WattzGOAT is an intentionally vulnerable web application. - wattzgoat/wattzgoat-web

3 points•wattzgoat•about 10 hours ago•0 comments•
Built this as a hands-on lab for teaching web application security. It is a fictional electricity utility's customer portal with 48 deliberately planted flags (most of OWASP Top 10) you find and exploit CTF-style, including a simulated (rule-based, not a real model) AI assistant with its own prompt-injection-style vulnerabilities.

Full disclosure, built this with AI assistance but I promise you're going to enjoy tinkering with it.

0 comments

No comments yet.

Read the full thread on Hacker News →

Related stories