Vulnerable Platforms Environment for Improving your Penetration Testing Skills

ulnerable Web Applications [64 unique web applications]
OWASP BWAhttp://code.google.com/p/owaspbwa/
OWASP Hackademichttp://hackademic1.teilar.gr/
OWASP SiteGeneratorhttps://www.owasp.org/index.php/Owasp_SiteGenerator
OWASP Brickshttp://sourceforge.net/projects/owaspbricks/
OWASP Security Shepherdhttps://www.owasp.org/index.php/OWASP_Security_Shepherd
WebGoat.NEThttps://github.com/jerryhoff/WebGoat.NET/
PentesterLabhttps://pentesterlab.com/
Butterfly Security Projecthttp://thebutterflytmp.sourceforge.net/
Foundstone Hackme Bankhttp://www.mcafee.com/us/downloads/free-tools/hacme-bank.aspx
Foundstone Hackme Bookshttp://www.mcafee.com/us/downloads/free-tools/hacmebooks.aspx
Foundstone Hackme Casinohttp://www.mcafee.com/us/downloads/free-tools/hacme-casino.aspx
Foundstone Hackme Shippinghttp://www.mcafee.com/us/downloads/free-tools/hacmeshipping.aspx
Foundstone Hackme Travelhttp://www.mcafee.com/us/downloads/free-tools/hacmetravel.aspx
LAMPSecurityhttp://sourceforge.net/projects/lampsecurity/
Mothhttp://www.bonsai-sec.com/en/research/moth.php
WackoPickohttps://github.com/adamdoupe/WackoPicko
BadStorehttp://www.badstore.net/
WebSecurity Dojohttp://www.mavensecurity.com/web_security_dojo/
BodgeIt Storehttp://code.google.com/p/bodgeit/
hackxorhttp://hackxor.sourceforge.net/cgi-bin/index.pl
SecuriBenchhttp://suif.stanford.edu/~livshits/securibench/
SQLolhttps://github.com/SpiderLabs/SQLol
CryptOMGhttps://github.com/SpiderLabs/CryptOMG
XMLmaohttps://github.com/SpiderLabs/XMLmao
Exploit KB Vulnerable Web Apphttp://exploit.co.il/projects/vuln-web-app/
PHDays iBank CTFhttp://blog.phdays.com/2012/05/once-again-about-remote-banking.html
GameOverhttp://sourceforge.net/projects/null-gameover/
Zap WAVEhttp://code.google.com/p/zaproxy/downloads/detail?name=zap-wave-0.1.zip
PuzzleMallhttp://code.google.com/p/puzzlemall/
VulnApphttp://www.nth-dimension.org.uk/blog.php?id=88
sqli-labshttps://github.com/Audi-1/sqli-labs
Drunk Admin Web Hacking Challengehttps://bechtsoudis.com/work-stuff/challenges/drunk-admin-web-hacking-challenge/
bWAPPhttp://www.mmeit.be/bwapp/
Vulnerable Operating System Installations [36+ unique OS setups]
Damn Vulnerable Linuxhttp://sourceforge.net/projects/virtualhacking/files/os/dvl/
Metasploitablehttp://sourceforge.net/projects/virtualhacking/files/os/metasploitable/
LAMPSecurityhttp://sourceforge.net/projects/lampsecurity/
UltimateLAMPhttp://www.amanhardikar.com/mindmaps/practice-links.html
De-ICE, hackerdemiahttp://hackingdojo.com/downloads/iso/De-ICE_S1.100.iso
http://hackingdojo.com/downloads/iso/De-ICE_S1.110.iso
http://hackingdojo.com/downloads/iso/De-ICE_S1.120.iso
http://hackingdojo.com/downloads/iso/De-ICE_S2.100.iso
hackerdemia - http://hackingdojo.com/downloads/iso/De-ICE_S1.123.iso
pWnOShttp://www.pwnos.com/
Holynixhttp://sourceforge.net/projects/holynix/files/
Kioptrixhttp://www.kioptrix.com/blog/
exploit-exercises - nebula, protostar, fusionhttp://exploit-exercises.com/download
PenTest Laboratoryhttp://pentestlab.org/lab-in-a-box/
RebootUser Vulnixhttp://www.rebootuser.com/?page_id=1041
neutronstarhttp://neutronstar.org/goatselinux.html
scriptjunkie.ushttp://www.scriptjunkie.us/2012/04/the-hacker-games/
21LTRhttp://21ltr.com/scenes/
SecGame # 1: Sauronhttp://sg6-labs.blogspot.co.uk/2007/12/secgame-1-sauron.html
TurnKey Linuxhttp://www.turnkeylinux.org/
CentOShttp://www.centos.org/
Sites for Downloading Older Versions of Various Software [3 sources]
Old Appshttp://www.oldapps.com/
Old Versionhttp://www.oldversion.com/
Exploit-DBhttp://www.exploit-db.com/
Sites by Vendors of Security Testing Software [9 unique sites]
Acunetix acuforumhttp://testasp.vulnweb.com/
Acunetix acubloghttp://testaspnet.vulnweb.com/
Acunetix acuarthttp://testphp.vulnweb.com/
Cenzic crackmebankhttp://crackme.cenzic.com
HP freebankhttp://zero.webappsecurity.com
IBM altoromutualhttp://demo.testfire.net/
Mavituna testsparkerhttp://aspnet.testsparker.com
Mavituna testsparkerhttp://php.testsparker.com
NTOSpider Test Sitehttp://www.webscantest.com/
Sites for Improving Your Hacking Skills [25 unique sites]
EnigmaGrouphttp://www.enigmagroup.org/
Exploit Exerciseshttp://exploit-exercises.com/
Google Gruyerehttp://google-gruyere.appspot.com/
Hack This Sitehttp://www.hackthissite.org/
HackThishttp://www.hackthis.co.uk/
HackQuesthttp://www.hackquest.com/
Hack.mehttps://hack.me
Hacking-Labhttps://www.hacking-lab.com
Hacker Challengehttp://www.dareyourmind.net/
Hacker Testhttp://www.hackertest.net/
hACME Gamehttp://www.hacmegame.org/
Hax.Torhttp://hax.tor.hu/
OverTheWirehttp://www.overthewire.org/wargames/
PentestIThttp://www.pentestit.ru/en/
pwn0https://pwn0.com/home.php
RootContesthttp://rootcontest.com/
Root Mehttp://www.root-me.org/?lang=en
Security Treasure Hunthttp://www.securitytreasurehunt.com/
Smash The Stackhttp://www.smashthestack.org/
TheBlackSheep and Erikhttp://www.bright-shadows.net/
ThisIsLegalhttp://thisislegal.com/
Try2Hackhttp://www.try2hack.nl/
WabLabhttp://www.wablab.com/hackme
XSS: Can You XSS This?http://canyouxssthis.com/HTMLSanitizer/
XSS: ProgPHPhttp://xss.progphp.com/
CTF Sites / Archives [3 sites/repos]
CTFtime (Details of CTF Challenges)http://ctftime.org/ctfs/
shell-storm Repohttp://shell-storm.org/repo/CTF/
CAPTF Repohttp://captf.com/
Miscellaneous [10 items]
ExploitMe Mobile Android Labshttp://securitycompass.github.io/AndroidLabs/
ExploitMe Mobile iPhone Labshttp://securitycompass.github.io/iPhoneLabs/
NcN Wargamehttp://noconname.org/evento/wargame/
NETinVMhttp://informatica.uv.es/~carlos/docencia/netinvm/
OWASP iGoathttp://code.google.com/p/owasp-igoat/
OWASP Goatdroidhttps://github.com/jackMannino/OWASP-GoatDroid-Project
Hacme Bank Androidhttp://www.mcafee.com/us/downloads/free-tools/hacme-bank-android.aspx
InsecureBankhttp://www.paladion.net/downloadapp.html
VulnVPNhttp://www.rebootuser.com/?page_id=1041
VulnVoIPhttp://www.rebootuser.com/?page_id=1041


http://www.vulnweb.com/
https://www.vulnhub.com
http://blog.taddong.com/2011/10/hacking-vulnerable-web-applications.html
https://www.novainfosec.com/resources/training/
https://securitythoughts.wordpress.com/2010/03/22/vulnerable-web-applications-for-learning/
http://www.irongeek.com/i.php?page=security/deliberately-insecure-web-applications-for-learning-web-app-security



  • Ruby on rails: http://www.mcafee.com/us/downloads/free-tools/hacme-casino.aspx
    • Tip for tests: 
      • http://www.slideshare.net/labs3/ruby-on-rails-penetration-testing 
      • Join group https://groups.google.com/forum/#!forum/rubyonrails-security
      • https://web.archive.org/web/20140619132611/http://blog.pentesterlab.com/2012/07/how-to-get-first-pentester-job.html
      • https://web.archive.org/web/20140331032857/http://blog.pentesterlab.com/2013_01_01_archive.html  
      • http://blog.securityinnovation.com/blog/2015/05/ruby-on-rails.html 
      • https://www.linkedin.com/pulse/web-security-ruby-rails-framework-ben-hudson
      • https://web.archive.org/web/20140330230944/http://blog.pentesterlab.com/2013/01/on-exploiting-cve-2012-5664.html

    • http://security.stackexchange.com/questions/83001/ruby-on-rails-pentesting-web-applications
    • Rack::Session::Cookie is used by default in Rack based applications (most of Ruby applications use Rack). This provides a different session mechanism. The information is sent back to users, but is signed with a secret. This way, the users cannot tamper with the information in the session (but they can still access it, once they decode it). https://pentesterlab.com/exercises/web_for_pentester/course https://ptl.io/web_for_pentester_i386.iso
    • https://pentesterlab.com/exercises/web_for_pentester_II/course
    •  https://pentesterlab.com/exercises/cve-2012-2661/course
    •  https://web.archive.org/web/20140210231242/http://blog.pentesterlab.com/2012/06/cve-2012-2661-exploitation-write-up.html
    • https://web.archive.org/web/20140331032857/http://blog.pentesterlab.com/2013_01_01_archive.html



Source: http://www.amanhardikar.com/mindmaps/PracticeUrls.html