Audit a Deliberately Vulnerable Application
~12h estimatedFind and document real vulnerabilities on a legal practice target.
Use OWASP Juice Shop or DVWA — both exist precisely for this. Work the OWASP Top 10 methodically. For each finding, prove it, explain the impact, and write the fix.
Assessed against
- Five or more distinct findings, each with reproduction steps
- Severity rated with stated reasoning
- A concrete remediation for every finding
- Testing performed only on the practice target
Suggested datasets
- OWASP Juice Shop
- DVWA
- PortSwigger Web Security Academy labs
You'll finish with
- GitHub repo with the report
- Reproduction steps per finding