Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(sandbox): add more challenges #2655

Closed
lifeforms opened this issue Jun 20, 2022 · 3 comments
Closed

feat(sandbox): add more challenges #2655

lifeforms opened this issue Jun 20, 2022 · 3 comments
Labels
sandbox Sandbox related problems 👍 Feature Request

Comments

@lifeforms
Copy link
Member

lifeforms commented Jun 20, 2022

Motivation

We currently serve the OWASP Juiceshop as a vulnerable application.

In August there will be an on-site live hacking event that would include us as a target. We have not committed fully yet, within 2 weeks we will have to make a decision. Some of our crew would be there to coach the hackers and perform really fast triaging and analysis, since the event is short we have to decide very quickly.

It would be useful to have multiple vulnerable applications in various languages. This could vary from a simple PHP script to a vulnerable app.

Proposed solution

  • Add a PHP vulnerable app or a simple script (vulnerable to SQLi and/or XSS)
  • Find vulnerable apps using other languages/frameworks? Inspiration for vulnerable apps: https://github.com/vulhub/vulhub
  • To be debated: Do we want to kill the Juiceshop?

Alternatives

  • Do nothing!
@fzipi fzipi added the sandbox Sandbox related problems label Jun 26, 2022
@github-actions
Copy link
Contributor

This issue has been open 120 days with no activity. Remove the stale label or comment, or this will be closed in 14 days

@RedXanadu
Copy link
Member

RedXanadu commented Oct 25, 2022

It looks like this still needs to be done in preparation for future bug bounties and similar programmes. Although maybe not urgent. Removing stale label.

@fzipi fzipi removed their assignment Jan 22, 2023
@fzipi
Copy link
Member

fzipi commented Apr 21, 2024

I'm closing this one as challenges are not strictly necessary in the sandbox. In the future we can bring them as GSoC or other ways.

@fzipi fzipi closed this as completed Apr 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
sandbox Sandbox related problems 👍 Feature Request
Projects
None yet
Development

No branches or pull requests

4 participants