owasp juice shop 5.x and beyond

25
OWASP Juice Shop 5.x and beyond German OWASP Day-Update 2017 by / Björn Kimminich @bkimminich https://www.owasp.org/index.php/OWASP_Juice_Shop_Project Tweet Follow @owasp_juiceshop Follow @bkimminich Follow @bkimminich 192 Star 587 Like 177

Upload: bjoern-kimminich

Post on 28-Jan-2018

658 views

Category:

Technology


3 download

TRANSCRIPT

Page 2: OWASP Juice Shop 5.x and beyond

Logo Facelift (💅)

💅 Because: What could be more important, right? Right?!

Page 3: OWASP Juice Shop 5.x and beyond

Maturity Promotion (🎓)

 Lab  Project 🎓 Review was �nalized at the Project Summit during AppSecEU

Page 4: OWASP Juice Shop 5.x and beyond

Stats, Stats & Stats (📈)Juice Shop

downloadsdownloads 1k/total1k/total downloadsdownloads 2k total2k total docker pullsdocker pulls 157k157k contributorscontributors 2222 closed pull requestsclosed pull requests 191191

Page 5: OWASP Juice Shop 5.x and beyond

Stats, Stats & Stats (📈)Juice Shop

downloadsdownloads 1k/total1k/total

downloadsdownloads 2k total2k total

docker pullsdocker pulls 157k157k

contributorscontributors 2222

closed pull requestsclosed pull requests 191191

Page 6: OWASP Juice Shop 5.x and beyond

Security Questions (🐹)

🐹 Find out in three new challenges what can go wrong with these fantastic security questions added with 4.x

Page 7: OWASP Juice Shop 5.x and beyond

NoSQL Database (📃)

📃 With as an additional NoSQL datastore two new challenges came in with 5.xMarsDB

Page 8: OWASP Juice Shop 5.x and beyond

Typosquatting (🔤)

🔤 Two new challenges from 5.x explain how to trick those with a weak mind (but quick �ngers)

Page 9: OWASP Juice Shop 5.x and beyond

More Languages (🌏)

🌏 Full UI translation available for 17+ languages

Page 10: OWASP Juice Shop 5.x and beyond

Less Docker�le (📦)

📦 Less meaning reduced image size from 900 to 300 MB

Page 11: OWASP Juice Shop 5.x and beyond

≈500 LeanPub Readers (📖)

📖 Find helpful hints in the eBooko�cial companion guide

Page 12: OWASP Juice Shop 5.x and beyond

Google Summer of Code (💔)

💔 OWASP unfortunately was not selected as an organization for GSoC 2017

Page 13: OWASP Juice Shop 5.x and beyond

OWASP Summit (💚)

💚 At OWASP Summit 2017 there were coding & threat modelling sessions in a dedicated track & villa

Page 14: OWASP Juice Shop 5.x and beyond

Logo Variation (🎨)

🎨 But, why create this " -accidentally-pierced-by-straw"-inspired logo?Capri-Sun

Page 15: OWASP Juice Shop 5.x and beyond

CTF Extension (🚩)

🚩 Use to set up an event on in 5minjuice-shop-ctf-cli CTFd

Page 16: OWASP Juice Shop 5.x and beyond

Frictionless CTFs (🚀)

🚀 Participants use individual server instances anywhere, sharing only a �ag code-ctfKey & central score server

Page 17: OWASP Juice Shop 5.x and beyond

Re-branding (🎭)

🎭 Fully business context and look & feel for maximum immersioncustomizable

Page 18: OWASP Juice Shop 5.x and beyond

Upcoming Release 6.x (🔮)Two new 🍪JWT-related vulnerabilities...

...bringing the total to ≥48 challengesOverhaul of the 📍Object-Relational-Mapping...

...and all generated parts of the API

...�xing our two oldest open 🐛bugs along the wayNode.js 8.x is the 🆕recommended version...

...but 6.x will continue to work as well

...and on the 🔥-new 9.x it also runs smoothly

Page 19: OWASP Juice Shop 5.x and beyond

Beyond Release 6.x (🌌)Frontend update to 🍭Angular ≥5...

...or something completely di�erentParticipate in 🌻Google Summer of Code 2018...

...given OWASP is selected next yearGet Juice Shop 🍾promoted to  Flagship  Project ...

...at some point in its lifecycle

Page 20: OWASP Juice Shop 5.x and beyond

Special Thanks (💖)

(CTFd SQLs🚩 / JWT🍪)

Josh Grossman

(Re-Branding🎭 / 🎶)

Timo PagelLoud XSS-Demo

(NoSQL📃 / CTF🌟 / Docker📦 / ORM+📍)

Jannik Hollenbach

Page 21: OWASP Juice Shop 5.x and beyond

Special Thanks (💖)

(CTFd SQLs🚩 / JWT🍪)

(Re-Branding🎭 / 🎶)

(NoSQL📃 / CTF🌟 / Docker📦 / ORM+📍)

Josh Grossman

Timo PagelLoud XSS-Demo

Jannik Hollenbach

Page 22: OWASP Juice Shop 5.x and beyond

Very Special Thanks (💝)

💝 3D-printed Keychain by Viktor Lindström

Page 23: OWASP Juice Shop 5.x and beyond

Very Special Thanks (💝)

💝 3D-printed Keychain by Viktor Lindström