Project Information:template Vicnum Project

=Main= {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 * valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |

OWASP Vicnum Project
OWASP Vicnum Project is a collection of intentionally vulnerable web applications and will now includes an intentionally vulnerable web API

Introduction
“Flexible, realistic, vulnerable web applications useful to auditor’s honing their web application security skills”

They demonstrate common web application vulnerabilities such as SQL injection and cross site scripting.

Vicnum applications are commonly used in Capture the Flag exercises at security conferences.

See http://vicnum.ciphertechs.com/

Project Goal
Have fun and stimulate interest in the field

Test web application scanners Test manual attack techniques

Test source code analysis tools

Look at the code that allows the vulnerabilities

Test web application firewalls Examine evidence left by attacks

Learn how to test API's


 * valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |

Where is Vicnum?
Vulnerable VM of some Vicnum applications are downloadable from sourceforge. (see https://sourceforge.net/projects/vicnum/ )

Since individual applications within the project are constantly being updated, not everything is on that VM. Individual components are either on sourceforge or on github. (https://github.com/thedeadrobots/bwa_cyclone_transfers)

Vicnum applications are also distributed as part of the Broken Web Application Project (see https://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project)

Vicnum applications are also typically available online at http://vicnum.ciphertechs.com and http://cyclone.ciphertechs.com

Presentation
http://www.slideshare.net/mkraushar/vicnumdescription

Project Leader
Mordecai Kraushar

Nicole Becher

Related Projects
https://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project

Ohloh

 * https://www.ohloh.net/p/OWASP-VicNum

Licensing
OWASP Vicnum is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.


 * valign="top" style="padding-left:25px;width:200px;" |

Quick Downloads
http://vicnum.sourceforge.net/

https://github.com/fridaygoldsmith/bwa_cyclone_transfers

http://xxe.sourceforge.net

Sponsored By
This project is sponsored by CipherTechs.

http://www.ciphertechs.com/

Classifications

 * }

=FAQs=


 * Q1
 * A1


 * Q2
 * A2

= Acknowledgements =

Volunteers
Vicnum is developed by a worldwide team of volunteers. The primary contributors to date have been:


 * Nicole Becher
 * Mordecai Kraushar

Others

 * xxx
 * xxx

= Road Map and Getting Involved = As of February, the priorities are:
 * xxx
 * xxx
 * xxx

Involvement in the development and promotion of Vicnum is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:
 * xxx
 * xxx

=Project About=