://xss.pwnfunction.com/
https://www.deepfryd.com/burp-academy-apprentice/
https://domgo.at/cxss/intro
https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
http://testasp.vulnweb.com/
http://testaspnet.vulnweb.com/
http://testphp.vulnweb.com/
http://crackme.cenzic.com/kelev/view/home.php
http://zero.webappsecurity.com/
http://demo.testfire.net/
https://github.com/Kajmer/Pentest-Resources
https://lab.pentestit.ru/
https://pentesterlab.com/exercises/
https://www.hackthebox.eu/
https://www.vulnhub.com/
https://github.com/jerryhoff/WebGoat.NET
http://www.dvwa.co.uk/
https://github.com/s4n7h0/xvwa
http://sourceforge.net/projects/lampsecurity/
https://github.com/Audi-1/sqli-labs
https://github.com/paralax/lfi-labs
https://hack.me/
http://azcwr.org/az-cyber-warfare-ranges
https://github.com/adamdoupe/WackoPicko
https://github.com/rapid7/hackazon
https://www.hackthissite.org/