Commando-X/vuln-bank

▲ 1 stars today★ 968⑂ 352

A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews.

About Commando-X/vuln-bank

Commando-X/vuln-bank is an open-source project on GitHub, mainly written in HTML. A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. It currently holds 968 stars and 352 forks with 0 open issues, and was last pushed on an unknown date (repository created unknown).

Project Overview

AI Homed tracks it on the Today's Trending board, currently at rank #68 with 1 new stars today.

GitHub Repository Details

Repository Commando-X/vuln-bank · default branch - · size 0 KB · watchers 0 · source: GitHub REST API and repository README

README

Vulnerable Bank Application 🏦

A deliberately vulnerable web application for practicing application security testing of Web, APIs and LLMs, secure code review and implementing security in CI/CD pipelines.

⚠️ WARNING: This application is intentionally vulnerable and should only be used for educational purposes in isolated environments.

image

Overview

This project is a simple banking application with multiple security vulnerabilities built in. It's designed to help security engineers, developers, interns, QA analyst and DevSecOps practitioners learn about:

Features & Vulnerabilities

Core Banking Features

image

Implemented Vulnerabilities

1. Authentication & Authorization

2. Data Security 3. Transaction Vulnerabilities 4. File Operations 5. Session Management 6. Client and Server-Side Flaws 7. Virtual Card Vulnerabilities 8. Bill Payment Vulnerabilities 9. Merchant Payment API Vulnerabilities 10. AI Customer Support Vulnerabilities 11. GraphQL Vulnerabilities

Installation & Setup 🚀

Prerequisites

Option 1: Using Docker (Recommended)

Using Docker Compose (Easiest)

1. Clone the repository:
git clone https://github.com/Commando-X/vuln-bank.git
cd vuln-bank

2. Start the application:

docker-compose up -d --build

The application will be available at http://localhost:5000

Container recovery behavior

The Docker setup includes a few operational safeguards so the app can recover without manual SSH intervention: This keeps the intentionally vulnerable application behavior intact while making the container lifecycle more resilient.

Local smoke test

You can validate the local runtime wiring without starting real containers:
python3 -m unittest discover -s tests -v

This checks the /healthz endpoint behavior and verifies that start.sh waits for the database and then launches the Flask app. If the Flask app dependencies are not installed in your current Python environment, the /healthz route test is skipped and the startup-script smoke test still runs.

Using Docker Only

1. Clone the repository:
git clone https://github.com/Commando-X/vuln-bank.git
cd vuln-bank

2. Build the Docker image:

docker build -t vuln-bank .

3. Run the container:

docker run -p 5000:5000 vuln-bank

Option 2: Local Installation

Prerequisites

Steps

1. Clone the repository:
git clone https://github.com/Commando-X/vuln-bank.git
cd vuln-bank

2. Create and activate a virtual environment (recommended):

# On Windows
python -m venv venv
venv\Scripts\activate

On Linux/Mac

python3 -m venv venv source venv/bin/activate

3. Install required packages:

pip install -r requirements.txt

4. Create necessary directories:

# On Windows
mkdir static\uploads

On Linux/Mac

mkdir -p static/uploads

5. Modify the .env file:

6. Run the application:
# On Windows
python app.py

On Linux/Mac

python3 app.py

Environment Variables

The .env file is intentionally included in this repository to facilitate easy setup for educational purposes. In a real-world application, you should never commit .env files to version control.

Current environment variables:

DB_NAME=vulnerable_bank
DB_USER=postgres
DB_PASSWORD=postgres
DB_HOST=db  # Change to 'localhost' for local installation
DB_PORT=5432

Database Setup

The application uses PostgreSQL. The database will be automatically initialized when you first run the application, creating:

Accessing the Application

Common Issues & Solutions

Windows

1. If you get "python not found": 2. Permission issues with uploads folder:

Linux/Mac

1. Permission denied when creating directories:
   sudo mkdir -p static/uploads
   sudo chown -R $USER:$USER static/uploads
   

2. Port 5000 already in use:

   # Kill process using port 5000
   sudo lsof -i:5000
   sudo kill 
   

PostgreSQL Issues

1. Connection refused:

2. Authentication failed:
     ALTER ROLE postgres WITH PASSWORD 'your_password';
     

3. Installation errors:

     choco install postgresql --version=17.4.0 -y
     # Use the generated password, or immediately reset it:
     & 'C:\Program Files\PostgreSQL\17\bin\psql.exe' -U postgres -c "ALTER ROLE postgres WITH PASSWORD 'postgres';"
     

4. Database does not exist:

     CREATE DATABASE vulnerable_bank;
     
     createdb -U postgres -h localhost vulnerable_bank
     

Testing Guide 🎯

Authentication Testing

1. SQL Injection in login 2. Weak password reset (bruteforce 3-digit PIN) 3. JWT token manipulation 4. Username enumeration 5. Token storage vulnerabilities

Authorization Testing

1. Access other users' transaction history via account number 2. Upload malicious files 3. Access admin panel 4. Manipulate JWT claims 5. Exploit BOPLA (Excessive Data Exposure and Mass Assignment) 6. Privilege escalation through registration

Transaction Testing

1. Attempt negative amount transfers 2. Race conditions in transfers 3. Transaction history access 4. Balance manipulation

File Upload Testing

1. Upload unauthorized file types 2. Attempt path traversal 3. Upload oversized files 4. Test file overwrite scenarios 5. File type bypass 6. SSRF: Use /upload_profile_picture_url with an internal or controlled URL

Example SSRF Flow

curl -s -X POST http://localhost:5000/upload_profile_picture_url \
  -H "Authorization: Bearer " \
  -H "Content-Type: application/json" \
  -d '{"image_url":"http://127.0.0.1:5000/internal/secret"}'

-> Copy the returned file_path and GET http://localhost:5000/<file_path>

API Security Testing

1. Token manipulation 2. BOLA/BOPLA in API endpoints 3. Information disclosure 4. Error message analysis

GraphQL Testing

1. Run schema introspection against /graphql 2. Manipulate JWT claims to reach admin-scoped analytics 3. Test SQL injection through GraphQL resolver inputs such as accountNumber 4. Observe GraphQL error messages and path disclosure 5. Test large or nested queries for missing depth / complexity controls

Virtual Card Testing

1. Exploit mass assignment in card limit updates 2. Manipulate exchange_rate in /api/virtual-cards/<card_id>/fund to over-credit a card during USD conversion 3. Analyze card number generation patterns 4. Access unauthorized card details 5. Test card freezing bypasses 6. Transaction history manipulation 7. Card limit validation bypass

Merchant Payment API Testing

The public merchant API lets intentionally vulnerable demo apps, such as ecommerce labs, accept payments from Vulnbank virtual cards.

Example Ecommerce Integration Flow

1. Register or log in as a normal Vulnbank user. 2. Create a virtual card and fund it from the user's main balance. 3. Register a merchant integration from http://localhost:5000/merchant/register or by API:

   curl -s -X POST http://localhost:5000/api/v1/merchants/register \
     -H "Content-Type: application/json" \
     -d '{"name":"Demo Ecommerce","email":"merchant@example.com","password":"password123"}'
   

4. Charge the user's Vulnbank card from the ecommerce app using the merchant API key:

   curl -s -X POST http://localhost:5000/api/v1/payments/charge \
     -H "X-Merchant-Api-Key: <MERCHANT_API_KEY>" \
     -H "Content-Type: application/json" \
     -d '{
       "amount": 49.99,
       "currency": "USD",
       "card_number": "4111111111111111",
       "cvv": "123",
       "expiry_date": "12/28",
       "merchant_order_id": "ORDER-1001",
       "description": "Demo ecommerce checkout"
     }'
   

5. View the merchant dashboard at http://localhost:5000/merchant/dashboard, or retrieve payment details with either the API key or the weak merchant JWT:

   curl -s http://localhost:5000/api/v1/payments/<payment_id> \
     -H "Authorization: Bearer <MERCHANT_JWT>"
   

Merchant Payment Attacks To Try

1. Request another merchant's payment history through /api/v1/payments/merchant_id/<merchant_id> 2. Compare /api/v1/payments with /api/v1/payments/merchant_id/<merchant_id> 3. Replay the same charge request multiple times 4. Submit negative payment amounts 5. Trigger detailed decline reasons with invalid CVV, frozen cards, inactive cards, and insufficient balance 6. Attempt SQL injection in merchant login, API key lookup, and raw card lookups

Bill Payment Testing

1. Test biller enumeration 2. Payment amount validation bypass 3. Access unauthorized payment history 4. SQL injection in biller selection 5. Reference number prediction 6. Race condition exploitation in payments

AI Customer Support Testing

Access the AI Chat: Look for the blue chat bubble in the bottom-right corner of the dashboard

Note: The chat widget has two modes:

AI Technology: Uses DeepSeek API for real LLM vulnerabilities, with mock fallback if no API key configured.

1. Prompt Injection Attacks

2. Information Disclosure via AI 3. Authorization Bypass through AI 4. AI System Exploitation 5. Context Injection & Mode Testing 6. Real-World Prompt Injection Techniques

Contributing 🤝

Contributions are welcome! Feel free to:

📝 Blog Write-Up

A detailed walkthrough about this lab and my findings here: 👇 Read the Blog By DghostNinja

(https://dghostninja.github.io/posts/Vulnerable-Bank-API/)

👇 Detailed Walkthrough by CyberPreacher

(https://medium.com/@cyberpreacher_/hacking-vulnerable-bank-api-extensive-d2a0d3bb209e)

Ethical hacking only. Scope respected. Coffee consumed. ☕

Disclaimer ⚠️

This application contains intentional security vulnerabilities for educational purposes. DO NOT:

License

This project is licensed under the MIT License - see the LICENSE file for details.

--- Made with ❤️ for Security Education

GitHub Stars & Activity

968Stars
352Forks
0Open issues
HTMLLanguage

GitHub Popularity

GitHub stars968
Forks352
Open issues0
Primary languageHTML
License-
Stars gained today1
Created-
Last pushed-

Trending History

Daily boardrank #68 · ▲ 1 stars

Related AI Projects

1

cathrynlavery / diagram-design

HTML★ 43,907⑂ 2,840▲ 227 stars
→
2

DozenTwelve / Papermorph

HTML★ 431⑂ 50
→
3
→
4

mattpocock / skills

Shell★ 277,947⑂ 23,273▲ 972 stars
→
5

affaan-m / ECC

JavaScript★ 274,182⑂ 40,904▲ 731 stars
→
6

NousResearch / hermes-agent

Python★ 251,657⑂ 0
→
7

deepseek-ai / deepseek-harness

TypeScript★ 244,544⑂ 0
→
8

n8n-io / n8n

TypeScript★ 206,762⑂ 0
→

More AI Rankings