ASL HackMe Labs is yet another vulnerabile web application to practice various web based attacks. You can practice many web application attacks with these labs. Can be installed in both XAMPP and WAMPP.
Please feel free to develop, modify, customize and share it. And don't forget to give credits.
To install extract all contents in web root.
Create a database named "security" and import security.sql file to it.
For RFI to work set allow_url_include=On and allow_url_fopen=On in your php.ini
Attacks You Can Practice With ASL HackMe Labs are
- SQLi login bypass
- SQLi Error Based
- SQLi UNION based
- Bilnd SQLi
- SQLi filter bypassing
- SQLi with INSERT_INTO
- User Agent based SQLi
- XSS through SQLi
- Upload webshell through SQLi
- XSS
- User Agent based XXS
- Full Path Disclosure
- LFI
- RFI
- PHP Wrapper injections
- Cookie based SQLi
- Image Upload bypasses
- Javascript Login Bypass
- Logs Poisoning
- Remote Command Execution
- Header Injections
There are three realistic scenarios also.
Keep checking our blog and youtube channel for ASL HackMe Labs tutorials:
Blog: http://www.aslitsecurity.blogspot.com/
Youtube Channel: https://www.youtube.com/channel/UCvQqfl3gCjepWk5VwMJS5oA
Website: www.aslitsecurity.com
Trainings: www.training.aslitsecurity.com