Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Tiny, deliberately insecure web application to demonstrate application security tools.

Notifications You must be signed in to change notification settings

Santhosh26/insecureforum

 
 

Repository files navigation

Insecure Forum

An intentionally vulnerable Java Spring Boot web application designed for security testing and educational purposes.

⚠️ WARNING: This application contains deliberate security vulnerabilities and should NEVER be used in production.

Quick Start

# Build and run
mvn clean package
java -jar target/insecureforum-0.0.1-SNAPSHOT.war

# Or using Maven
mvn spring-boot:run

Access the application at http://localhost:8180

Default Credentials

  • admin/admin
  • eddy/eddy
  • john/john

Tech Stack

  • Java 8
  • Spring Boot 1.5.19
  • H2 Database (in-memory)
  • JSP/JSTL
  • Maven

Security Vulnerabilities

This application intentionally contains:

  • SQL Injection
  • Insecure authentication
  • Missing CSRF protection
  • No input validation
  • Plain text passwords

Testing

mvn test

Security Analysis

Use Fortify CLI for security scanning (see CLAUDE.md for detailed workflow).

About

Tiny, deliberately insecure web application to demonstrate application security tools.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Java 92.8%
  • JavaScript 2.8%
  • Batchfile 1.7%
  • Other 2.7%