AspGoat

AspGoat

AspGoat is an ASP.NET Core application that deliberately creates vulnerabilities to learn and practice the security of web applications.

104GitHub
Description

##The default username for AspGoat is admin and the default password is admin123. ## The default username for AspGoat is admin and the default password is admin123. AspGoat is an intentionally vulnerable ASP.NET Core application that helps Security Engineers and Developers analyze and mitigate common web application vulnerabilities. It includes the OWASP Top 10 and beyond, providing hands-on Application Security challenges. ## ✨ Features 🐞 Intentionally vulnerable ASP.NET Core MVC app 📚 Hands-on labs for: 🐞 Cross-Site Scripting (XSS) 🐞 Cross-Site Request Forgery (CSRF) 🐞 SQL Injection (SQLi) 🐞 XML External Entity (XXE) 🐞 Local File Inclusion (LFI) 🐞 Remote Code Execution (RCE) 🐞 Unrestricted File Upload 🐞 Information Disclosure 🐞 Broken Authentication 🐞 Server-Side Request Forgery (SSRF) 🐞 Insecure Direct Object Reference (IDOR) 🐞 Insecure Deserialization 🐞 Command Injection 🐞 Prototype Pollution 🛡️ Secure vs Insecure coding snippets 🐳 Ready-to-run Docker setup

Screenshots
Screenshot 1
Screenshot 2
Screenshot 3
Mobile Screenshots
Mobile Screenshot 1
Mobile Screenshot 2
Mobile Screenshot 3
Mobile Screenshot 4
App Information
Version
0.0.1
Package Size
472.88 KB
Image Size
117.12 MB
Updated
October 11, 2025
Source Code
Soham7-dev
Platform Support
PCMobile
Keywords
aspgoatasp