OWASP Web Security Testing Guide ↗
A structured reference for testing web applications.
Curated by Ophion. Start with a guide, then practise in the dedicated training environments below. Only test systems you own or have permission to assess.
Nine primary-source starting points, reviewed 28 September 2026. Some hosted exercises require a free account.
A structured reference for testing web applications.
Concise defensive guidance for authentication, sessions, input handling and other application-security topics.
Free web-security lessons and interactive practice labs.
An intentionally vulnerable application for practising in a controlled training environment.
A deliberately insecure application with lessons about common web vulnerabilities.
Carnegie Mellon security-learning challenges; the legacy picoCTF site directs visitors to its successor.
Progressive exercises in command-line skills and security concepts.
Hands-on computing and security exercises arranged into learning modules.
Free technical training, including low-level computing and security topics.