Over the course of this capstone project, a full-stack web application using Flask, MySQL, and (potentially, as of 12/1) a combination of Docker, WSGI, and HTTP. This web application is built as a controlled target for iterative penetration testing based on the OWASP Top 10 attack classes. Throughout this process, a meticulous record of development, exploits, mitigations, and secure implementation is created as to provide a reproducible technical report.
The final web application must have user input, a database, toggleable vulnerabilities, user accounts, and user authentication. It must be capable of running on multiple servers. As a stretch goal, the web application will have a database of hashed passwords of different encryption methods with varying algorithmic strengths, where these passwords must be attempted to crack.
Oregon State University - Computer Science Department
Senior Capstone - Website Security Research Project
Fall 2025 to Spring 2026
Dylan Freshman 11/2
Alyce Harlan 11/2
Zoey Adams 11/2
Umer Mansoor 11/3