LKWA
Lesser Known Web Attack Lab
Install / Use
/learn @weev3/LKWAREADME
LKWA
Lesser Known Web Attack Lab is for intermediate pentester that can test and practice lesser known web attacks such as Object Injection, XSSI, PHAR Deserialization, variables variable ..etc. Write-ups are welcome. My own walk-through is here .
Installation - Local
Just clone the git with git clone https://github.com/weev3/LKWA and move it to your web server and you are good to go.
- For XSSI, challenge you need to change Allow Override None to Allow Override ALL in apache2.conf file or move apache2.conf file to /etc/apache2/
- For PHAR Deserialization, you need to change phar.readonly = On to phar.readonly = Off in php.ini setting.
Installation - Docker
- Just run
docker-compose upinside the Docker folder and open the browser on http://localhost:3000. - For Docker Hub run
docker pull kminthein/lkwa:latestthen rundocker run -ti -p 3000:80 kminthein/lkwa:latest
Current Vulns
- Blind RCE
- XSSI
- PHAR Deserialization
- PHP Object Injection
- PHP Object Injection via Cookies
- PHP Object Injection (Object Reference)
- SSRF
- Variables variable

Contributors
- Edoardo Rosa (@edoz90)
Related Skills
node-connect
348.5kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
109.1kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
348.5kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
qqbot-media
348.5kQQBot 富媒体收发能力。使用 <qqmedia> 标签,系统根据文件扩展名自动识别类型(图片/语音/视频/文件)。
