Date: 2010-09-22

Hi does anybody know of any other programs similar to Webgoat for the demonstration of web application security flaws?

The big ones I would think of would be Fortify and HP WebInspect.

Fortify will scan the source code and find potential vulnerabilities HP WebInspect will scan/brute force a website in production and find/report actual vulnerabilities.

Both require a fairly expensive license.

There are plenty of them. Some hosted, some for local installation. Some targeted more to teaching about web security, others for testing. Fortunately some folks already made some lists:




I personally would start with Google Gruyere (http://google-gruyere.appspot.com/).

There is a really good list in here: http://ha.ckers.org/blog/20090406/hacking-without-all-the-jailtime/

Take a look at:

Acunetix WVS automatically checks your web applications for SQL Injection, XSS & other web vulnerabilities.