AspGoat
AspGoat is an ASP.NET Core application that deliberately creates vulnerabilities to learn and practice the security of web applications.
##The default username for AspGoat is admin and the default password is admin123. ## The default username for AspGoat is admin and the default password is admin123. AspGoat is an intentionally vulnerable ASP.NET Core application that helps Security Engineers and Developers analyze and mitigate common web application vulnerabilities. It includes the OWASP Top 10 and beyond, providing hands-on Application Security challenges. ## ✨ Features 🐞 Intentionally vulnerable ASP.NET Core MVC app 📚 Hands-on labs for: 🐞 Cross-Site Scripting (XSS) 🐞 Cross-Site Request Forgery (CSRF) 🐞 SQL Injection (SQLi) 🐞 XML External Entity (XXE) 🐞 Local File Inclusion (LFI) 🐞 Remote Code Execution (RCE) 🐞 Unrestricted File Upload 🐞 Information Disclosure 🐞 Broken Authentication 🐞 Server-Side Request Forgery (SSRF) 🐞 Insecure Direct Object Reference (IDOR) 🐞 Insecure Deserialization 🐞 Command Injection 🐞 Prototype Pollution 🛡️ Secure vs Insecure coding snippets 🐳 Ready-to-run Docker setup






