CTFs y plataformas vulnerables
Listado de plataformas, webs vulnerables y CTFs para practicar ciberseguridad
- Arcanum: Labs, CTFs, competitions, bounties & tooling for AI red teaming and prompt-injection testing.
- CryptoHack: A free, fun platform for learning modern cryptography
- CTFLEARN: The most beginner-friendly way to get into hacking.
- CTFtime: There are a lot of Capture The Flag (CTF) competitions in our days, some of them have excelent tasks, but in most cases theyâre forgotten just after the CTF finished. We decided to make some kind of CTF archive and of course, itâll be too boring to have just an archive, so we made a place, where you can get some another CTF-related info - current overall Capture The Flag team rating, per-team statistics etc
- DAMN VULNERABLE WEB APPLICATION: Damn Vulnerable Web Application (DVWA) is a PHP/MariaDB web application that is damn vulnerable. Its main goal is to be an aid for security professionals to test their skills and tools in a legal environment.
- DockerLabs: DockerLabs es una plataforma web open-source que permite a los usuarios desplegar, practicar y aprender ciberseguridad sin las complicaciones de configurar mĂĄquinas virtuales pesadas. Con un solo clic, puedes lanzar entornos vulnerables aislados, listos para ser explotados.
- Hack The Box: We empower individuals and teams to build real-world cybersecurity skills.
- Hacker101 CTF: The Hacker101 CTF is a game designed to let you learn to hack in a safe, rewarding environment. Hacker101 is a free educational site for hackers, run by HackerOne. This CTF is another integral component in our plans to make the world a better place, one bug at a time.
- LetsDefend: LetsDefend is an interactive cybersecurity training platform designed to help you build practical, job-ready skills in a real-world environment. Instead of relying only on theory, LetsDefend places you in the role of a Security Operations Center (SOC) analyst, where you investigate alerts, analyze incidents, and respond to simulated cyber threats.
- Metasploitable: Metasploitable helps learners practice vulnerability testing, ethical hacking basics, and security tool usage in a controlled lab environment. It is designed for cybersecurity students, training labs, CTF practice, and safe testing without targeting real systems.
- Mobile Hacking Lab: SQL injection, buffer overflows, WebView exploits, AI prompt hacking, kernel vulnerabilities, and more. No device, no setup â just pick a target and start exploiting.
- OverTheWire: The wargames offered by the OverTheWire community can help you to learn and practice security concepts in the form of fun-filled games.
- OWASP Juice Shop: OWASP Juice Shop is probably the most modern and sophisticated insecure web application! It can be used in security trainings, awareness demos, CTFs and as a guinea pig for security tools! Juice Shop encompasses vulnerabilities from the entire OWASP Top Ten along with many other security flaws found in real-world applications!
- OWASP WebGoat: WebGoat is a deliberately insecure application that allows interested developers just like you to test vulnerabilities commonly found in Java-based applications that use common and popular open source components.
- PentesterLab: PentesterLab is built for people who want more than surface-level labs: understand how vulnerabilities work, find them in code, and exploit them with precision.
- PicoCTF: A free cybersecurity education program created by security experts at Carnegie Mellon University built around hands-on Capture the Flag challenges.
- PortSwigger Web Security Academy: PortSwiggerâs Web Security Academy enables the world to secure the web. Featuring over 200 topics and interactive labs that cover even the latest vulnerabilities.
- Pwnable.tw: Pwnable.tw is a wargame site for hackers to test and expand their binary exploiting skills.
- QryptLab: Aprende computaciĂłn cuĂĄntica, criptografĂa y seguridad a travĂŠs de retos, simuladores y mĂłdulos.
- Root Me: A fast, accessible, and realistic platform to test your hacking skills.
- The Hackers Labs: The leading platform for cybersecurity training, enterprise solutions, and hands-on hacking challenges designed by industry experts. And the best part: Itâs all completely free! Test yourself, learn, and compete with the hacker community!
- Try Hack Me: Weâre a gamified, hands-on cyber security training platform that you can access through your browser, with blue, red and purple team content for all skill levels.
- VulnBank: This is an intentionally vulnerable application, built to practice and teach application security testing, and to help security professionals, and tooling companies benchmark traditional SAST/DAST tools and offensive security AI agents.
- vulnhub: To provide materials that allows anyone to gain practical âhands-onâ experience in digital security, computer software & network administration.
- VulNyx: VulNyx is a free cybersecurity platform with intentionally vulnerable machines and CTF challenges designed to sharpen your offensive security skills.
- Wargames Nexus: This is an organized, PR-able list of wargame sites.