Skip to content

About

Web app penetration testing lab - OWASP Top 10 vulnerabilities, custom Python scanner, and professional pentest report

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

🔐 WebSec Audit Lab — Web Application Security Research Project

A hands-on security research project demonstrating end-to-end vulnerability discovery, exploitation, and remediation across a custom-built intentionally vulnerable web application.

Security OWASP Python License Status


📋 Project Overview

This project simulates a real-world penetration test against a deliberately vulnerable web application. It demonstrates:

  • Threat Modeling using the STRIDE framework
  • Automated vulnerability scanning with a custom Python tool
  • Manual exploitation of OWASP Top 10 vulnerabilities
  • Structured reporting following industry-standard pentest report format
  • Remediation guidance with before/after code comparisons

This project was built to demonstrate applied knowledge in offensive and defensive web security — not just theoretical understanding.


🗂️ Repository Structure

websec-audit/
├── README.md                   ← You are here
├── vulnerable-app/             ← Target application (Flask + SQLite)
│   ├── app.py                  ← Main application with intentional vulns
│   ├── templates/              ← HTML templates
│   ├── requirements.txt
│   └── setup.sh
├── scanner/                    ← Custom vulnerability scanner
│   ├── websec_scanner.py       ← Main scanner engine
│   ├── modules/                ← Individual vulnerability modules
│   │   ├── sqli_detector.py
│   │   ├── xss_detector.py
│   │   ├── csrf_detector.py
│   │   └── header_analyzer.py
│   └── requirements.txt
├── reports/                    ← Findings & formal report
│   ├── PENTEST_REPORT.md       ← Full professional report
│   ├── findings_summary.json   ← Machine-readable findings
│   └── screenshots/            ← Evidence (add yours here)
├── docs/                       ← Supporting documentation
│   ├── THREAT_MODEL.md         ← STRIDE threat model
│   ├── METHODOLOGY.md          ← Testing methodology
│   └── REMEDIATION_GUIDE.md    ← Fix-it guide
└── scripts/
    ├── setup_lab.sh            ← One-command lab setup
    └── run_audit.sh            ← Run full audit pipeline

🎯 Vulnerabilities Covered

# Vulnerability OWASP Category Severity Status
1 SQL Injection (Login Bypass) A03:2021 🔴 Critical Documented
2 Reflected XSS A03:2021 🟠 High Documented
3 Stored XSS A03:2021 🟠 High Documented
4 Broken Access Control A01:2021 🔴 Critical Documented
5 CSRF (No Token Validation) A01:2021 🟠 High Documented
6 Insecure Direct Object Ref. A01:2021 🟠 High Documented
7 Missing Security Headers A05:2021 🟡 Medium Documented
8 Sensitive Data Exposure A02:2021 🟠 High Documented
9 Hardcoded Credentials A07:2021 🔴 Critical Documented
10 Directory Traversal A01:2021 🟠 High Documented

🚀 Quick Start

Prerequisites

  • Python 3.10+
  • pip
  • Git

1. Clone and set up

git clone https://github.com/YOUR_USERNAME/websec-audit-lab.git
cd websec-audit-lab
chmod +x scripts/setup_lab.sh
./scripts/setup_lab.sh

2. Launch the vulnerable app

cd vulnerable-app
pip install -r requirements.txt
python app.py
# App runs on http://localhost:5000

3. Run the scanner

cd scanner
pip install -r requirements.txt
python websec_scanner.py --target http://localhost:5000 --output ../reports/findings_summary.json

4. View results

Open reports/PENTEST_REPORT.md for the full findings report.


⚠️ Ethical Use Disclaimer

This project is for educational purposes only. The vulnerable application is intentionally designed to be insecure. Never deploy it on a public server or a production environment. Only run security tests against systems you own or have explicit written permission to test. Unauthorized testing is illegal.


🧠 Key Learning Outcomes

  • Hands-on OWASP Top 10 exploitation and remediation
  • Writing custom security tooling in Python
  • Structured threat modeling with STRIDE
  • Professional penetration testing report writing
  • Defensive programming patterns

📚 References


👤 Author

[Olayinka David]
Security Enthusiast | Aspiring Cybersecurity Researcher
📧 urekayinka@gmail.com
🔗 LinkedIn | GitHub


This project is part of my cybersecurity portfolio demonstrating curiosity in security research skills

About

Web app penetration testing lab - OWASP Top 10 vulnerabilities, custom Python scanner, and professional pentest report

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages