github.com

Show HN: WattzGOAT – an intentionally vulnerable web app for security training

wattzgoat · 2 points · 0 comments · 2 jam yang lalu · Open original

Built this as a hands-on lab for teaching web application security. It is a fictional electricity utility's customer portal with 48 deliberately planted flags (most of OWASP Top 10) you find and exploit CTF-style, including a simulated (rule-based, not a real model) AI assistant with its own prompt-injection-style vulnerabilities. Full disclosure, built this with AI assistance but I promise you're going to enjoy tinkering with it.

Comments

0 preview comments · loading full thread