This blog post provides an extensive and updated list (as of October 20, 2011) of vulnerable web applications you can test your web hacking knowledge, pen-testing tools, skills, and kung-fu on, with an added bonus without going to jail 🙂 Vulnerable web applications have been classified in three categories: offline, VMs/ISOs, and online. Since October 18, 2013, this list has been moved to a new OWASP project: “OWASP Vulnerable Web Applications Directory (VWAD) Project “.”]
Source: http://blog.taddong.com/2011/10/hacking-vulnerable-web-applications.html

