Overview
WattzGOAT is an intentionally vulnerable web application built for hands-on security practice. It presents a fictional smart-meter company and customer portal as a training lab rather than a real commercial service.
Learners explore a realistic application surface and practise identifying weaknesses similar to those described in the OWASP Top 10, including broken access control and injection.
Training Features
The lab combines customer and administrator workflows so exercises are not limited to a single vulnerable form. Its main elements include:
- A customer portal with signup, meter dashboard, balance recharge, solar export, bills, and support tickets
- An administrator area for meter management and support-ticket handling
- Forty-eight hidden weaknesses ranging from easier to harder challenges
- A capture-the-flag Progress page that records discovered flags
- A simulated AI assistant containing five bonus flags
Learning Workflow
WattzGOAT follows a capture-the-flag format. Users create an account or use a sample customer account, explore the application, find and exploit weaknesses, then enter discovered flags on the Progress page.
The fictional company, accounts, and data provide a controlled setting for practising techniques that also relate to real web applications.
Setup and Safety
The application runs with its database in a single Docker container and supports Windows, macOS, and Linux hosts with Docker installed. It exposes both encrypted and unencrypted local ports because some exercises specifically require the latter.
Because the application is insecure by design, it should run only on a local computer or a controlled private network. It should never be exposed to the internet, and users should not enter real passwords or personal information. The project also notes that AI tools helped produce some code, so unplanned bugs or security issues may exist alongside the deliberate weaknesses.