Pentesting Vulnerable Study Frameworks Complete List

May 10th, 2011

It’s very difficult for the beginner security analyst, mainly the ones interested in the area of pentesting, to find good study pentesting resources. Starting from the principle that in pentesting there are many other sub areas of study, it becomes more and more difficult to choose and then find a proper pentesting study application.

As the beginner knows nearly nothing it became very difficult to prepare a Home Pentesting Lab for study, once that beginners has to know something about coding a vulnerable application fisrt, then exploit them.

Thinking about that i’ve decided to gather a list, the most complete I could, with all vulnerable pentesting tools I could find. They are categorized based on the type of application like Web Pentesting, War Games and Insecure Distributions. Due to the amount of tools I won’t be doing any previews because it would delay this post a lot and make it a little boring to read. I’m gonna review every tool with complete labs later on in future posts.

As I don’t know every pentesting tool in the planet, feel free to contact me if you remember any application, in fact I would much appreciate it. And I apologize if I miscategorized some of them, feel free to tell me when I’ve done that so i can correct that.

Note that this post intends to show only vulnerable applications used to be exploited, not the tools used to exploit them.

 

Web Pentesting

Application Name Company/Developer URL
OWASP WebGoat OWASP http://www.owasp.org/index.php/OWASP_WebGoat_Project
OWASP Vicnum OWASP http://www.owasp.org/index.php/Category:OWASP_Vicnum_Project
OWASP InsecureWebApp OWASP http://www.owasp.org/index.php/Category:OWASP_Insecure_Web_App_Project
Web Security DOJO Maven Security Consulting http://www.mavensecurity.com/web_security_dojo/
Gruyere (antigo Codelab / Jalsberg) Google http://google-gruyere.appspot.com/
Hacme Game NTNU http://hacmegame.org/
SPI Dynamics SPI Dynamics http://zero.webappsecurity.com/
Acunetix 1 Acunetix http://testphp.vulnweb.com/
Acunetix 2 Acunetix http://testasp.vulnweb.com/
Acunetix 3 Acunetix http://testaspnet.vulnweb.com/
PCTechtips Challenge PC Tech Tips http://pctechtips.org/hacker-challenge-pwn3d-the-login-form/
Damn Vulnerable Web Application DVWA http://dvwa.co.uk/
Mutillidae Iron Geek http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10
The Butterfly Security Project The Butterfly Security http://sourceforge.net/projects/thebutterflytmp/
Hacme Casino McAfee http://www.mcafee.com/us/downloads/free-tools/hacme-casino.aspx
Hacme Bank 2.0 McAfee http://www.mcafee.com/us/downloads/free-tools/hacme-bank.aspx
Updated HackmeBank McAfee http://www.o2-ounceopen.com/technical-info/2008/12/8/updated-version-of-hacmebank.html
Hacme Books McAfee http://www.mcafee.com/us/downloads/free-tools/hacmebooks.aspx
Hacme Travel McAfee http://www.mcafee.com/us/downloads/free-tools/hacmetravel.aspx
Hacme Shipping McAfee http://www.mcafee.com/us/downloads/free-tools/hacmeshipping.aspx
Moth Bonsai Sec http://www.bonsai-sec.com/en/research/moth.php
Stanford SecuriBench Standford http://suif.stanford.edu/%7Elivshits/securibench/
SecuriBench Micro Standford http://suif.stanford.edu/%7Elivshits/work/securibench-micro/
BadStore BadStore http://www.badstore.net/
WebMaven/Buggy Bank Maven Security http://www.mavensecurity.com/webmaven
EnigmaGroup Enigma Group http://enigmagroup.org/
XSS Encoding Skills – x5s (Casaba Watcher) X5S http://www.nottrusted.com/x5s/
Exploit- DB Exploit DB http://www.exploit-db.com/webapps
The Bodgeit Store The Bodgeit Store http://code.google.com/p/bodgeit/
LampSecurity MadIrish http://sourceforge.net/projects/lampsecurity/
hackxor Hackxor http://hackxor.sourceforge.net/cgi-bin/index.pl
WackoPicko WackoPicko

https://github.com/adamdoupe/WackoPicko

RSnake’s Vulnerability Lab RSnake http://ha.ckers.org/weird/

 

War Games

Application Name Company / Developer URL
Hell Bound Hackers Hell Bound Hackers http://hellboundhackers.org/
Vulnerability Assessment Kevin Orrey http://www.vulnerabilityassessment.co.uk/
Smash the Stack Smash the Stack http://www.smashthestack.org/
Over the Wire Over the Wire http://www.overthewire.org/wargames/
Hack This Site Hack This Site http://www.hackthissite.org/
Hacking Lab Hacking Lab https://www.hacking-lab.com/
We Chall We Chall https://www.wechall.net/
REMnux REMnux http://zeltser.com/remnux/

 

Insecure Distributions

Application Name Company / Developer URL
Damm Vulnerable Linux DVL http://www.damnvulnerablelinux.org/
Metasploitable Offensive Security http://blog.metasploit.com/2010/05/introducing-metasploitable.html
de-ICE Hacker Junkie http://www.de-ice.net/
Moth Bonsai Security Software http://www.bonsai-sec.com/en/research/moth.php
PwnOS Niel Dickson http://www.neildickson.com/os/
Holynix Pynstrom http://pynstrom.net/holynix.php

 

Have fun !!!

 

Source: FelipeMartins.info (Language: ) Licença Creative Commons

 

Share |

 

http://www.mcafee.com/us/downloads/free-tools/hacmebooks.aspx


Related Posts:



  1. Marcelo
    May 10th, 2011 at 19:58 | #1

    [-]

    Felipe,

    I thik you did an excellent job with this complete list I will use it like reference to my co-workers.

    Thanks for your time.

  2. Oscar
    May 11th, 2011 at 14:59 | #2

    [-]

    Great compilation, Thank You.

    Oscar

  3. Doug
    May 11th, 2011 at 16:59 | #3

    [-]

    Thanks for this Felipe, I agree with the others!

  4. May 11th, 2011 at 17:46 | #4

    [-]

    Thanks everyone, i’m gonna try to keep it updated whenever possible !!!

  5. Jean-Paul
    May 12th, 2011 at 08:42 | #5

    [-]

    Excellent page, my compliments.

    May I suggest the following:

    REMnux: A Linux Distribution for Reverse-Engineering Malware http://zeltser.com/remnux/
    Buster Sandbox Analyzer http://bsa.isoftware.nl/

  6. Dominique Berube
    May 12th, 2011 at 16:28 | #6

    [-]

    Hi Felipe,

    This will help me, because I will have to give a course in 2012 about an introduction to forensic.

    Thank’s!

  7. May 12th, 2011 at 16:53 | #7

    [-]

    Posted on exploits-brasil list by gustavofranco.com:

    http://www.gustavofranco.com/wp/?p=394

    I think it’s useful to complement yours Insecure Distros list :)

  8. May 12th, 2011 at 17:13 | #8

    [-]

    @Odilo Jr.
    Odilo, I liked your list very much, thanks for your comment, I’m gonna update the list with the ones you’ve sent me.

    Thank you again.

  9. Pat
    May 13th, 2011 at 09:26 | #9

    [-]

    I stumbled onto your list of vulnerable apps and noticed that the link to the Foundstone hacme apps is broken. The proper link is http://www.mcafee.com/us/downloads/free-tools/index.aspx . The tools are located under Foundstone SASS Tools. Also, I noticed that hackthissite.org was missing… It’s a good resource and you might drop it in the list.

  10. May 15th, 2011 at 12:44 | #10

    [-]

    Hi Felipe,

    Great list :)

    Minor point – the BodgeIt Store is hosted on Google code, but its nothing to do with Google the company.
    So the blame has to lie with me I’m afraid ;)

    Many thanks,

    Psiinon

  11. May 15th, 2011 at 17:28 | #11

    [-]

    @Jean-Paul
    Hi Jean, thanks for the hint, i’ve updated the list with REMnux,

    Thanks again.

  12. May 15th, 2011 at 17:29 | #12

    [-]

    @Dominique Berube
    I’m glad I can help you on that. If you want some more help just drop me a line. There are plenty of Forensic tools you can found very usefull at McAfee Website at http://www.mcafee.com/us/downloads/free-tools/index.aspx.

    Thanks again

  13. May 15th, 2011 at 17:37 | #13

    [-]

    @Pat
    Pat, thank you very much for that, i haven’t realized the link was wrong. I’ve corrected that, thanks again.

  14. May 16th, 2011 at 16:41 | #14

    [-]

    A good list – thank you.

    I got started with Whittaker’s CANNED HEAT and HALODECK LITE – I don’t know if they are still available.

    http://www.woodsmall.com/books.htm#CANNEDHEAT

  15. shshank
    May 17th, 2011 at 04:38 | #15

    [-]

    Hi Felip,

    Thanks for this great list.

  16. May 20th, 2011 at 00:22 | #16

    [-]

    muito bom. Hackthissite is one of my favorites. Informative, fun and challenging

    http://www.cryptool.org/ for those intested in crytpo

  17. Abeer
    May 25th, 2011 at 02:06 | #17

    [-]

    badstore.net is not loading

  18. July 8th, 2011 at 08:02 | #18

    [-]

    hi
    Felipe Martins
    This frame work can be added to the list http://www.getmantra.com

  19. July 14th, 2011 at 15:10 | #19

    [-]

    xSpider from http://www.ptsecurity.com/,

    If you’ll do review, could be nice to know ( some of them I know) : Is FREE or Commercial ? License cost. Short description of what tool can do
    Which complainces this tool covered (PCI, NSA etc…) ,

    And , I’m thinking that you should include BackTrack distributive.

  20. Luiz
    July 15th, 2011 at 20:12 | #20

    [-]

    Há o skipfish no site da Google.

    http://code.google.com/p/skipfish/

  21. July 17th, 2011 at 18:41 | #21

    [-]

    @Luiz
    Oi Luiz

    A lista trata apenas de ferramentas são inseguras para serem invadidas, ou seja, ferramentas inseguras par serem utilizadas como laboratório de invasão, e não de ferramentas para procurar as vulnerabilidades. Num futuro próximo farei um post sobre esse outro tipo de ferramentas.
    O Skipfish é uma ferramenta de reconhecimento de vulnerabilidades para aplicações web.

    Abraço

  22. @norld
    September 18th, 2011 at 12:16 | #22

    [-]

    Hi~ Felipe.

    The list will be helpful for my teaching~
    Tahnk you Felipe~ ^^

  23. September 19th, 2011 at 23:40 | #24

    [-]

    Great! it’s useful . thanks Felipe :)

  24. shashi
    October 3rd, 2011 at 01:07 | #25

    [-]

    thanks

  25. Invar
    March 3rd, 2012 at 13:16 | #26

    [-]

    Watch a short video about Top 10 vulnerable applications on your network:
    http://rocketviews.com/watch?416aO901fuUagic

  1. May 11th, 2011 at 06:47 | #1
  2. May 13th, 2011 at 14:19 | #2
  3. May 14th, 2011 at 21:30 | #3
  4. May 15th, 2011 at 16:15 | #4
  5. May 16th, 2011 at 05:07 | #5
  6. June 4th, 2011 at 20:43 | #6
  7. June 12th, 2011 at 13:34 | #7
  8. July 17th, 2011 at 20:57 | #8
  9. August 12th, 2011 at 13:35 | #9
  10. March 2nd, 2012 at 12:51 | #10
*