Skip to content

Public Vulnerable Websites

You can use this for copying and pasting. Note that you will need to set up authentication for some of these sites.

# Google Public Firing Range (no authentication required)
https://public-firing-range.appspot.com/
# Vulnweb
http://testphp.vulnweb.com
http://testhtml5.vulnweb.com
http://testasp.vulnweb.com
# Testsparker
http://aspnet.testsparker.com/
http://php.testsparker.com/
# REST APIs
http://rest.testsparker.com
# Testfire
http://demo.testfire.net/
# OWASP Juice Shop
https://juice-shop.herokuapp.com/

See the table below for a list of deliberately vulnerable public websites you can use for scanning.

SiteURLUsernamePassword
Google Public Firing Rangehttps://public-firing-range.appspot.comNoneNone
OWASP Juice Shophttps://juice-shop.herokuapp.comadmin@juice-sh.opadmin123
PHP Vulnwebhttp://testphp.vulnweb.comtesttest
HTML5 Vulnwebhttp://testhtml5.vulnweb.comadminadmin
ASP Vulnwebhttp://testasp.vulnweb.comRegistration requiredRegistration required
ASP.Net Vulnwebhttp://testaspnet.vulnweb.comRegistration requiredRegistration required
ASP.NET Testsparkerhttp://aspnet.testsparker.comalan@turing.comtheturingtest
PHP TestSparkerhttp://php.testsparker.comadminadmin123456

The table below lists deliberately vulnerable public REST APIs you can use for scanning. For an in-depth tutorial, see the example on Scanning REST APIs.

SiteBase Target URLOpenAPI File LocationHeader NameHeader Value
TestSparkerhttp://rest.testinvicti.com/jwt/apihttp://rest.testsparker.com/files/openapi-swagger_jwt.yamlAuthorizationBearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiIsImtpZCI6InNlY3JldC50eHQifQ.eyJ1c2VyIjoidGVzdCJ9.jqBFzyBB68KWiOvEJhcaDgMY0Gea-t0KNnf-fR2Ioyc