Targets

Challenges

321 challenges across six vulnerable apps, each tagged with its OWASP Top 10 category. Points scale with difficulty. Patch the regression test tied to each challenge to score it.

Hints are closed

The CTF has ended, so hints are no longer available. During the event, revealing one cost βˆ’10 pts off your leaderboard score. The challenges below stay up to work through at your own pace.

  • 55 challenges

    DVWA

    Damn Vulnerable Web Application: PHP classics at three security levels.

    OWASP-CTF/DVWA
  • 38 challenges

    Juice Shop

    The classic deliberately-insecure web shop. OWASP Web Top 10.

    OWASP-CTF/juice-shop
  • 40 challenges

    Security Shepherd

    Web and mobile security training platform with layered challenge levels.

    OWASP-CTF/SecurityShepherd
  • 9 challenges

    VAmPI

    Vulnerable REST API: the OWASP API Security Top 10 track.

    OWASP-CTF/VAmPI
  • 110 challenges

    VulnerableApp

    OWASP's extensible vulnerability playground with the deepest challenge pool.

    OWASP-CTF/VulnerableApp
  • 69 challenges

    WebGoat

    OWASP's guided insecure Java app with lesson-driven exploitation and fixes.

    OWASP-CTF/WebGoat