This is the VM for the Open Web Application Security Project (OWASP) Broken Web Applications project. It contains many, very vulnerable web applications, which are listed below. More information about this project can be found in the project User Guide and Home Page.

For details about the known vulnerabilities in these applications, see https://sourceforge.net/p/owaspbwa/tickets/?limit=999&sort=_severity+asc.

!!! This VM has many serious security issues. We strongly recommend that you run it only on the "host only" or "NAT" network in the virtual machine settings !!!

BUY BITCOINS LOCAL

OWASP WebGoat OWASP WebGoat.NET
OWASP ESAPI Java SwingSet Interactive OWASP Mutillidae II
OWASP RailsGoat OWASP Bricks
OWASP Security Shepherd Ghost
Magical Code Injection Rainbow bWAPP
Damn Vulnerable Web Application

ENCYCLOPEDIA OF PHYSICAL BITCOINS

OWASP Vicnum OWASP 1-Liner
Google Gruyere Hackxor
WackoPicko BodgeIt
Cyclone Peruggia

BITCOINS GIFT CARDS

WordPress OrangeHRM
GetBoo GTD-PHP
Yazd WebCalendar
Gallery2 Tiki Wiki
Joomla AWStats

AUSTRALIAN SELL BITCOIN

OWASP ZAP-WAVE WAVSEP
WIVET

0.1678 BITCOIN TO USD

OWASP CSRFGuard Test Application gate io
Simple ASP.NET Forms Simple Form with DOM Cross Site Scripting

APRIL 2017 BITCOIN

OWASP AppSensor Demo Application

BITCOIN P2P MEANING

For information about the known vulnerabilities in these applications (or to submit some), visit https://sourceforge.net/p/owaspbwa/tickets/?limit=999&sort=_severity+asc.

WITHDRAW BITCOIN FROM CASH APP

For more information about the specific versions of applications running and how to adminsiter this VM, see http://code.google.com/p/owaspbwa/wiki/UserGuide.

HAVE ALL THE BITCOINS BEEN MINED

If you encounter a problem with this VM (including with any of the installed applications), please submit an issue report on Google Code at http://code.google.com/p/owaspbwa/issues/list.

This project is sponsored by Mandiant, a FireEye Company