WebGoat is an intentionally insecure web application designed by OWASP to teach web application security lessons. You can practice on your system by installing WebGoat. In detail “What is Webgoat?” We reviewed Webgoat in our article. For installation, we first download webgoat from the link below. We open the WebGoat-WASP_Standard file using the following command.
sudo p7zip -d WebGoat-OWASP_Standard-5.3_RC1.7z
data:image/s3,"s3://crabby-images/6e63c/6e63c6814b605a63f0b109681562aace8a4ca9ef" alt="Download Webgoat"
Now we enter the Webgoat folder. You will need to start WebGoat as root.
data:image/s3,"s3://crabby-images/69da3/69da3a69fbec873380baca5972da4f3c4612247d" alt="start WebGoat"
We start Webgoat with the following command.
sh webgoat.sh start8080
data:image/s3,"s3://crabby-images/5bfc2/5bfc2e1ec7383eb17c8124089ca4946d8742700e" alt="sh webgoat.sh start8080"
We start your browser and go to http://localhost/webgoat/attack. You can login with the general username and password below.
User = guest,
Password = guest
data:image/s3,"s3://crabby-images/b1e74/b1e74128152742e18bc8fb096c7e5e49ab270d4d" alt="Introduction to Webgoat"