Ubuntu

How to install WebGoat on Ubuntu 14.04, 15.04 and 15.10

WebGoat is a deliberately insecure, Java web application designed for the sole purpose of teaching web application security lessons. The officially-stated aim is to enable developers to “test vulnerabilities commonly found in Java-based applications that use common and popular open source components”.

In other words, how to hack Java web applications. This tutorial shows how to install it on any recent version of Ubuntu, like Ubuntu 14.04, 15.04 and 15.10.

WebGoat is maintained by OWASP, the Open Web Application Security Project, and it features a series of lessons that teach different application security and penetration testing techniques.

Before you get started, you might want to first learn the basics of ethical hacking and online penetration testing by requesting a free video course of Online Penetration Testing and Ethical Hacking.

After you’ve completed that course, come back here and learn how to install WebGoat.

WebGoat is a Java application so you need to have a Java JRE installed. To install and verify that a Java JRE is installed on your edition of Ubuntu, launch a shell terminal and type the follow commands. The recommended JRE is 1.7, which is the current available version, so you’ll be covered by installing the default JRE package:

Related Post:  Install Godot game engine on Fedora or Ubuntu

Next, download the executable jar file by running the following command:

After that, you can run it using the following command:

Related Post:  Swap partition out, swap file in on Ubuntu 17.04

Finally, access the web interface by navigating to http://localhost:8000/WebGoat. You should get a login screen just like the one shown in Figure 1, and you can log in as a guest or privileged user using the webgoat account.

WebGoat's login screen
Figure 1: WebGoat’s login screen

Logging in gives you access to a bunch of lessons that allows you to practice pentesting on a live system that you have permission to mess with.

WebGoat's pentest lessons
Figure 2: WebGoat’s interface showing the category of lessons

Here, for example, is the DOM Injection lesson. WebGoat is a cool tool, but don’t take what you learn by using it to hack systems that you don’t own. The point of it is to become familiar with ways that Black Hats can use to compromise your system. If you know the secrets of their craft, you’re in a better position to secure your systems. Happy pentesting! Learn more about WebGoat from the project’s home page.

WebGoat DOM injection lesson
Figure 3: WebGoat’s interface showing the DOM injection lesson

LinuxBSDos needs your donation to continue!

I hope this article has saved you valuable time and effort to fix a problem that would have taken more time than is necessary. That makes me happy, and why I love doing this. But because more people than ever are reading articles like this with an adblocker, ad revenues have fallen to a level that's not enough to cover my operating costs. That's why I want to ask you a favor: To make a one-time or recurring donation to support this site and keep it going. It's a small favor, but every one counts. And you can make your donation using Patreon or directly via Paypal. Thank you for whatever donation you're able to make.

Donate via Patreon. Donate via Paypal.

Aside from donation, you may also signup to receive an email once I publish new content. Your email will not be shared or traded to anyone. And you can unsubscribe at any time.

Please share:

We Recommend These Vendors and Free Offers

Launch an SSD VPS in Europe, USA, Asia & Australia on Vultr's KVM-based Cloud platform starting at $5:00/month (15 GB SSD, 768 MB of RAM).

Deploy an SSD Cloud server in 55 seconds on DigitalOcean. Built for developers and starting at $5:00/month (20 GB SSD, 512 MB of RAM).

Want to become an expert ethical hacker and penetration tester? Request your free video training course of Online Penetration Testing and Ethical Hacking

Whether you're new to Linux or are a Linux guru, you can learn a lot more about the Linux kernel by requesting your free ebook of Linux Kernel In A Nutshell.


2 Comments

  1. Im getting a HTTP 500 status unable to compile class for Jsp when im running the jar file … i don’t know how this came up since ive followed all the steps exactly as said .

Leave a Comment

Your email address will not be published. Required fields are marked *

*