Skip to main content
availability

Package: Invicti AppSec Core (on-demand)

Authorized target scanning policy

Read before launching scans

Before initiating any scans, it's critical to ensure that you have proper authorization to test the target website or web application.

  • Unauthorized scanning is prohibited. Performing scans without consent may result in your IP address and all scan-related activity being logged on the target's web server.
  • Inform stakeholders. If you aren't the sole administrator of the website or application, you must notify all relevant administrators before starting a scan.
  • Be aware of the potential impact. Some scans may cause performance issues or even result in the target system becoming temporarily unavailable, requiring a manual restart.

By proceeding with a scan, you confirm that you've obtained all necessary permissions and accept responsibility for the actions and consequences associated with the scan.

Use Invicti test websites

If you're new to scanning or want a safe environment to experiment in, we recommend using our publicly available test websites. These are designed specifically for safe, controlled scanning and testing, so you can explore Invicti AppSec's capabilities without impacting live systems.

The testinvicti.com test environment provides reliable, comprehensive testing coverage with multiple technology stacks:

NameURLTechnologies
ASP.Net - Testinvictihttp://aspnet.testinvicti.comWindows, IIS, ASP.NET, MsSQL
PHP - Testinvictihttp://php.testinvicti.comWindows, Apache, PHP, MySQL
SPA - Angular - Testinvictihttp://angular.testinvicti.comUbuntu, Apache, PHP, Angular 5, MySQL
API - REST - Testinvictihttp://rest.testinvicti.comUbuntu 18, Apache, PHP 7.1, MySQL
GraphQL - Testinvictihttp://graphql.testinvicti.comUbuntu 22.04, NodeJS, GraphQL
Python - Testinvictihttp://python.testinvicti.comUbuntu 22.04, Flask, CouchDB, nginx
API - Vulnerable APIhttp://vulnapi.testinvicti.comUbuntu, NodeJS, Swagger, SQLite

⚠️ Alternative: vulnweb.com (May have availability issues)

Note: These sites may occasionally be unavailable due to maintenance or infrastructure issues. If you encounter connection problems, please use the testinvicti.com sites above.

NameURLTechnologies
SecurityTweetshttp://testhtml5.vulnweb.comnginx, Python, Flask, CouchDB
Acuarthttp://testphp.vulnweb.comApache, PHP, MySQL
Acuforumhttp://testasp.vulnweb.comIIS, ASP, Microsoft SQL Server
Acubloghttp://testaspnet.vulnweb.comIIS, ASP.NET, Microsoft SQL Server
REST APIhttp://rest.vulnweb.com/Apache, PHP, MySQL

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?