Juice Shop Master
This project documents the completion of three self-selected hacking challenges (3-star difficulty) from the OWASP Juice Shop, submitted as part of the practical project "Juice Shop Meister" at Developer Akademie. It covers three distinct vulnerability categories: OSINT-based account takeover, improper input validation, and SQL injection-based information disclosure. Each challenge page contains a step-by-step write-up, an explanation of the underlying vulnerability and its real-world risks, and a link to a short demonstration video. All content is provided strictly for educational purposes.
TOC
URL: https://github.com/HPetersen2/OWASP-Juice-Shop-Master
Checkout this repository to see the code/implementation
Quickstart
- Clone the GitHub repository.
- Start an OWASP Juice Shop instance locally (
docker run -d -p 3000:3000 bkimminich/juice-shop) or use the instance shown in the videos. - Open the page of the challenge you're interested in — each contains the full write-up and video link.
- Watch the linked video (max. 5 minutes each) alongside the write-up to reproduce the steps.
Challenges
| # | Challenge | Category | Difficulty | Video |
|---|---|---|---|---|
| 1 | Reset Jim's Password | OSINT | ⭐⭐⭐ | Watch video |
| 2 | Upload Size | Improper Input Validation | ⭐⭐⭐ | Watch video |
| 3 | Database Schema | Information Disclosure | ⭐⭐⭐ | Watch video |
Educational Purpose Notice
All challenges, exploits, and write-ups in the repository were performed exclusively against the intentionally vulnerable OWASP Juice Shop training application, for educational purposes as part of a security training program. No real personal data, credentials, tokens, or infrastructure information were used or stored anywhere in the repository.