OWASP Vulnerable Web Applications Directory

An OWASP production project

A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.

SQLI-labs

Platform to learn SQL injection. Covers error-based (union select, double injection), blind (boolean and time-based), update/insert and header injections, second-order injection, WAF bypass, and more for GET and POST scenarios.

Collections offline
Technology PHP
Categories Free-form Single-player
Stars 5775 stars
Last contribution Oct 31, 2014 2y +

Notes

Default DB credentials in install: root:toor (Backtrack). Run setup/reset DB from browser. Walkthroughs at dummy2dummies.blogspot.com, securitytube.net; book at leanpub.com/SQLI-LABS.

← Back to directory