Revisited to prepare for OSWE! https://github.com/juice-shop/juice-shop.
- Install Docker
- Run
docker pull bkimminich/juice-shop - Run
docker run --rm -p 3000:3000 bkimminich/juice-shop - Browse to http://localhost:3000 (on macOS and Windows browse to http://192.168.99.100:3000 if you are using docker-machine instead of the native docker installation)
# run unsafe mode to enable all challenge
docker run -d -e "NODE_ENV=unsafe" -p 3000:3000 bkimminich/juice-shop- Bonus Payload -
Improper Input Validation - Bully Chatbot
- Confidential Document -
Sensitive Data Exposure - DOM XSS -
XSS - Error Handling -
Security Misconfiguration - Exposed Metrics -
Sensitive Data Exposure - Missing Encoding -
Improper Input Validation - Outdated Whitelist -
Unvalidated Redirects - Privacy Policy
- Repetitive Registration -
Improper Input Validation - Score Board
- Zero Stars -
Improper Input Validation
Old
- Reflected XSS -
XSS
- Admin Section -
Broken Access Control - Deprecated Interface -
Security Misconfiguration - Five-Star Feedback -
Broken Access Control - Login Admin -
Injection - Login MC SafeSearch
- Meta Geo Stalking
- Password Strength -
Broken Authentication - Reflected XSS -
XSS - Security Policy
- View Basket -
Broken Access Control - Visual Geo Stalking
- Weird Crypto -
Cryptographic Issues
Old
- API-only XSS -
XSS - Admin Registration -
Improper Input Validation - Bjoern's Favorite Pet -
Broken Authentication - CAPTCHA Bypass -
Broken Anti Automation - CSRF -
Broken Access Control - Client-side XSS Protection -
XSS - Database Schema -
Injection - Deluxe Fraud -
Improper Input Validation - Forged Feedback -
Broken Access Control - Forged Review -
Broken Access Control - GDPR Data Erasure -
Broken Authentication - Login Amy -
Sensitive Data Exposure - Login Bender -
Injection - Login Jim -
Injection - Manipulate Basket -
Broken Access Control - Payback Time -
Improper Input Validation - Privacy Policy Inspection -
Security through Obscurity - Product Tampering -
Broken Access Control - Reset Jim's Password -
Broken Authentication - Upload Size -
Improper Input Validation - Upload Type -
Improper Input Validation - XXE Data Access -
XXE
- Access Log -
Sensitive Data Exposure - Allowlist Bypass -
Unvalidated Redirects - CSP Bypass -
XSS - Christmas Special -
Injection - Easter Egg -
Broken Access Control - Ephemeral Accountant -
Injection - Expired Coupon -
Improper Input Validation - Forgotten Sales Backup -
Sensitive Data Exposure - GPDR Data Theft -
Senstive Data Exposure - HTTP-Header XSS -
XSS - Leaked Unsafe Product -
Sensitive Data Exposure - Legacy Typosquatting -
Vulnerable Components - Login Bjoern -
Broken Authentication - Misplaced Signature File -
Sensitive Data Exposure - Nested Easter Egg -
Cryptographic Issues - NoSQL Dos -
Injection - NoSQL Manipulation -
Injection - Poison Null Byte -
Improper Input Validation - Reset Bender's Password -
Broken Authentication - Reset Uvogin's Password -
Sensitive Data Exposure - Server-side XSS Protection -
XSS - Steganography -
Security Through Obscurity - User Credentials -
Injection - Vulnerable Library -
Vulnerable Components