bWAPP is a PHP application that uses a MySQL database. It helps security enthusiasts, developers and students to discover and to prevent web vulnerabilities. bWAPP, or a buggy web application, is a free and open source deliberately insecure web application. It's also possible to download our bee-box, a custom VM pre-installed with bWAPP. bWAPP helps security enthusiasts, developers and students to discover and to prevent web vulnerabilities. So bWAPP is a test platform for improving your security-testing skills. ITSEC GAMES are a fun approach to IT security education. Everybody heard about Heartbleed and bWAPP integrates a vulnerable version of OpenSSL. BWAPP CSRF Challenges Solutions | Cross Site Request Forgery The CSRF or Cross Site Request Forgery is a web vulnerability, where an attacker tricks the victim's browser to send forged requests to a website which performs certain actions on behalf of the logged in user or the victim. XXE stands for Xml eXternal Entity. Another possible solution is to run application server software that use robust session id generation algorithm like Tomcat or Jetty.