Challenge hunting

This part of the book can be read from end to end as a hacking guide. Used in that way you will be walked through various types of web vulnerabilities and learn how to exploit their occurrences in the Juice Shop application. Alternatively you can start hacking the Juice Shop on your own and use this part simply as a reference and source of hints in case you get stuck at a particular challenge.

In case you want to look up hints for a particular challenge, the following tables lists all challenges of the OWASP Juice Shop grouped by their difficulty and in the same order as they appear on the Score Board.

The challenge hints found in this release of the companion guide are compatible with v17.1.0 of OWASP Juice Shop.

Name Description Hints Solution

API-only XSS

Perform a persisted XSS attack with <iframe src="javascript:alert(`xss)">` without using the frontend application at all.

πŸ’‘

πŸ“•

Access Log

Gain access to any access log file of the server.

πŸ’‘

πŸ“•

Admin Registration

Register as a user with administrator privileges.

πŸ’‘

πŸ“•

Admin Section

Access the administration section of the store.

πŸ’‘

πŸ“•

Allowlist Bypass

Enforce a redirect to a page you are not supposed to redirect to.

πŸ’‘

πŸ“•

Arbitrary File Write

Overwrite the Legal Information file.

πŸ’‘

πŸ“•

Bjoern’s Favorite Pet

Reset the password of Bjoern’s OWASP account via the Forgot Password mechanism with the truthful answer to his security question.

πŸ’‘

πŸ“•

Blockchain Hype

Learn about the Token Sale before its official announcement.

πŸ’‘

πŸ“•

Blocked RCE DoS

Perform a Remote Code Execution that would keep a less hardened application busy forever.

πŸ’‘

πŸ“•

Bonus Payload

Use the bonus payload <iframe width="100%" height="166" scrolling="no" frameborder="no" allow="autoplay" src="https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/771984076&color=%23ff5500&auto_play=true&hide_related=false&show_comments=true&show_user=true&show_reposts=false&show_teaser=true"></iframe> in the DOM XSS challenge.

πŸ’‘

πŸ“•

Bully Chatbot

Receive a coupon code from the support chatbot.

πŸ’‘

πŸ“•

CAPTCHA Bypass

Submit 10 or more customer feedbacks within 10 seconds.

πŸ’‘

πŸ“•

Change Bender’s Password

Change Bender’s password into slurmCl4ssic without using SQL Injection or Forgot Password.

πŸ’‘

πŸ“•

Christmas Special

Order the Christmas special offer of 2014.

πŸ’‘

πŸ“•

CSP Bypass

Bypass the Content Security Policy and perform an XSS attack with <script>alert(`xss)</script>` on a legacy page within the application.

πŸ’‘

πŸ“•

Client-side XSS Protection

Perform a persisted XSS attack with <iframe src="javascript:alert(`xss)">` bypassing a client-side security mechanism.

πŸ’‘

πŸ“•

Confidential Document

Access a confidential document.

πŸ’‘

πŸ“•

Cross-Site Imaging

Stick cute cross-domain kittens all over our delivery boxes.

πŸ’‘

πŸ“•

CSRF

Change the name of a user by performing Cross-Site Request Forgery from another origin.

πŸ’‘

πŸ“•

DOM XSS

Perform a DOM XSS attack with <iframe src="javascript:alert(`xss)">`.

πŸ’‘

πŸ“•

Database Schema

Exfiltrate the entire DB schema definition via SQL Injection.

πŸ’‘

πŸ“•

Deluxe Fraud

Obtain a Deluxe Membership without paying for it.

πŸ’‘

πŸ“•

Deprecated Interface

Use a deprecated B2B interface that was not properly shut down.

πŸ’‘

πŸ“•

Easter Egg

Find the hidden easter egg.

πŸ’‘

πŸ“•

Email Leak

Perform an unwanted information disclosure by accessing data cross-domain.

πŸ’‘

πŸ“•

Empty User Registration

Register a user with an empty email and password.

πŸ’‘

πŸ“•

Ephemeral Accountant

Log in with the (non-existing) accountant acc0unt4nt@juice-sh.op without ever registering that user.

πŸ’‘

πŸ“•

Error Handling

Provoke an error that is neither very gracefully nor consistently handled.

πŸ’‘

πŸ“•

Expired Coupon

Successfully redeem an expired campaign coupon code.

πŸ’‘

πŸ“•

Exposed Metrics

Find the endpoint that serves usage data to be scraped by a popular monitoring system.

πŸ’‘

πŸ“•

Extra Language

Retrieve the language file that never made it into production.

πŸ’‘

πŸ“•

Five-Star Feedback

Get rid of all 5-star customer feedback.

πŸ’‘

πŸ“•

Forged Coupon

Forge a coupon code that gives you a discount of at least 80%.

πŸ’‘

πŸ“•

Forged Feedback

Post some feedback in another user’s name.

πŸ’‘

πŸ“•

Forged Review

Post a product review as another user or edit any user’s existing review.

πŸ’‘

πŸ“•

Forged Signed JWT

Forge an almost properly RSA-signed JWT token that impersonates the (non-existing) user rsa_lord@juice-sh.op.

πŸ’‘

πŸ“•

Forgotten Developer Backup

Access a developer’s forgotten backup file.

πŸ’‘

πŸ“•

Forgotten Sales Backup

Access a salesman’s forgotten backup file.

πŸ’‘

πŸ“•

Frontend Typosquatting

Inform the shop about a typosquatting imposter that dug itself deep into the frontend. (Mention the exact name of the culprit)

πŸ’‘

πŸ“•

GDPR Data Erasure

Log in with Chris' erased user account.

πŸ’‘

πŸ“•

GDPR Data Theft

Steal someone else’s personal data without using Injection.

πŸ’‘

πŸ“•

HTTP-Header XSS

Perform a persisted XSS attack with <iframe src="javascript:alert(`xss)">` through an HTTP header.

πŸ’‘

πŸ“•

Imaginary Challenge

Solve challenge #999. Unfortunately, this challenge does not exist.

πŸ’‘

πŸ“•

Kill Chatbot

Permanently disable the support chatbot so that it can no longer answer customer queries.

πŸ’‘

πŸ“•

Leaked Access Logs

Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to. (Creating a new account with the same password does not qualify as a solution.)

πŸ’‘

πŸ“•

Leaked Unsafe Product

Identify an unsafe product that was removed from the shop and inform the shop which ingredients are dangerous.

πŸ’‘

πŸ“•

Legacy Typosquatting

Inform the shop about a typosquatting trick it has been a victim of at least in v6.2.0-SNAPSHOT. (Mention the exact name of the culprit)

πŸ’‘

πŸ“•

Local File Read

Gain read access to an arbitrary local file on the web server.

πŸ’‘

πŸ“•

Login Admin

Log in with the administrator’s user account.

πŸ’‘

πŸ“•

Login Amy

Log in with Amy’s original user credentials. (This could take 93.83 billion trillion trillion centuries to brute force, but luckily she did not read the "One Important Final Note")

πŸ’‘

πŸ“•

Login Bender

Log in with Bender’s user account.

πŸ’‘

πŸ“•

Login Bjoern

Log in with Bjoern’s Gmail account without previously changing his password, applying SQL Injection, or hacking his Google account.

πŸ’‘

πŸ“•

Login Jim

Log in with Jim’s user account.

πŸ’‘

πŸ“•

Login MC SafeSearch

Log in with MC SafeSearch’s original user credentials without applying SQL Injection or any other bypass.

πŸ’‘

πŸ“•

Login Support Team

Log in with the support team’s original user credentials without applying SQL Injection or any other bypass.

πŸ’‘

πŸ“•

Manipulate Basket

Put an additional product into another user’s shopping basket.

πŸ’‘

πŸ“•

Mass Dispel

Close multiple "Challenge solved"-notifications in one go.

πŸ’‘

πŸ“•

Meta Geo Stalking

Determine the answer to John’s security question by looking at an upload of him to the Photo Wall and use it to reset his password via the Forgot Password mechanism.

πŸ’‘

πŸ“•

Mint the Honey Pot

Mint the Honey Pot NFT by gathering BEEs from the bee haven.

πŸ’‘

πŸ“•

Misplaced Signature File

Access a misplaced SIEM signature file.

πŸ’‘

πŸ“•

Missing Encoding

Retrieve the photo of Bjoern’s cat in "melee combat-mode".

πŸ’‘

πŸ“•

Multiple Likes

Like any review at least three times as the same user.

πŸ’‘

πŸ“•

Nested Easter Egg

Apply some advanced cryptanalysis to find the real easter egg.

πŸ’‘

πŸ“•

NFT Takeover

Take over the wallet containing our official Soul Bound Token (NFT).

πŸ’‘

πŸ“•

NoSQL DoS

Let the server sleep for some time. (It has done more than enough hard work for you)

πŸ’‘

πŸ“•

NoSQL Exfiltration

All your orders are belong to us! Even the ones which don’t!

πŸ’‘

πŸ“•

NoSQL Manipulation

Update multiple product reviews at the same time.

πŸ’‘

πŸ“•

Outdated Allowlist

Let us redirect you to one of our crypto currency addresses which are not promoted any longer.

πŸ’‘

πŸ“•

Password Strength

Log in with the administrator’s user credentials without previously changing them or applying SQL Injection.

πŸ’‘

πŸ“•

Payback Time

Place an order that makes you rich.

πŸ’‘

πŸ“•

Poison Null Byte

Bypass a security control with a Poison Null Byte to access a file not meant for your eyes.

πŸ’‘

πŸ“•

Premium Paywall

Unlock Premium Challenge to access exclusive content.

πŸ’‘

πŸ“•

Privacy Policy

Read our privacy policy.

πŸ’‘

πŸ“•

Privacy Policy Inspection

Prove that you actually read our privacy policy.

πŸ’‘

πŸ“•

Product Tampering

Change the href of the link within the OWASP SSL Advanced Forensic Tool (O-Saft) product description into https://owasp.slack.com.

πŸ’‘

πŸ“•

Reflected XSS

Perform a reflected XSS attack with <iframe src="javascript:alert(`xss)">`.

πŸ’‘

πŸ“•

Repetitive Registration

Follow the DRY principle while registering a user.

πŸ’‘

πŸ“•

Reset Bender’s Password

Reset Bender’s password via the Forgot Password mechanism with the truthful answer to his security question.

πŸ’‘

πŸ“•

Reset Bjoern’s Password

Reset the password of Bjoern’s internal account via the Forgot Password mechanism with the truthful answer to his security question.

πŸ’‘

πŸ“•

Reset Jim’s Password

Reset Jim’s password via the Forgot Password mechanism with the truthful answer to his security question.

πŸ’‘

πŸ“•

Reset Morty’s Password

Reset Morty’s password via the Forgot Password mechanism with his obfuscated answer to his security question.

πŸ’‘

πŸ“•

Reset Uvogin’s Password

Reset Uvogin’s password via the Forgot Password mechanism with the original answer to his security question.

πŸ’‘

πŸ“•

Retrieve Blueprint

Deprive the shop of earnings by downloading the blueprint for one of its products

πŸ’‘

πŸ“•

SSRF

Request a hidden resource on server through server.

πŸ’‘

πŸ“•

SSTi

Infect the server with juicy malware by abusing arbitrary command execution.

πŸ’‘

πŸ“•

Score Board

Find the carefully hidden 'Score Board' page.

πŸ’‘

πŸ“•

Security Policy

Behave like any "white hat" should before getting into the action.

πŸ’‘

πŸ“•

Server-side XSS Protection

Perform a persisted XSS attack with <iframe src="javascript:alert(`xss)">` bypassing a server-side security mechanism.

πŸ’‘

πŸ“•

Steganography

Rat out a notorious character hiding in plain sight in the shop. (Mention the exact name of the character)

πŸ’‘

πŸ“•

Successful RCE DoS

Perform a Remote Code Execution that occupies the server for a while without using infinite loops.

πŸ’‘

πŸ“•

Supply Chain Attack

Inform the development team about a danger to some of their credentials. (Send them the URL of the original report or an assigned CVE or another identifier of this vulnerability)

πŸ’‘

πŸ“•

Two Factor Authentication

Solve the 2FA challenge for user "wurstbrot". (Disabling, bypassing or overwriting his 2FA settings does not count as a solution)

πŸ’‘

πŸ“•

Unsigned JWT

Forge an essentially unsigned JWT token that impersonates the (non-existing) user jwtn3d@juice-sh.op.

πŸ’‘

πŸ“•

Upload Size

Upload a file larger than 100 kB.

πŸ’‘

πŸ“•

Upload Type

Upload a file that has no .pdf or .zip extension.

πŸ’‘

πŸ“•

User Credentials

Retrieve a list of all user credentials via SQL Injection

πŸ’‘

πŸ“•

Video XSS

Embed an XSS payload </script><script>alert(`xss)</script>` into our promo video.

πŸ’‘

πŸ“•

View Basket

View another user’s shopping basket.

πŸ’‘

πŸ“•

Visual Geo Stalking

Determine the answer to Emma’s security question by looking at an upload of her to the Photo Wall and use it to reset her password via the Forgot Password mechanism.

πŸ’‘

πŸ“•

Vulnerable Library

Inform the shop about a vulnerable library it is using. (Mention the exact library name and version in your comment)

πŸ’‘

πŸ“•

Wallet Depletion

Withdraw more ETH from the new wallet than you deposited.

πŸ’‘

πŸ“•

Web3 Sandbox

Find an accidentally deployed code sandbox for writing smart contracts on the fly.

πŸ’‘

πŸ“•

Weird Crypto

Inform the shop about an algorithm or library it should definitely not use the way it does.

πŸ’‘

πŸ“•

XXE Data Access

Retrieve the content of C:\Windows\system.ini or /etc/passwd from the server.

πŸ’‘

πŸ“•

XXE DoS

Give the server something to chew on for quite a while.

πŸ’‘

πŸ“•

Zero Stars

Give a devastating zero-star feedback to the store.

πŸ’‘

πŸ“•

Challenge Solutions

In case you are getting frustrated with a particular challenge, you can refer to the Challenge solutions appendix where you find explicit instructions how to successfully exploit each vulnerability. It is highly recommended to use this option only as a last resort. You will learn a lot more from hacking entirely on your own or relying only on the hints in this part of the book.

Hoping you have a great time solving these challenges.