/secDevLabs

🔐 OWASP Top 10 vulnerable apps based on real-life scenarios.

Primary LanguagePHPBSD 3-Clause "New" or "Revised" LicenseBSD-3-Clause

secDevLabs

The main goal of this project is to provide a laboratory for those who are interested in learning about web security development in a practical manner.

Build your own lab!

By provisioning a local lab via docker-compose, you will learn how to find, test and mitigate the most critical web application security risks.

Disclaimer

These are vulnerable applications! 🔥

OWASP Top 10 (2017) Apps

So you think you know how to solve a vulnerability?

Nice! You can send us your mitigation of the vulnerability directly through a Pull Request, using the review requested 👀 label. We expect your mitigation proposal to have all the changes needed to completely fix the vulnerability and a short explanation on what you are doing. If you're feeling a bit lost, try having a look at this mitigation solution, it might help!

Contributing

We encourage you to contribute to SecDevLabs! Please check out the Contributing to SecDevLabs guide for guidelines on how to proceed!

License

This project is licensed under the BSD 3-Clause "New" or "Revised" License - read LICENSE.md file for details.