OWASP Vulnerable Web Applications Directory

An OWASP production project

A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.

Altoro Mutual (AltoroJ)

Sample banking J2EE web application. Shows what happens when applications are written for functionality but not security; simple platform for demonstrating and learning real-life application security issues. Standard Java & JSP; REST API with Swagger.

Collections online offline
Technology J2EE Java Apache Derby OpenAPI Swagger
Categories Free-form Single-player
Author HCL/IBM/Watchfire
Stars 291 stars
Last contribution Jul 23, 2024 < 2y

Notes

Run only in a sheltered environment (e.g. VM). Log in with jsmith/demo1234 or admin/admin. Hosted demo: altoromutual.com:8080.

← Back to directory