Web application security is major concern these days. There are various attacks listed by OWASP and provide Top 10 List over period of time. Preventing from those attacks is real challenge so identifying those attacks are challenge so proposing the test environment to identifying attacks like SQL injection, LDAP injection, OS command injection for the web application or OS. The result will be useful for identifying root cause of security incident and creating self-aware security infrastructure.