A hands-on security research project demonstrating end-to-end vulnerability discovery, exploitation, and remediation across a custom-built intentionally vulnerable web application.
This project simulates a real-world penetration test against a deliberately vulnerable web application. It demonstrates:
- Threat Modeling using the STRIDE framework
- Automated vulnerability scanning with a custom Python tool
- Manual exploitation of OWASP Top 10 vulnerabilities
- Structured reporting following industry-standard pentest report format
- Remediation guidance with before/after code comparisons
This project was built to demonstrate applied knowledge in offensive and defensive web security — not just theoretical understanding.
websec-audit/
├── README.md ← You are here
├── vulnerable-app/ ← Target application (Flask + SQLite)
│ ├── app.py ← Main application with intentional vulns
│ ├── templates/ ← HTML templates
│ ├── requirements.txt
│ └── setup.sh
├── scanner/ ← Custom vulnerability scanner
│ ├── websec_scanner.py ← Main scanner engine
│ ├── modules/ ← Individual vulnerability modules
│ │ ├── sqli_detector.py
│ │ ├── xss_detector.py
│ │ ├── csrf_detector.py
│ │ └── header_analyzer.py
│ └── requirements.txt
├── reports/ ← Findings & formal report
│ ├── PENTEST_REPORT.md ← Full professional report
│ ├── findings_summary.json ← Machine-readable findings
│ └── screenshots/ ← Evidence (add yours here)
├── docs/ ← Supporting documentation
│ ├── THREAT_MODEL.md ← STRIDE threat model
│ ├── METHODOLOGY.md ← Testing methodology
│ └── REMEDIATION_GUIDE.md ← Fix-it guide
└── scripts/
├── setup_lab.sh ← One-command lab setup
└── run_audit.sh ← Run full audit pipeline
| # | Vulnerability | OWASP Category | Severity | Status |
|---|---|---|---|---|
| 1 | SQL Injection (Login Bypass) | A03:2021 | 🔴 Critical | Documented |
| 2 | Reflected XSS | A03:2021 | 🟠 High | Documented |
| 3 | Stored XSS | A03:2021 | 🟠 High | Documented |
| 4 | Broken Access Control | A01:2021 | 🔴 Critical | Documented |
| 5 | CSRF (No Token Validation) | A01:2021 | 🟠 High | Documented |
| 6 | Insecure Direct Object Ref. | A01:2021 | 🟠 High | Documented |
| 7 | Missing Security Headers | A05:2021 | 🟡 Medium | Documented |
| 8 | Sensitive Data Exposure | A02:2021 | 🟠 High | Documented |
| 9 | Hardcoded Credentials | A07:2021 | 🔴 Critical | Documented |
| 10 | Directory Traversal | A01:2021 | 🟠 High | Documented |
- Python 3.10+
- pip
- Git
git clone https://github.com/YOUR_USERNAME/websec-audit-lab.git
cd websec-audit-lab
chmod +x scripts/setup_lab.sh
./scripts/setup_lab.shcd vulnerable-app
pip install -r requirements.txt
python app.py
# App runs on http://localhost:5000cd scanner
pip install -r requirements.txt
python websec_scanner.py --target http://localhost:5000 --output ../reports/findings_summary.jsonOpen reports/PENTEST_REPORT.md for the full findings report.
This project is for educational purposes only. The vulnerable application is intentionally designed to be insecure. Never deploy it on a public server or a production environment. Only run security tests against systems you own or have explicit written permission to test. Unauthorized testing is illegal.
- Hands-on OWASP Top 10 exploitation and remediation
- Writing custom security tooling in Python
- Structured threat modeling with STRIDE
- Professional penetration testing report writing
- Defensive programming patterns
- OWASP Top 10 (2021)
- OWASP Testing Guide v4.2
- NIST Cybersecurity Framework
- CVSSv3 Scoring System
- PTES Technical Guidelines
[Olayinka David]
Security Enthusiast | Aspiring Cybersecurity Researcher
📧 urekayinka@gmail.com
🔗 LinkedIn | GitHub
This project is part of my cybersecurity portfolio demonstrating curiosity in security research skills