Any demo site for testing sql injection or xss

21,003 views
Skip to first unread message

mayank verma

unread,
Sep 6, 2012, 8:20:44 AM9/6/12
to null-...@googlegroups.com
hi 
   if any one know demo site for testing sql injection or xss plz share it...

--
Regards
Mayank 



Tamilarasan Rathinagiri

unread,
Sep 6, 2012, 8:46:13 AM9/6/12
to null-...@googlegroups.com

testfire.net is one such site with many other vulnerabilities.

Tamil.

--
Get ready for the Dilli Shakedown!
nullcon security conference Delhi Sept 26-29th 2012
http://nullcon.net
 
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
 
 

w3bd...@gmail.com

unread,
Sep 6, 2012, 8:49:03 AM9/6/12
to null-...@googlegroups.com
There is a load of such websites compiled here
http://securitythoughts.wordpress.com/2010/03/22/vulnerable-web-applications-for-learning/
Sent from BlackBerry® on Airtel

From: Tamilarasan Rathinagiri <tamilar...@gmail.com>
Date: Thu, 6 Sep 2012 18:16:13 +0530
Subject: Re: [null] Any demo site for testing sql injection or xss

warri0r_

unread,
Sep 6, 2012, 9:24:24 AM9/6/12
to null-...@googlegroups.com
You can also use DVWA and Webgoat to host in your own system and test.

Abdul Rehaman

unread,
Sep 6, 2012, 10:41:44 AM9/6/12
to null-...@googlegroups.com

Nikhil Kulkarni

unread,
Sep 6, 2012, 11:03:20 AM9/6/12
to null-...@googlegroups.com
U can use DVWA...
And there is one more set of series of videos on Securitytube from the author named Audi1 who gives a testbed to download and test ur sql skills... But this is kinda basic...
But u can use DVWA... Thats the best way to test your skills...:)

Regards,
Nikhil Kulkarni(Intrud3r)

null

unread,
Sep 6, 2012, 1:38:25 PM9/6/12
to null-...@googlegroups.com
Alternatively,

u may find our very own game|over worth trying out: http://null.co.in/2012/06/14/gameover-web-pentest-learning-platform/

Cheers,
@

--
Get ready for the Dilli Shakedown!
nullcon security conference Delhi Sept 26-29th 2012
http://nullcon.net
 
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
 
 



--
Cheers,
@seem

AMol NAik

unread,
Sep 7, 2012, 7:18:56 AM9/7/12
to null-...@googlegroups.com
Check out this thread from garage4hackers:

Regularly updated with new apps.

AMol NAik

Abir Banerjee

unread,
Sep 7, 2012, 7:31:02 AM9/7/12
to null-...@googlegroups.com

rupesh kumar

unread,
Sep 7, 2012, 1:47:17 PM9/7/12
to null-...@googlegroups.com
Can we able to capture the URL's of the webgoat in paros or burpsuite.

Anant Shrivastava

unread,
Sep 7, 2012, 2:41:28 PM9/7/12
to null-...@googlegroups.com
you will be if you just remove localhost from "no proxy for" setting in your browser :P

-Anant

On Fri, Sep 7, 2012 at 11:17 PM, rupesh kumar <thisisr...@gmail.com> wrote:
Can we able to capture the URL's of the webgoat in paros or burpsuite.

SAN THO

unread,
Sep 6, 2012, 10:52:04 AM9/6/12
to null-...@googlegroups.com
Jovin aka j0k3r did a good job here  http://null.co.in/2012/06/14/gameover-web-pentest-learning-platform/ 

all you need to do is just host it in a VM and practice...practice....practice... and a little more practice..


All the Best
--

Reply all
Reply to author
Forward
0 new messages