Top Banner
OWASP Juice Shop 5.x and beyond German OWASP Day-Update 2017 by / Björn Kimminich @bkimminich https://www.owasp.org/index.php/OWASP_Juice_Shop_Project Tweet Follow @owasp_juiceshop Follow @bkimminich Follow @bkimminich 192 Star 587 Like 177
25

OWASP Juice Shop 5.x and beyond

Jan 28, 2018

Download

Technology

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 2: OWASP Juice Shop 5.x and beyond

Logo Facelift (💅)

💅 Because: What could be more important, right? Right?!

Page 3: OWASP Juice Shop 5.x and beyond

Maturity Promotion (🎓)

 Lab  Project 🎓 Review was �nalized at the Project Summit during AppSecEU

Page 4: OWASP Juice Shop 5.x and beyond

Stats, Stats & Stats (📈)Juice Shop

downloadsdownloads 1k/total1k/total downloadsdownloads 2k total2k total docker pullsdocker pulls 157k157k contributorscontributors 2222 closed pull requestsclosed pull requests 191191

Page 5: OWASP Juice Shop 5.x and beyond

Stats, Stats & Stats (📈)Juice Shop

downloadsdownloads 1k/total1k/total

downloadsdownloads 2k total2k total

docker pullsdocker pulls 157k157k

contributorscontributors 2222

closed pull requestsclosed pull requests 191191

Page 6: OWASP Juice Shop 5.x and beyond

Security Questions (🐹)

🐹 Find out in three new challenges what can go wrong with these fantastic security questions added with 4.x

Page 7: OWASP Juice Shop 5.x and beyond

NoSQL Database (📃)

📃 With as an additional NoSQL datastore two new challenges came in with 5.xMarsDB

Page 8: OWASP Juice Shop 5.x and beyond

Typosquatting (🔤)

🔤 Two new challenges from 5.x explain how to trick those with a weak mind (but quick �ngers)

Page 9: OWASP Juice Shop 5.x and beyond

More Languages (🌏)

🌏 Full UI translation available for 17+ languages

Page 10: OWASP Juice Shop 5.x and beyond

Less Docker�le (📦)

📦 Less meaning reduced image size from 900 to 300 MB

Page 11: OWASP Juice Shop 5.x and beyond

≈500 LeanPub Readers (📖)

📖 Find helpful hints in the eBooko�cial companion guide

Page 12: OWASP Juice Shop 5.x and beyond

Google Summer of Code (💔)

💔 OWASP unfortunately was not selected as an organization for GSoC 2017

Page 13: OWASP Juice Shop 5.x and beyond

OWASP Summit (💚)

💚 At OWASP Summit 2017 there were coding & threat modelling sessions in a dedicated track & villa

Page 14: OWASP Juice Shop 5.x and beyond

Logo Variation (🎨)

🎨 But, why create this " -accidentally-pierced-by-straw"-inspired logo?Capri-Sun

Page 15: OWASP Juice Shop 5.x and beyond

CTF Extension (🚩)

🚩 Use to set up an event on in 5minjuice-shop-ctf-cli CTFd

Page 16: OWASP Juice Shop 5.x and beyond

Frictionless CTFs (🚀)

🚀 Participants use individual server instances anywhere, sharing only a �ag code-ctfKey & central score server

Page 17: OWASP Juice Shop 5.x and beyond

Re-branding (🎭)

🎭 Fully business context and look & feel for maximum immersioncustomizable

Page 18: OWASP Juice Shop 5.x and beyond

Upcoming Release 6.x (🔮)Two new 🍪JWT-related vulnerabilities...

...bringing the total to ≥48 challengesOverhaul of the 📍Object-Relational-Mapping...

...and all generated parts of the API

...�xing our two oldest open 🐛bugs along the wayNode.js 8.x is the 🆕recommended version...

...but 6.x will continue to work as well

...and on the 🔥-new 9.x it also runs smoothly

Page 19: OWASP Juice Shop 5.x and beyond

Beyond Release 6.x (🌌)Frontend update to 🍭Angular ≥5...

...or something completely di�erentParticipate in 🌻Google Summer of Code 2018...

...given OWASP is selected next yearGet Juice Shop 🍾promoted to  Flagship  Project ...

...at some point in its lifecycle

Page 20: OWASP Juice Shop 5.x and beyond

Special Thanks (💖)

(CTFd SQLs🚩 / JWT🍪)

Josh Grossman

(Re-Branding🎭 / 🎶)

Timo PagelLoud XSS-Demo

(NoSQL📃 / CTF🌟 / Docker📦 / ORM+📍)

Jannik Hollenbach

Page 21: OWASP Juice Shop 5.x and beyond

Special Thanks (💖)

(CTFd SQLs🚩 / JWT🍪)

(Re-Branding🎭 / 🎶)

(NoSQL📃 / CTF🌟 / Docker📦 / ORM+📍)

Josh Grossman

Timo PagelLoud XSS-Demo

Jannik Hollenbach

Page 22: OWASP Juice Shop 5.x and beyond

Very Special Thanks (💝)

💝 3D-printed Keychain by Viktor Lindström

Page 23: OWASP Juice Shop 5.x and beyond

Very Special Thanks (💝)

💝 3D-printed Keychain by Viktor Lindström