Hi @MegaManSec.
Thank you for maintaining the project and saving it from AI slop, highly appreciate the work you've done.
I recently been working on a damn vulnerable nginx reverse proxy project which is now hosted under OWASP VWAD, it was first meant for black-box testing but then I thought of gixy as I been using it while writing the bad configs, and thought maybe it would be helpful to add it here so that anyone testing gixy can directly test it on a vulnerable configuration and see how misconfigs look like in code and get a better grasp on gixy's outputs.
Feel free to check it out, and I'm open to any suggestions from your part
https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/
Have a great time!
Hi @MegaManSec.
Thank you for maintaining the project and saving it from AI slop, highly appreciate the work you've done.
I recently been working on a damn vulnerable nginx reverse proxy project which is now hosted under OWASP VWAD, it was first meant for black-box testing but then I thought of gixy as I been using it while writing the bad configs, and thought maybe it would be helpful to add it here so that anyone testing gixy can directly test it on a vulnerable configuration and see how misconfigs look like in code and get a better grasp on gixy's outputs.
Feel free to check it out, and I'm open to any suggestions from your part
https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/
Have a great time!