Category:OWASP Vicnum Project

Revision as of 05:50, 31 August 2009 by Paulo Coimbra (Talk | contribs)

Jump to: navigation, search


Mordecai: Please, fill in here as you find best. Paulo Coimbra

Project Identification (Old Version)


OWASP Inactive Banner.jpg

OWASP Vicnum Project

OWASP Vicnum Project is a collection of intentionally vulnerable web applications.


“Flexible, realistic, vulnerable web applications useful to auditor’s honing their web application security skills”

They demonstrate common web application vulnerabilities such as SQL injection and cross site scripting.

Vicnum applications are commonly used in Capture the Flag exercises at security conferences.


Project Goal

Have fun and stimulate interest in the field

Test web application scanners

Test manual attack techniques

Test source code analysis tools

Look at the code that allows the vulnerabilities

Test web application firewalls

Examine evidence left by attacks

Where is Vicnum?

Vulnerable VM of some Vicnum applications are downloadable from sourceforge.

Since individual applications within the project are constantly being updated, not everything is on that VM. Individual components are either on sourceforge or on github.

Vicnum applications are also distributed as part of the Broken Web Application Project (see

Vicnum applications are also typically available online at


Project Leader

Mordecai Kraushar

Nicole Becher

Related Projects



OWASP Vicnum is free to use. It is licensed under the Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

Quick Downloads

News and Events

This project is sponsored by CipherTechs.


New projects.png Owasp-builders-small.png
Project Type Files CODE.jpg



Vicnum is developed by a worldwide team of volunteers. The primary contributors to date have been:

  • xxx
  • xxx


  • xxx
  • xxx

As of February, the priorities are:

  • xxx
  • xxx
  • xxx

Involvement in the development and promotion of Vicnum is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:

  • xxx
  • xxx

Project Identification (New Version - under work)

What does this OWASP project offer you?
What does this OWASP project release offer you?
what is this project?
OWASP Vicnum Project

Purpose: A lightweight vulnerable web application based on a game played to kill time. It demonstrates common web application vulnerabilities such as cross site scripting . Vicnum is especially helpful to IT auditors who need to hone web security skills

License: Creative Commons Attribution Share Alike 3.0

who is working on this project?
Project Leader: Mordecai Kraushar

Project Maintainer: Mordecai Kraushar

Project Contributor(s): N/A

how can you learn more?
Project Pamphlet: N/A

3x slide Project Presentation: N/A

Mailing list: Subscribe or read the archives

Project Roadmap: N/A

Main links:

Project Health: Yellow button.JPG Not Reviewed (Provisional)
To be reviewed under Assessment Criteria v2.0

Key Contacts
  • Contact Mordecai Kraushar to contribute, review or sponsor this project
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
First Release - August 2009 - (download)

Release Leader: Mordecai Kraushar

Release details: Main links, release roadmap and assessment

Rating: Yellow button.JPG Not Reviewed
To be reviewed under Assessment Criteria v2.0

This category currently contains no pages or media.