Application for Simulating OWASP Vulnerabilities
摘要
This paper presents a novel platform for novice learners to learn cyber security and web application penetration testing by presenting challenges that imitate real-world security breaches based on OWASP’s top 10 breaches of 2021. The platform features web pages that contain potential breach doors that reflect real websites, designed with similar breaches that may lead to data or financial loss. The platform is gamified, featuring a ranking system, scoring, and a Catch The Flag (CTF) learning approach to enable users to learn and compete simultaneously. The proposed platform consists of several web pages that include potential breach doors, designed to reflect real-world websites with similar vulnerabilities that may lead to financial or data loss for the website owner. The web pages are designed and hosted in a manner that simulates a real competition, with a ranking system and proper scoring. The objective of the proposed platform is to provide an interactive and engaging learning experience for novice learners that is both practical and challenging. By utilizing a gamification approach, the platform aims to promote active learning and enhance user engagement. Furthermore, the platform is designed to be easily accessible and user-friendly, with no special hardware or software requirements. The proposed platform offers several benefits for novice learners, including the opportunity to gain practical experience in cyber security and web application penetration testing. By practicing the challenges and security breaches presented in the platform, users can develop practical skills that are relevant in real-world scenarios. Additionally, the platform offers a safe environment for learners to experiment with security breaches without the risk of causing harm to real-world systems.