Damn Vulnerable Web Application
A deliberately insecure PHP and MariaDB web application for practising common web vulnerabilities legally.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About Damn Vulnerable Web Application
Damn Vulnerable Web Application (DVWA) is a PHP/MariaDB web application that is vulnerable on purpose. You run it yourself and practise common web vulnerabilities at several difficulty levels through a simple interface. Some vulnerabilities are documented and others are not, so you can go looking for issues on your own.
It suits security professionals testing their skills and tools, web developers learning how applications get compromised, and teachers running classroom exercises. The project warns against installing it on any internet-facing server. It recommends a virtual machine on NAT networking with XAMPP, and the repository also includes a Dockerfile.
Strengths
- Covers common web vulnerabilities at several difficulty levels
- Includes undocumented flaws to discover on your own
- Dockerfile included for container setups
- README translated into many languages
Limitations
- Must never be exposed to the internet, as it will be compromised
- Intended for authorized practice in an isolated lab only
- Requires setting up a PHP and database environment
Details
- Pricing
- FreeFree and open source under the GPL-3.0 licence.
- License
- GPL-3.0
- Developer
- digininja
- Platforms
- Self-hosted
- How it runs
- Self-hosted
- Account
- Not required
- Works offline
- Yes
- Best suited for
- Practising web application attacks in an isolated home or classroom lab
- Categories
- Learning tools, Security tools
- Last verified
- Added
- Provenance
- Selected from the TechWalrus Resource Hub (Cybersecurity & Pentesting); facts checked against the developer's own pages, 3 sources on file.