Firing Range is an intentionally vulnerable web application designed to evaluate the real-world effectiveness of web security scanners and training exercises. Deployed as a cloud-friendly app, it aggregates dozens of vulnerability patterns in repeatable, labeled routes so tools can be benchmarked on coverage and noise. The project doesn’t just include simple XSS forms; it spans variants such as DOM-based issues, context-sensitive sinks, template mishandling, CSRF, open redirects, and mixed content problems. Each scenario is crafted to reflect how bugs appear in production—behind frameworks, in odd encodings, or across redirects—so scanners must demonstrate accurate crawling and context understanding. Because the behaviors are stable and documented, teams can run comparative tests over time and quantify regression or improvement in their pipelines. It’s equally useful for human training, giving analysts a safe playground to practice exploitation and triage skills.

Features

  • Curated routes that exercise many classes of web vulnerabilities
  • Realistic variants of issues such as reflected, stored, and DOM XSS
  • Scenarios targeting crawling, context resolution, and encoding edge cases
  • Cloud-friendly deployment for consistent benchmarking runs
  • Clear labeling and repeatability for longitudinal comparisons
  • Suitable for both automated scanner evaluation and human training labs

Project Samples

Project Activity

See All Activity >

Categories

Security

License

Apache License V2.0

Follow Firing Range

Firing Range Web Site

You Might Also Like
MongoDB Atlas runs apps anywhere Icon
MongoDB Atlas runs apps anywhere

Deploy in 115+ regions with the modern database for every enterprise.

MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
Start Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Firing Range!

Additional Project Details

Programming Language

Java

Related Categories

Java Security Software

Registered

2025-10-10