github.com
Show HN: WattzGOAT – an intentionally vulnerable web app for security training
Built this as a hands-on lab for teaching web application security. It is a fictional electricity utility's customer portal with 48 deliberately planted flags (most of OWASP Top 10) you find and exploit CTF-style, including a simulated (rule-based, not a real model) AI assistant with its own prompt-injection-style vulnerabilities. Full disclosure, built this with AI assistance but I promise you're going to enjoy tinkering with it.
评论
0 条预览评论 · 正在加载完整讨论请先登录 h4cker 账号,然后连接 Hacker News 后发表评论。