Skip to main content

Juice Shop Master

This project documents the completion of three self-selected hacking challenges (3-star difficulty) from the OWASP Juice Shop, submitted as part of the practical project "Juice Shop Meister" at Developer Akademie. It covers three distinct vulnerability categories: OSINT-based account takeover, improper input validation, and SQL injection-based information disclosure. Each challenge page contains a step-by-step write-up, an explanation of the underlying vulnerability and its real-world risks, and a link to a short demonstration video. All content is provided strictly for educational purposes.

TOC​

team-collaboration/version-control/githubGithub Tip

URL: https://github.com/HPetersen2/OWASP-Juice-Shop-Master

Checkout this repository to see the code/implementation

Quickstart​

  1. Clone the GitHub repository.
  2. Start an OWASP Juice Shop instance locally (docker run -d -p 3000:3000 bkimminich/juice-shop) or use the instance shown in the videos.
  3. Open the page of the challenge you're interested in — each contains the full write-up and video link.
  4. Watch the linked video (max. 5 minutes each) alongside the write-up to reproduce the steps.

Challenges​

#ChallengeCategoryDifficultyVideo
1Reset Jim's PasswordOSINT⭐⭐⭐Watch video
2Upload SizeImproper Input Validation⭐⭐⭐Watch video
3Database SchemaInformation Disclosure⭐⭐⭐Watch video

Educational Purpose Notice​

All challenges, exploits, and write-ups in the repository were performed exclusively against the intentionally vulnerable OWASP Juice Shop training application, for educational purposes as part of a security training program. No real personal data, credentials, tokens, or infrastructure information were used or stored anywhere in the repository.