Menu

  • Home
  • About
Skip to content

Curiosity Kills Colby

Northwestern Misadventures

Author: codeblue04

Hacking OWASP’s Juice Shop Pt. 55: GDPR Data Theft

Posted on December 20, 2020 by codeblue04

Challenge: 

Name: GDPR Data Theft

Description: Steal someone else’s personal data without using Injection.

Difficulty: 4 star

Category: Sensitive Data Exposure

Expanded Description: https://pwning.owasp-juice.shop/part2/sensitive-data-exposure.html

Read More

Hacking OWASP’s Juice Shop Pt. 54: Login Bjoern

Posted on December 19, 2020 by codeblue04

Challenge: 

Name: Login Bjoern

Description: Log in with Bjoern’s Gmail account without previously changing his password, applying SQL Injection, or hacking his Google account.

Difficulty: 4 star

Category: Broken Authentication

Expanded Description: https://pwning.owasp-juice.shop/part2/broken-authentication.html

Read More

Hacking OWASP’s Juice Shop Pt. 53: Reset Uvogin’s Password

Posted on December 18, 2020 by codeblue04

Challenge: 

Name: Reset Uvogin’s Password

Description: Reset Uvogin’s password via the Forgot Password mechanism with the original answer to his security question.

Difficulty: 4 star

Category: Sensitive Data Exposure

Expanded Description: https://pwning.owasp-juice.shop/part2/sensitive-data-exposure.html

Read More

Hacking OWASP’s Juice Shop Pt. 52: Legacy Typosquatting

Posted on December 17, 2020 by codeblue04

Challenge: 

Name:  Legacy Typosquatting

Description: Inform the shop about a typosquatting trick it has been a victim of at least in v6.2.0-SNAPSHOT. (Mention the exact name of the culprit)

Difficulty: 4 star

Category: Vulnerable Components

Expanded Description: https://pwning.owasp-juice.shop/part2/vulnerable-components.html

Read More

Hacking OWASP’s Juice Shop Pt. 51: Ephemeral Accountant

Posted on December 16, 2020 by codeblue04

Challenge: 

Name: Ephemeral Accountant

Description: Log in with the (non-existing) accountant acc0unt4nt@juice-sh.op without ever registering that user.

Difficulty: 4 star

Category: Injection

Expanded Description: https://pwning.owasp-juice.shop/part2/injection.html

Read More

Hacking OWASP’s Juice Shop Pt. 50: Leaked Unsafe Product

Posted on December 15, 2020 by codeblue04

Challenge: 

Name: Leaked Unsafe Product

Description: Identify an unsafe product that was removed from the shop and inform the shop which ingredients are dangerous.

Difficulty: 4 star

Category: Sensitive Data Exposure

Expanded Description: https://pwning.owasp-juice.shop/part2/sensitive-data-exposure.html

Read More

Hacking OWASP’s Juice Shop Pt. 49: NoSQL Manipulation

Posted on December 14, 2020 by codeblue04

Challenge: 

Name: NoSQL Manipulation

Description: Update multiple product reviews at the same time.

Difficulty: 4 star

Category: Injection

Expanded Description: https://pwning.owasp-juice.shop/part2/injection.html

Read More

Hacking OWASP’s Juice Shop Pt. 48: Access Log

Posted on December 13, 2020 by codeblue04

Challenge: 

Name: Access Log

Description: Gain access to any access log file of the server

Difficulty: 4 star

Category: Sensitive Data Exposure

Expanded Description: https://pwning.owasp-juice.shop/part2/sensitive-data-exposure.html

Read More

Hacking OWASP’s Juice Shop Pt. 47: Forged Coupon

Posted on December 12, 2020 by codeblue04

Challenge: 

Name:  Forged Coupon

Description: Forge a coupon code that gives you a discount of at least 80%.

Difficulty: 6 star

Category: Cryptographic Issues

Expanded Description: https://pwning.owasp-juice.shop/part2/cryptographic-issues.html

Read More

Hacking OWASP’s Juice Shop Pt 46: User Credentials

Posted on December 11, 2020 by codeblue04

Challenge: 

Name: User Credentials

Description: Retrieve a list of all user credentials via SQL Injection.

Difficulty: 4 star

Category: Injection

Expanded Description: https://pwning.owasp-juice.shop/part2/injection.html

Read More

Posts navigation

Older Posts
Newer Posts
Follow Curiosity Kills Colby on WordPress.com

Enter your email address to follow this blog and receive notifications of new posts by email.

Categories

  • Information Security
  • Motorcycles
  • Musings
  • Raspberry Pi projects
  • Wandering

Archives

Follow Curiosity Kills Colby on WordPress.com

Enter your email address to follow this blog and receive notifications of new posts by email.

Categories

  • Information Security
  • Motorcycles
  • Musings
  • Raspberry Pi projects
  • Wandering

Archives

Blog at WordPress.com.
  • Follow Following
    • Curiosity Kills Colby
    • Already have a WordPress.com account? Log in now.
    • Curiosity Kills Colby
    • Customize
    • Follow Following
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...