pygoat
intentionally vuln web Application Security in django
File Explorer
Download Latest Version (.zip)- flake8.yml
- hadolint.yml
- settings.json
- populate_challenge.py
- populate_challenges.py
- 0001_initial.py
- 0002_challenge_docker_port.py
- 0003_alter_challenge_docker_image_alter_challenge_id_and_more.py
- __init__.py
- chal-not-found.html
- challenge.html
- __init__.py
- admin.py
- apps.py
- challenge.json
- models.py
- README.md
- tests.py
- urls.py
- utility.py
- views.py
- pygoatbot.ipynb
- README.md
- style.css
- base.html
- dashboard.html
- index.html
- lab.html
- reset.html
- app.py
- docker-compose.yml
- Dockerfile
- README.md
- requirements.txt
- style.css
- base.html
- index.html
- result.html
- .dockerignore
- docker-compose.yml
- Dockerfile
- main.py
- README.md
- requirements.txt
- 0001_initial.py
- __init__.py
- __init__.py
- forms.py
- models.py
- urls.py
- views.py
- __init__.py
- settings.py
- urls.py
- wsgi.py
- about.html
- base.html
- index.html
- lesson.html
- login.html
- profile.html
- register.html
- docker-compose.yml
- Dockerfile
- entrypoint.sh
- manage.py
- README.md
- requirements.txt
- dev_guide.md
- test.py
- 0001_initial.py
- 0002_auto_20210414_1510.py
- 0003_password_user.py
- 0004_auto_20210415_1722.py
- 0005_auto_20210415_1748.py
- 0006_comments.py
- 0007_auto_20210418_0022.py
- 0008_otp.py
- 0009_auto_20210517_2047.py
- 0010_authlogin.py
- 0011_tickits.py
- 0012_alter_tickits_user.py
- 0013_alter_comments_id_alter_faang_id_alter_info_id_and_more.py
- 0014_sql_lab_table.py
- 0015_blogs.py
- 0016_alter_blogs_blog_id.py
- 0017_cf_user.py
- 0018_cf_user_password2.py
- 0019_af_admin.py
- 0020_af_session_id_alter_af_admin_lockout_cooldown.py
- 0021_csrf_user_tbl.py
- __init__.py
- soln.py
- utility.py
- api.py
- archive.py
- main.py
- blog1.txt
- blog2.txt
- blog3.txt
- blog4.txt
- __init__.py
- main.py
- secret.txt
- test.py
- __init__.py
- readme.md
- common.css
- dark-challenges.css
- dark-theme.css
- home.css
- light.css
- playground.css
- style.css
- a6.js
- a7.js
- a9.js
- pygoat-mini.png
- pygoat-mini.svg
- pygoat-small.png
- pygoat-small.svg
- pygoat.png
- pygoat.svg
- xxe.jpg
- ssrf.css
- ssrf.js
- ssti.css
- xss.js
- fake.txt
- google.jpg
- real.txt
- base.html
- home.html
- a10.html
- a10_lab.html
- a10_lab2.html
- debug.log
- a11.html
- a11_lab.html
- a9.html
- a9_lab.html
- a9_lab2.html
- auth_home.html
- auth_lab.html
- auth_lab_login.html
- auth_lab_signup.html
- auth_success.html
- ba.html
- ba_lab.html
- bau.html
- bau_lab.html
- otp.html
- cmd.html
- cmd_lab.html
- cmd_lab2.html
- data_exp.html
- data_exp_lab.html
- robots.txt
- insec_des.html
- insec_des_lab.html
- sec_mis.html
- sec_mis_lab.html
- sec_mis_lab3.html
- sql.html
- sql_lab.html
- blog1.txt
- blog2.txt
- blog3.txt
- blog4.txt
- secret.txt
- ssrf.html
- ssrf_discussion.html
- ssrf_lab.html
- ssrf_lab2.html
- ssrf_target.html
- xss.html
- xss_lab.html
- xss_lab_2.html
- xss_lab_3.html
- xxe.html
- xxe_lab.html
- broken_access.html
- broken_access_lab_1.html
- broken_access_lab_2.html
- broken_access_lab_3.html
- secret.html
- crypto_failure.html
- crypto_failure_lab.html
- crypto_failure_lab2.html
- crypto_failure_lab3.html
- 0db9c0e7093d.html
- 9d73d120683d.html
- a2538af1b5e4.html
- injection.html
- sql_lab.html
- ssti.html
- ssti_lab.html
- a7.html
- lab2.html
- lab3.html
- desc.html
- lab2.html
- lab3.html
- csrf_dashboard.html
- csrf_lab_login.html
- mitre_lab_17.html
- mitre_lab_25.html
- mitre_top1.html
- mitre_top10.html
- mitre_top11.html
- mitre_top12.html
- mitre_top13.html
- mitre_top14.html
- mitre_top15.html
- mitre_top16.html
- mitre_top17.html
- mitre_top18.html
- mitre_top19.html
- mitre_top2.html
- mitre_top20.html
- mitre_top21.html
- mitre_top22.html
- mitre_top23.html
- mitre_top24.html
- mitre_top25.html
- mitre_top3.html
- mitre_top4.html
- mitre_top5.html
- mitre_top6.html
- mitre_top7.html
- mitre_top8.html
- mitre_top9.html
- index.html
- index.html
- index.html
- login.html
- logout.html
- register.html
- __init__.py
- admin.py
- apis.py
- apps.py
- forms.py
- mitre.py
- models.py
- tests.py
- urls.py
- utility.py
- views.py
- xee_see.txt
- __init__.py
- asgi.py
- settings.py
- urls.py
- wsgi.py
- img4.png
- pic1.png
- pic2.png
- pic3.png
- solution.md
- .all-contributorsrc
- .gitignore
- CHANGELOG.md
- docker-compose.yml
- Dockerfile
- gh-md-toc
- installer.sh
- LICENSE.md
- manage.py
- Procfile
- PyGoatBot.py
- README.md
- requirements.txt
- setup.py
- uninstaller.py
- uninstaller.sh
# Installation Guide
1. Get the code
git clone https://github.com/adeyosemanputra/pygoat
Downloads the entire project code from GitHub to your computer.
cd pygoat
Moves into the project folder you just downloaded.
2. Docker
Easy RecommendedPrerequisites
- Git Needed to download the project code from GitHub.
- Docker Desktop Needed to build and run containers. Install it and keep it running in the background.
docker compose exec web python manage.py populate_challenges
Runs the command against the services defined in the compose file.
2. Build the docker image from Dockerfile using   `docker build -f Dockerfile -t pygoat .`
Builds a runnable image based on the Dockerfile.
3. Run the docker image  `docker run --rm -p 8000:8000 pygoat:latest`
Runs the built image as an actual container.
* [Docker Container](#docker-container)
Type this command into your terminal and run it.
Run docker compose ps to check the containers are Up. If the README mentions a port, open http://localhost:PORT in your browser.
Pulled directly from this repo's README.
3. Python
EasyPrerequisites
pip install -r dockerized_labs/broken_auth_lab/requirements.txt
Installs the Python libraries listed in requirements.txt (or similar).
python manage.py runserver
Starts the Django development server.
If it runs without errors and prints output in the terminal, it worked.
// repository documentation
Was this content helpful?
(0 ratings)
