bWAPP, a buggy web application! bWAPP an extremely buggy web app ! Home Bugs Download Talks & Training Blog Home bWAPP, or a buggy web application, is a free and open source deliberately insecure web application. It helps security enthusiasts, developers and students to discover and to prevent web vulnerabilities. bWAPP prepares one to conduct successful penetration testing and ethical hacking projects. What makes bWAPP so unique? Well, it has over 100 web vulnerabilities! It covers all major known web bugs, including all risks from the OWASP Top 10 project. bWAPP is a PHP application that uses a MySQL database. It can be hosted on Linux/Windows with Apache/IIS and MySQL. It can also be installed with WAMP or XAMPP. Another possibility is to download the bee-box, a custom Linux VM pre-installed with bWAPP. Download our What is bWAPP? introduction tutorial, including free exercises... bWAPP is for web application security-testing and educational purposes only. Have fun with this free and open source project! Cheers, Malik Mesellem bWAPP is licensed under © 2022 MME BV / Follow @MME_IT on Twitter and ask for our cheat sheet, containing all solutions! / Need an exclusive training?
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
All-in-one vulnerability intelligence platform for prioritizing remediation efforts and driving security strategies.
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
An AI-powered Google Dorking tool that helps create effective search queries to uncover sensitive information on the internet.
Simple script to check a domain's email protections and identify vulnerabilities.
Dnscan is a DNS reconnaissance tool that performs DNS scans, DNS cache snooping, and DNS amplification attack detection.
LeakIX is a red-team search engine that indexes mis-configurations and vulnerabilities online.
A fully customizable, offensive security reporting solution for pentesters, red teamers, and other security professionals.
Automate Google Hacking Database scraping and searching with Pagodo, a tool for finding vulnerabilities and sensitive information.
Crt.sh is a website that allows users to search for SSL/TLS certificates of a targeted domain, providing transparency into certificate logs.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.