This project is designed for educational purposes to help individuals understand and practice various web security vulnerabilities. Each level introduces a specific vulnerability, allowing learners to practice detection and exploitation techniques using tools commonly found in Kali Linux.
The project consists of 10 levels, each focusing on a different web security vulnerability. From basic HTML form vulnerabilities to advanced server misconfigurations, participants will encounter a wide range of challenges commonly found in real-world web applications.
To get started with the project, follow these steps:
- Clone or download the project repository to your local machine.
- Ensure you have Node.js and npm (Node Package Manager) installed on your system.
- Navigate to the project directory in your terminal.
- Install project dependencies by running
npm install. - Start the server by running
node server.js. - Access the levels through your web browser by visiting
http://localhost:3000.
Each level presents a different challenge related to web security. Here's a brief overview of each level:
- Basic HTML Form without Security: Hardcoded credentials in JavaScript.
- Client-Side Validation: Credentials validated only on the client side.
- Simple Server-Side Validation: Credentials checked on the server side, but communication is in plaintext.
- Insecure Direct Object References (IDOR): Access control flaws allow users to access data belonging to other users.
- Broken Authentication: Vulnerabilities in the authentication mechanism allow unauthorized access.
- SQL Injection: Improperly sanitized inputs allow SQL code execution.
- Cross-Site Scripting (XSS): Reflective or stored XSS vulnerabilities in user inputs or messages.
- Cross-Site Request Forgery (CSRF): Lack of CSRF tokens makes the site vulnerable to CSRF attacks.
- File Inclusion and Upload Vulnerabilities: The application allows unverified file uploads or includes files from untrusted sources.
- Server Misconfigurations and Advanced Exploitation: Misconfigured server settings or outdated software leading to unauthorized access or information disclosure.
Participants are encouraged to utilize various tools and techniques to solve each challenge. Some of the recommended tools include:
- Browser Developer Tools
- Burp Suite
- sqlmap
- BeEF (Browser Exploitation Framework)
- Nikto
- Nmap
- DirBuster
- gobuster
These challenges are for educational purposes only. It's essential to have proper authorization before testing vulnerabilities on any system. Always ensure you have permission to conduct security testing on any web application or network.
Special thanks to the creators of Kali Linux and the various security tools used in this project for their invaluable contributions to the field of cybersecurity.
