As I mentioned in my previous post, I have been working on creating a Linux Virtual Machine containing a variety of vulnerable web applications. Just in time for the OWASP AppSec DC Conference, version 0.9 of the VM has been released!
The VM is still a work in progress. I would like to add additional applications, especially those that use different application frameworks, but the applications that are there should work. I really hope that some people at the conference will get excited about the project and contribute some additional content that can be included on the 1.0 release.
If you would like to contribute some effort or a vulnerable application or just have some comments / criticism, I'd love to hear from you at chuck.willis (at) mandiant (dot) com.
I will be speaking about this project at the OWASP AppSec DC Conference. I hope to see you there!
Chuck
