Skip to content
Cipher Bridge
The one rule. Testing is legal only with the owner's authorisation, because US and UK computer misuse laws turn on it. So Cipher Bridge tests only systems you own or are explicitly authorised to test.

Learn it

Vulnerable sites for testing: where you are allowed to practise

Vulnerable sites for testing exist so learners never need to touch a real system. So the first rule is simple: practise only where you are explicitly invited, and read each platform's rules before you start.

  • Authorisation before any test
  • Plain-English guidance
  • Written scope on every engagement
Vulnerable sites for testing: pick an invited target, read the rules and write it up

Hosted vulnerable sites for testing

These platforms host targets built for practice, with the permission written into their terms. Therefore you can learn without legal risk, provided you stay inside their rules.

PlatformBest forNote
PortSwigger Web Security AcademyWeb application security.Free, with guided labs.
TryHackMeBeginners and structured paths.Guided rooms.
Hack The BoxHarder, realistic machines.Rules on sharing answers.
OverTheWireCommand-line basics.Wargames, free.

Vulnerable sites for testing you run yourself

Some deliberately insecure applications are meant to run on your own machine. For example, OWASP Juice Shop is a modern web shop full of intentional flaws. Also, running it locally means nothing leaves your own hardware.

Is this one of the vulnerable sites for testing?

Tick what is true about the target you have in mind.

Your result appears here as you tick, so you can see what is still open.

The rules for vulnerable sites for testing

Every platform sets limits, so read them first.

  • Attack only the targets listed, never the platform itself
  • Keep self-hosted labs off the public internet
  • Respect rules on publishing answers
  • Never reuse what you learn on a system you do not own

Turning practice into a record

Employers cannot see your practice, so they read your writing instead. Therefore write up each lab clearly, and publish where the platform allows it. In addition, follow a published method such as the OWASP Web Security Testing Guide.

What is never a practice target

A real company's website is not a practice target, even if it looks insecure. Under the UK Computer Misuse Act 1990, scanning it without permission can already be an offence. So stay on invited targets.

Vulnerable sites for testing questions

Are vulnerable sites for testing legal to attack?

Yes, within each platform's rules. That permission is the point of them.

Which vulnerable sites for testing suit beginners?

Guided platforms such as TryHackMe and the PortSwigger academy suit beginners.

Can I test a real site that looks insecure?

No. Without permission that is unauthorised access.

Should I publish my answers?

Only where the platform's rules allow it.

Related guides

Need a real test instead?

If your organisation needs its own systems tested, tell us what you are protecting. A senior practitioner replies within one business day.

Ask about authorised testing