Darkly is a project aimed at introducing the fundamentals of cybersecurity in the field of web development. The primary goal is to teach users about the common security vulnerabilities found in websites by allowing them to audit a simple, vulnerable site.
Darkly, web geliştirme alanında siber güvenliğin temellerini öğretmeye yönelik bir projedir. Bu projenin amacı, kullanıcıların basit bir güvenlik açığı bulunan web sitesini denetleyerek yaygın güvenlik açıkları hakkında bilgi edinmelerini sağlamaktır.
Learn about general web vulnerabilities, many of which still exist in popular websites. Understand OWASP (Open Web Application Security Project) and how modern frameworks attempt to mitigate these vulnerabilities automatically.
Web sitelerinde sıkça rastlanan güvenlik açıklarını öğrenin, bu açıkların çoğu günümüzde popüler sitelerde hala mevcuttur. OWASP'ı (Open Web Application Security Project) öğrenin ve modern çerçevelerin bu açıkları otomatik olarak nasıl engellemeye çalıştığını keşfedin.
The project uses an i386 virtual machine, which needs to be properly configured and launched with a specific ISO file. Once configured, access the web challenges by navigating to the provided IP address from the virtual machine.
Proje, doğru şekilde yapılandırılması ve belirli bir ISO dosyası ile başlatılması gereken i386 sanal makinesini kullanır. Yapılandırıldıktan sonra, sanal makine üzerinden sağlanan IP adresine tarayıcıyla giderek web tabanlı zorlukları başlatın.
The goal is to discover and exploit 14 different security breaches within the provided website. For each breach you discover, document your steps and save all the necessary proof in the designated folder. Be prepared to explain your approach during the evaluation. The project will be reviewed by humans, and you may need to demonstrate your findings.
Bu projedeki amacınız, verilen web sitesinde 14 farklı güvenlik açığını keşfetmek ve kullanmaktır. Keşfettiğiniz her açık için adımlarınızı belgeleyin ve tüm kanıtları belirlenen klasörde saklayın. Proje değerlendirilirken bulgularınızı açıklamaya hazır olun. Proje insanlar tarafından gözden geçirilecek ve bulgularınızı göstermelisiniz.
If the mandatory part is completed perfectly, advanced explanations of the breaches you discovered can earn you bonus points.
Zorunlu bölüm mükemmel bir şekilde tamamlanırsa, keşfettiğiniz güvenlik açıkları için ileri düzey açıklamalar bonus puan kazandırabilir.
Virtual Machine (i386) OWASP Vulnerabilities
Sanal Makine (i386) OWASP Güvenlik Açıkları