Skip to content

Latest commit

 

History

History
63 lines (41 loc) · 2.15 KB

README.md

File metadata and controls

63 lines (41 loc) · 2.15 KB

Pwning OWASP Juice Shop

Written by Björn Kimminich

OWASP Juice Shop logo

This is the official companion guide to the OWASP Juice Shop application. Being a web application with well over 30 intended security vulnerabilities, the OWASP Juice Shop is supposed to be the opposite of a best practice or template application for web developers: It is an awareness, training, demonstration and exercise tool for security risks in modern web applications. The OWASP Juice Shop is an open-source project hosted by the non-profit Open Web Application Security Project (OWASP) and is developed and maintained by volunteers.

The book is divided into three parts.

Part I - Hacking preparations

Part one helps you to get the application running and to set up optional hacking tools.

Part II - Challenge hunting

Part two gives an overview of the vulnerabilities found in the OWASP Juice Shop including hints how to find and exploit them in the application.

Part III - Getting involved

Part three shows up various ways to contribute to the OWASP Juice Shop open source project.


Please be aware that this book is not supposed to be a comprehensive introduction to Web Application Security in general. For every category of vulnerabilities present in the OWASP Juice Shop you will find a brief explanation - typically by quoting existing sources on the topic. You will also find references to detailed attack descriptions as well as possible mitigations.


Download a .pdf, .epub, or .mobi file from:

Contribute content, suggestions, and fixes on GitHub:

Official project landing page on the OWASP wiki:


CC BY-NC-ND 4.0

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.