Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

WebGOAT

Simple testing room for beating on WebGOAT

easy

45 min

14,339

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off

WebGOAT is another very popular vulnerable web application project, providing a testing ground for tool development and learning. This room is unguided and acts purely as a testing environment.

You can access WebGoat via the following URL:  ://MACHINE_IP:8080/WebGoat/ (opens in new tab). You will need to register an account by clicking the link on the login form.

Some labs require the timezone to match. WebGoat has been configured to use Europe/London, you may need to configure your client's timezone to match this for these labs.

The machine may take up to 5 minutes to boot.

Answer the questions below

Deploy WebGOAT and have fun!