Challenge 1 - Stored cross-site scripting attack
Practice stored XSS in a vulnerable lab and learn how malicious input can be saved and shown to other users.
Practice stored XSS in a vulnerable lab and learn how malicious input can be saved and shown to other users.
A beginner-friendly guide to cross-site scripting using Kurukshetra, an intentionally vulnerable XSS practice lab.
Learn how brute force attacks work in DVWA, what makes them dangerous, and which defenses help reduce risk.
Learn practical ways to reduce cross-site scripting risk with output encoding, validation, CSP, and safer development habits.
Understand command injection risks and learn practical mitigation steps for safer handling of system commands.
Walk through DVWA high-severity brute force testing and see how weak fixes can still be bypassed with BurpSuite.
Walk through DVWA medium-severity brute force testing and learn how partial defenses can be bypassed in practice.
Set up a local DVWA lab with Docker so you can safely practice common web application security testing techniques.
A beginner-friendly overview of BurpSuite and the core tools used during web application security testing.
Install BurpSuite on Linux, understand available packages, and prepare the tool for web application security testing.