Showing 84 open source projects for "php vulnerable lab"

View related business solutions
  • 99.99% Uptime for MySQL and PostgreSQL Databases Icon
    99.99% Uptime for MySQL and PostgreSQL Databases

    Sub-second maintenance. 2x read/write performance. Built-in vector search for AI apps.

    Cloud SQL Enterprise Plus delivers near-zero downtime with 35 days of point-in-time recovery. Supports MySQL, PostgreSQL, and SQL Server.
    Start Free
  • Veeam Data Platform v13.1 - Get Your Free Trial Icon
    Veeam Data Platform v13.1 - Get Your Free Trial

    Secure by design, portable by default. Recover clean, fast, anywhere. Start a free trial.

    Try Veeam Data Platform today. Experience the unified platform that's secure by design, portable by default, and proven to recover clean, fast, and anywhere.
    Try it Free
  • 1

    Hullu Vulnerable System

    Pentesting OVA, suits VMware or VirtualBox

    Hullu is a lightweight vulnerable Alpine Linux VM for cybersecurity education, ethical hacking practice, and isolated lab/CTF-style scenarios. It includes DVWA, FlaskVA, DNS Lab, BIND 9, Apache, MariaDB/MySQL, phpMyAdmin, SSH/SFTP, and optional FTP/Samba practice. Hullu 3 adds DNS Lab, BIND 9 interface, FTP/Samba server support, and separate service accounts for Flask-based services compared with Hullu 2.
    Downloads: 13 This Week
    Last Update:
    See Project
  • 2
    DVWA

    DVWA

    PHP/MySQL web application

    Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and aid teachers/students to teach/learn web application security in a classroom environment.
    Downloads: 425 This Week
    Last Update:
    See Project
  • 3
    GOAD (Game of Active Directory)

    GOAD (Game of Active Directory)

    game of active directory

    GOAD (Gather Open Attack Data) is a security reconnaissance framework for collecting, enriching, and visualizing open-source intelligence (OSINT) around hosts, domains, and certificates. It automates queries to certificate transparency logs, passive DNS, subdomain enumeration, web endpoints, and other public threat feeds. The tool aggregates results into structured formats and can produce interactive graphs to highlight relationships between entities (e.g. domain → IP → cert → ASN). Analysts...
    Downloads: 2 This Week
    Last Update:
    See Project
  • 4
    Splunk Attack Range

    Splunk Attack Range

    A tool that allows you to create vulnerable environments

    The Splunk Attack Range is an open-source project maintained by the Splunk Threat Research Team. It builds instrumented cloud (AWS, Azure) and local environments (Virtualbox), simulates attacks, and forwards the data into a Splunk instance. This environment can then be used to develop and test the effectiveness of detections.
    Downloads: 11 This Week
    Last Update:
    See Project
  • MongoDB Atlas runs apps anywhere Icon
    MongoDB Atlas runs apps anywhere

    Deploy in 115+ regions with the modern database for every enterprise.

    MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
    Start Free
  • 5
    eLabFTW

    eLabFTW

    Open source electronic lab notebook for research labs

    eLabFTW is a modern, open-source electronic laboratory notebook (ELN) that helps research teams store, organize, and manage experimental records and laboratory data from a central web interface. Designed for scientific environments, the software provides a secure, browser-accessible platform where users can log protocols, results, and observations in structured records that replace traditional paper notebooks. Beyond simple experiment journaling, eLabFTW includes an inventory database for...
    Downloads: 8 This Week
    Last Update:
    See Project
  • 6
    Privilege-Escalation

    Privilege-Escalation

    This cheasheet is aimed at the CTF Players and Beginners

    ...Topics include sudo permissions, SUID binaries, kernel weaknesses, scheduled jobs, Linux capabilities, writable files, containers, databases, and network services. Individual guides connect these concepts to vulnerable lab machines and CTF examples. This structure helps learners recognize recurring misconfigurations and understand why they create security risk. The collection is primarily focused on Linux-oriented privilege escalation and educational security practice.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 7
    PVPLE
    VPLE (Linux) Vulnerable Pentesting Lab Environment VPLE is an Intentionally Vulnerable Linux Virtual Machine. This VM can be used to conduct security training, test security tools, and practice common penetration testing Labs. In VPLE bunch of labs are Available. NOTE:- "Only run in VMWare Pls Don’t run in VirtualBox" Will also run on the ProxMox server to understand how to do it pls refer to the doc in the zip named "Cybersecurity Lab Deployment on Proxmox" The default login and password is administrator: password. ...
    Leader badge
    Downloads: 26 This Week
    Last Update:
    See Project
  • 8

    Suricata Anti-DDoS Lab

    Suricata VMware VM dor IDS practicing

    Suricata Anti-DDoS Security Lab (Debian 13 VMware Virtual Machine): Preconfigured VMware virtual machine for educational network security monitoring and intrusion detection using Suricata. Designed for hands-on IDS and SOC-style training in a controlled lab environment. Includes the following integrated services: + Suricata – network intrusion detection and traffic inspection + EveBox – alert visualisation and event analysis + DVWA – vulnerable web application for traffic generation and testing + phpMyAdmin – database management and inspection Default setup demonstrates DDoS-related detection scenarios, but the lab is fully customisable for other network-based attacks. ...
    Downloads: 1 This Week
    Last Update:
    See Project
  • 9

    CyberPrint-Server

    Alpine Linux + CUPS print-server VM for cybersecurity training labs

    ...It includes CUPS/IPP on port 631, SSH/SFTP access, and a ready-to-use Generic Text-Only printer for practising secure printing, service hardening, and defensive monitoring. The vulnerable lab version includes scenarios for CVE-2024-47176, a CUPS/cups-browsed issue used in the Evil CUPS attack chain, and CVE-2026-31431, also known as Copy Fail, a Linux local privilege escalation vulnerability. For full setup instructions, lab scenarios, and updates, visit the GitHub repository: https://github.com/kaledaljebur/CyberPrint-Server Regards, Kaled Aljebur.
    Downloads: 2 This Week
    Last Update:
    See Project
  • Train ML Models With SQL You Already Know Icon
    Train ML Models With SQL You Already Know

    BigQuery automates data prep, analysis, and predictions with built-in AI assistance.

    Build and deploy ML models using familiar SQL. Automate data prep with built-in Gemini. Query 1 TB and store 10 GB free monthly.
    Start Free
  • 10
    virgosun teaching support

    virgosun teaching support

    Mentor, code c, c++, java, go, php, swift, .. DevSecOps virtual lab, .

    Menor, code c, c++, java, python, go, php, swift, .., DevSecOps virtual lab, .. This software is provided as a demonstration build. Redistribution of the binary is allowed for academic evaluation only. More previously completed projects will be released incrementally as executable packages are rebuilt for public distribution. www.youtube.com/embed/fzoISpZv5d0?rel=0
    Downloads: 0 This Week
    Last Update:
    See Project
  • 11

    ProxMox-Stuff

    Wordpress template container (LXC based) for ProxMox

    ...This container is based on Ubuntu 24, while the default Wordpress container in Proxmox (turnkey-wordpress) is based on Debian 12. It is suitable for development, testing it as CMS, or test the security of Wordpress within ProxMox-based Cybersecurity lab. Services in the container: - Apache with PHP integration - MySQL - SSH/SFTP (under construction) - phpMyadmin (under construction) To use it in ProxMox: - In the shell of PVE, run "wget https://sourceforge.net/projects/proxmox-stuff/files/wordpress-template.tar.gz/download -O /var/lib/vz/template/cache/wordpress-template-ubuntu24.tar.gz" - Then create a new container, and select "wordpress-template-ubuntu24.tar.gz" as a template Please let me know if there is any question of suggestion. ...
    Downloads: 1 This Week
    Last Update:
    See Project
  • 12
    Easy Database Forms For All

    Easy Database Forms For All

    Create Web Based Forms Quickly, With In-built DB, For All Your Teams

    Please watch the video till 18m:00s / screenshots below for easy installation steps. This video is taken from my other project, with many similarities and some naming differences. After installation, login to the Administrator Page with : Username : root Password : change_this and look at the team1 database and the sample_table in it, from all aspects. You can now create your own tables/forms. Also, login into the team1 user page ( from homepage ) with : Username : team1...
    Downloads: 14 This Week
    Last Update:
    See Project
  • 13
    vulnerable-AD

    vulnerable-AD

    Create a vulnerable active directory

    ...The project can create user objects with default or weak passwords, inject passwords into object descriptions, disable SMB signing, and manipulate ACLs to reproduce real-world privilege escalation and persistence scenarios. A convenience wrapper and examples make it straightforward to deploy in a local lab: you can install AD services, run the script on a domain controller, and generate hundreds of vulnerable accounts and conditions for testing. The repository emphasizes full coverage of the listed attack types and includes options to randomize which weakness
    Downloads: 0 This Week
    Last Update:
    See Project
  • 14
    Vulnhub-CTF-Writeups

    Vulnhub-CTF-Writeups

    This cheasheet is aimed at CTF Players to sort Vulnhub Labs

    ...Each entry links to a complete external walkthrough based on the maintainers' experience solving the lab. The collection spans many generations of VulnHub challenges and a wide range of attack scenarios. It is primarily an educational index for self-paced security training and CTF preparation.
    Downloads: 1 This Week
    Last Update:
    See Project
  • 15
    Confused

    Confused

    Tool to check for dependency confusion vulnerabilities

    A tool for checking for lingering free namespaces for private package names referenced in dependency configuration for Python (pypi) requirements.txt, JavaScript (npm) package.json, PHP (composer) composer.json or MVN (maven) pom.xml. confused simply reads through a dependency definition file of an application and checks the public package repositories for each dependency entry in that file. It will proceed to report all the package names that are not found in the public repositories - a state that implies that a package might be vulnerable to this kind of attack, while this vector has not yet been exploited.
    Downloads: 10 This Week
    Last Update:
    See Project
  • 16
    VPLE

    VPLE

    Vulnerable Pentesting Lab Environment

    VPLE (Linux) Vulnerable Pentesting Lab Environment VPLE is an Intentionally Vulnerable Linux Virtual Machine. This VM can be used to conduct security training, test security tools, and practice common penetration testing Labs. In VPLE bunch of labs are Available. NOTE:- "Only run in VMWare Pls Don’t run in VirtualBox" The default login and password is administrator: password.
    Downloads: 26 This Week
    Last Update:
    See Project
  • 17
    AIGLe
    A.I.G.Le is a French PHPMySQL code to simplify lab management. A.I.G.Le means "Aide Interactive a la Gestion de Laboratoire"
    Downloads: 1 This Week
    Last Update:
    See Project
  • 18
    Web Security Dojo

    Web Security Dojo

    Virtual training environment to learn web app ethical hacking.

    Web Security Dojo is a virtual machine that provides the tools, targets, and documentation to learn and practice web application security testing. A preconfigured, stand-alone training environment ideal for classroom and conferences. No Internet required to use. Ideal for those interested in getting hands-on practice for ethical hacking, penetration testing, bug bounties, and capture the flag (CTF). A single OVA file will import into VirtualBox and VMware. There is also an Ansible...
    Leader badge
    Downloads: 99 This Week
    Last Update:
    See Project
  • 19

    MX Linux Bare Server Edition Respin

    MX Linux Bare Server Edition

    Based on the MX18 Continuum (Minimal) Release by manyroads, this is an even more minimal version of MX-Linux intended for use as a base for configuring a server for use in a home environment, or in a lab for experimental use or as a learning platform. Other types of servers (Apache Web/PHP, MySQL, media, etc.) may be created by installing the appropriate packages from the MX Stable Repository using the MX Package Installer (MXPI.) Intrusion detection and system monitoring apps are also available. DISCLAIMER: using this or any other desktop-oriented Linux distribution as a server for mission-critical applications is not recommended. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 20
    ExploitMe REST

    ExploitMe REST

    A deliberately vulnerable REST API built with PHP and MySQL.

    A deliberately vulnerable Representational State Transfer (REST) API built with PHP and MySQL. Version 1.0 is already out with basic features. You can get it from download page. In security testing labs. Using it in a public facing server or production environment is more or less like installing a back-door to your system.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 21
    Logic Lab

    Logic Lab

    This is a suite of mathematical software solvers GUI

    This is a suite of mathematical software solvers interface on DLV and other command-line solvers. It helps researchers and students to better comprehend their declarative definitions published on papers. The user can have links to the related papers and to the software of the corresponding definitions.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 22

    MOIRAI

    Simple Scientific Workflow System for CAGE Analysis

    Cap analysis of gene expression (CAGE) is a sequencing based technology to capture the 5’ ends of RNAs in a biological sample. After mapping, a CAGE peak on the genome indicates the position of an active transcriptional start site (TSS) and the number of reads correspond to its expression level. CAGE is prominently used in both the FANTOM and ENCODE project. MOIRAI is a compact yet flexible workflow system designed to carry out the main steps in data processing and analysis of CAGE data....
    Downloads: 3 This Week
    Last Update:
    See Project
  • 23

    RIPS - PHP Security Analysis

    Free Static Code Analysis Tool for PHP Applications

    RIPS is a static code analysis tool for the automated detection of security vulnerabilities in PHP applications. It was released 2010 during the Month of PHP Security (www.php-security.org). NOTE: RIPS 0.5 development is abandoned. A complete rewrite with OOP support and higher precision is available at https://www.ripstech.com/next-generation/
    Downloads: 12 This Week
    Last Update:
    See Project
  • 24
    LAMPSecurity training is designed to be a series of vulnerable virtual machine images along with complementary documentation designed to teach linux,apache,php,mysql security.
    Leader badge
    Downloads: 11 This Week
    Last Update:
    See Project
  • 25
    Vulnerawa
    Vulnerawa stands for vulnerable web application, though I think it should be renamed Vulnerable website. Unlike other vulnerable web apps, this application strives to be close to reality as possible. To know more about Vulnerawa, go here https://www.hackercoolmagazine.com/vulnerawa-vulnerable-web-app-for-practice/ See how to setup Vulnerawa in Wamp server.
    Downloads: 0 This Week
    Last Update:
    See Project
  • Previous
  • You're on page 1
  • 2
  • 3
  • 4
  • Next