--- title: "Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop" url: https://appsecpodcast.com/bjorn-kimminich-the-joy-of-the-vulnerable-web-juiceshop/ date: 2018-11-19 duration_seconds: 2190 guests: ["Björn Kimminich"] topics: ["OWASP Projects", "Vulnerabilities and Exploits"] audio: https://www.buzzsprout.com/1730684/episodes/8122663-bjorn-kimminich-the-joy-of-the-vulnerable-web-juiceshop.mp3 transcript: true --- # Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop *November 19, 2018 · 37 min* with [Björn Kimminich](https://appsecpodcast.com/guests/bjorn-kimminich/) on [OWASP Projects](https://appsecpodcast.com/topics/owasp-projects/), [Vulnerabilities and Exploits](https://appsecpodcast.com/topics/vulnerabilities/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122663-bjorn-kimminich-the-joy-of-the-vulnerable-web-juiceshop.mp3) ## Show notes Can an intentionally broken online shop help change an organization’s security culture? OWASP Juice Shop creator Björn Kimminich explains how a realistic application full of vulnerabilities gives developers, testers, and managers a shared way to experience security problems. He traces the project’s origins, describes how real incidents become challenges, and discusses the community that keeps adding new ideas. Chris asks about management awareness demonstrations, capture-the-flag events, deployment options, and the range of challenge difficulty. They also explore what was new in Juice Shop 8 and where Björn hoped to take the project next. The conversation shows how hands-on exploration can connect an abstract vulnerability to something people recognize in their own software, without requiring everyone to begin as an expert. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Björn Kimminich: → [Björn Kimminich on GitHub](https://github.com/bkimminich) → [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/) Mentioned in this episode: → [Juice Shop project website](https://owasp-juice.shop/) → [Juice Shop source code](https://github.com/juice-shop/juice-shop) → [Node.js](https://nodejs.org/) Chapters: 00:00 Learning security with Björn Kimminich and Juice Shop 01:37 Björn’s path from development into security 03:41 Why Juice Shop was created 04:51 What makes an intentionally broken application 05:41 Turning real vulnerabilities into challenges 07:42 The community behind the project 11:04 Who uses Juice Shop and why 13:08 Security awareness demonstrations for managers 14:56 How managers respond to seeing attacks 17:04 Running Juice Shop for capture-the-flag events 19:31 Deployment options 20:29 Trying the demo instance 23:24 Exploring with browser developer tools 25:17 What was new in Juice Shop 8 27:26 Challenges for different skill levels 29:03 The project’s future direction 33:42 Sharing ideas and getting involved ## Transcript *5,956 words · assemblyai* **0:00 Chris Romeo:** Hey folks, season 4, episode 17 of the AppSec Podcast. On this episode, we're joined by Bjorn Kimminich, the lead for the OWASP Juice Shop project. Juice Shop is a vulnerable web application written entirely in Node, and it is a great way to impact the security culture inside any organization by letting developers actually put their hands on and test a vulnerable web application to find problems and then really experience things like cross-site scripting, SQL injection. So we hope you enjoy this conversation with Bjorn where he gets into what is Juice Shop, and he also talks about the latest release and some of the cool things that are up and coming in the Juice Shop world. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. I am actually very excited today to be talking with one of the primary authors of one of my favorite OWASP projects called Juice Shop. And so joining us today is Bjorn, who is— are you the primary project lead, Bjorn, or are you— is there other people? **1:37 Björn Kimminich:** Yes, I am. **1:37 Chris Romeo:** You're the primary one. Wow. This is the guy behind the Juice Shop. And so, but before we get into that, on the AppSec Podcast, we always start by asking people, what's your security origin story? If there was a comic book about Bjorn, What does episode 1 look like in regards to security? **1:55 Björn Kimminich:** Okay, yeah, so hi guys, um, my name is Björn, Björn Kimminich, and, um, well, my security origin story is mostly a developer origin story. So I started programming when I was like 12 years old or something and kept doing that for a big portion of my professional career. And at some point I basically went from developing web applications more into the architecture perspective. So right now I'm working for a big logistics company, and as an architect, you're somewhat also responsible for security topics. And I was for a couple of years responsible for the AppSec part of one of our biggest web applications. And from there, I basically went to teaching developers the, let's say, AppSec basics. And right now, I'm basically dealing with security most of my time, but completely focusing on AppSec. And I would still consider myself 100% of a builder, and I'm not a pentester, and I'm not certified in any security stuff or anything. **3:09 Chris Romeo:** Yeah. And you're actually based in Germany? **3:14 Björn Kimminich:** Yes, I'm based in Germany, in Hamburg. **3:15 Chris Romeo:** Very cool. Very cool. And that's— there's a strong OWASP presence in Germany as well, right? **3:20 Björn Kimminich:** Yes, there is actually. So we have this little different setup than other countries do. So we only have one big OWASP chapter for the entire country. And then we have so-called Stammtisch segments in major cities. And they meet every month mostly and are pretty popular actually. **3:41 Chris Romeo:** Yeah, very cool. And so, you kind of made this journey from developer to architect to security, and I'm guessing that all of those things really contributed to kind of what made you kind of think about kicking off the Juice Shop. So, would you say that you were influenced by kind of wanting to solve this problem based on the background you had across, you know, kind of a diverse background? **4:08 Björn Kimminich:** Well, what I actually wanted to do is give my developers who attended my trainings a better exercise environment. Because in the past, I used— I don't know if you know it— the Budget Store, which is a really, really old vulnerable application. Yeah, I do. Also some online website. I think it was provided by a big company who sells security tools. I mean, that was just outdated at some point. So, I wanted to have something new, and I also never wrote any pure JavaScript applications, so I thought, okay, why not write my own little broken web app? **4:51 Chris Romeo:** Yeah. So, when we think about the juice shop, then we refer to it as a broken web app. What does that actually mean that it's a broken web app? **5:03 Björn Kimminich:** So that means if you just use it in a nice and normal way, then it looks like a regular e-commerce application. So it's an actual working web shop where you can buy juice, obviously, and related products. So you can register. You can log in. You can put stuff into your shopping basket, everything that you would expect. And everything works except for the part where I send you the actual products. That is the only thing that doesn't happen. But everything else actually works. And, um, but in the behind the scenes, it's a complete disaster from a security perspective. **5:41 Chris Romeo:** That's a— that's a— I think that's a great way to describe a broken web application, just a complete disaster. So how much of this is based in real life? Like, like, you know, sometimes they have that made-for-TV movie that says it was influenced by, you know, a true story. Like, where is that? Is that how Juice Shop is? Is it based on things you've seen in the past that are like really bad? **6:03 Björn Kimminich:** Yes, it definitely is. So, um, I mean, it has the obvious things that you would expect. So some, some classical cross-site scripting, SQL injection, that kind of stuff. But it also has a lot of, uh, more complex problems, uh, authorization issues and, and, and other things, uh, business logic flaws which you which you really cannot make up. So you really have to steal those from real experience or from things you saw on, on the news. So that's also something I like to do when I— when some new nice vulnerability is being, uh, published, then I try to integrate it somehow also into the Juice Shop. **6:44 Chris Romeo:** Yeah, so give us, give us an example of one that you've recently integrated that was based on something kind of in real life, a juicy new vulnerability. **6:53 Björn Kimminich:** ability. One of the newest ones is this— what is it called? Ziploc, this file upload thing where you could put commands or file traversal, path traversal into a zip library or zip archive. One developer on the Juice Shop actually made a challenge out of that, like, I guess, maybe 2 weeks after that was published. So that's what went into the Juice Shop really quickly. Another example is a supply chain attack. So basically not a vulnerability of the application itself, but a vulnerability in one of the libraries that only the developers typically get on their machines when they work on this application. And that is also vulnerable and could actually be exploited, or at least we make it look like it could be. **7:42 Chris Romeo:** Yeah, and that's one of the things I love about G-Shop is that you you, and I want to talk about the team as well. That's kind of— I know there's other people behind you that are helping to drive this, but one of the things that I love is the fact that you are constantly updating it and adding those new challenges to it, which makes the Juice Shop kind of a living vulnerable application environment versus something that just has, you know, 10 challenges and then, you know, it's not going to be updated for a number of years. So, who is the— when you talk about the team, What does the team actually look like as far as how many people are behind Juice Shop? **8:15 Björn Kimminich:** So we are 3, let's say, core contributors. So that's me, and that's Timo and Yannick, also from Germany, from Hamburg or nearby Hamburg. So they contributed some major new features to the Juice Shop some time ago, so like a CTF mode and customization feature. So they are basically my my main support crew. **8:44 Chris Romeo:** Okay. **8:45 Björn Kimminich:** And then the Juice Shop actually participated in the Google Summer of Code this year with the OWASP Foundation. **8:52 Chris Romeo:** Okay. **8:53 Björn Kimminich:** So we had 2 students from India, Shoaib and Ashish, and they both did big, big, big work towards the 8.0 release that we just put out. **9:07 Chris Romeo:** Very cool. **9:07 Björn Kimminich:** And otherwise, I think in total we had, I think GitHub says we had like 40 contributors in total. Some of them small changes, some of them medium changes, but yeah. Those are the main contributors, I would say. **9:23 Chris Romeo:** Yeah, I think of Juice Shop outside of some of the big OWASP projects that are document-based like the top 10. I think of Juice Shop as one of the more active projects from across the community. And, and 40 contributors historically is, is a nice number of people that are, that are getting involved and getting behind it. So I think that's pretty cool. **9:42 Björn Kimminich:** Especially because it's only, uh, started, uh, I think in 2014. So, and it didn't, it didn't even start as an OWASP project. So it started as a private project of my own and became an OWASP project 2015. So it's just 3 years in OWASP and already that many contributors and it already got promoted to flagship, which is really nice. So. **10:04 Chris Romeo:** Yeah, congratulations for that too. And that's a— **10:06 Björn Kimminich:** Yeah, thanks. **10:07 Chris Romeo:** That just reinforces— **10:09 Björn Kimminich:** That's pretty big. **10:09 Chris Romeo:** All the work that you put in. And I gotta tell you this, like, you seem to be the person who never sleeps because I see you on the OWASP channel, the GShop channel all the time. And I know some of those things are coming from build bots and stuff, but like, it seems like— **10:24 Björn Kimminich:** Most of it, yes. **10:25 Chris Romeo:** But a lot of the time it seems like you're working on this 24/7. So I guess the first question is, do you sleep? Or just work on this all the time? **10:31 Björn Kimminich:** Well, I have to squeeze off a lot of time from my otherwise, which I would otherwise probably use for gaming or other stuff. **10:38 Chris Romeo:** Ah, okay. **10:39 Björn Kimminich:** And sometimes my family also complains, but— **10:42 Chris Romeo:** So does your family, when they hear Juice Shop, is your family still impressed or are they like, ugh, more of this Juice Shop thing? **10:49 Björn Kimminich:** My daughter actually is, and she actually contributed one of the images I'm using in the product list of the Juice Shop. Ah, that's cool. she drew a pretty picture of the Juice Shop logo, and we're actually selling that. **11:04 Chris Romeo:** Okay, very cool. That's very awesome that she's getting involved with kind of this project here. So kind of stepping back again, I know I feel like we kind of really covered the what is Juice Shop quite well. I feel like I've got a lot better idea now. When we think about why, so why Juice Shop? I know you mentioned the fact that, you know, you wanted to give developers a better exercise environment, but Tell me more about the why behind this project. **11:32 Björn Kimminich:** My goal was actually to have an application that immediately tells you when you did something right. In that case, it means when you broke something or when you found a vulnerability actually. The budget store did that, and basically that's where I stole the idea of having a scoreboard which shows you what you already practically solved. But the Juice Shop took that a little bit further with notifications popping up whenever you solved a challenge. So the main driver actually was trainings. And later, there were initial use cases we didn't really think about in the first place, like awareness sessions, for example. So I already used the Juice Shop in my own company and also at other places. to give awareness sessions for managers, for example, from IT management. That's one big other use case which might even more important than teaching developers about security. Yeah. **12:37 Chris Romeo:** I think I saw the awareness sessions for managers, did that involve a YouTube video? **12:43 Björn Kimminich:** There is a YouTube video which shows some pretty nasty cross-site scripting. Sometimes I show that, sometimes I don't. But it's pretty loud, actually. So the Juice Shop is starting to dance and the user interface is doing weird stuff. **13:03 Chris Romeo:** Yeah, that's the one I'm thinking of, yeah. **13:05 Björn Kimminich:** A keylogger is involved. **13:06 Chris Romeo:** Yeah, okay. **13:07 Björn Kimminich:** Really bad. **13:08 Chris Romeo:** So how do you use Juice Shop then as an awareness session for managers? I want to poke at that a little bit more. So what— like, how are you— What are you showing them that's making them aware? **13:18 Björn Kimminich:** Yeah, so I have different levels depending on how technical the audience is. So on the highest level, what I show is, hey, this is just a regular webshop, and I show how it works and don't show any vulnerability actually. Then I ask them to, or ask one of them to actually register their own user and put some stuff into the shopping basket, so play around with it. What I afterwards do is, demonstrate how I can then break into their account. So the first thing I try is getting their password back from the password hash, which is happily exposed by the juice shop in different ways. **13:57 Chris Romeo:** Yeah. **13:58 Björn Kimminich:** That in many cases doesn't work. So then I will go to check if they chose a stupid security question to answer and actually answered them truthfully. So like, what's your favorite pet's name? Typically, I cannot break that, but I can at least explain, hey, there's only so many names pets typically have in a given country. So it's like maybe if I would have the time to try 100 times, I would probably get it. But then in the end, I mostly show it with SQL injection. Like, okay, if I know your email address, I don't have to know your password, I get just in. So that's one way I like to show. If they choose to register with their Google account, there's a little bit more technical way to be that, but that's also something that managers can understand if you show them because the Juice Shop behaves really silly after doing a proper OAuth 2 authentication with Google. Okay. **14:56 Chris Romeo:** And what are the results that you see? Like, how do managers respond to you when you show them these things? What are their feedback? **15:03 Björn Kimminich:** They typically find it very interesting and often also very scary, especially when I tell them that, hey, in our company and probably in most other companies, we have also applications which behave like that. So if you look long enough or search long enough, then you wouldn't actually— you might not even need a juice shop because your own applications might be enough to show all those vulnerabilities because most of them are available in one application or the other. **15:32 Chris Romeo:** Yeah. And you find most of these people that you're showing this demo to, is this really their eye-opening moment? Like they didn't they didn't really understand the depth of vulnerabilities that exist in web apps before you showed them the demo? **15:46 Björn Kimminich:** Yeah, it depends. So if someone comes in with a— let's say with more of an infrastructure background, so they understand the concept of a firewall and how that makes your network secure and that kind of stuff, so they understand how a VPN works, for example, then they often think, OK, I mean, we have all this expensive security equipment and Why does this guy tell us now that it actually doesn't make us really secure because there's a way to get through all this and just attack your whole nice IT equipment through port 80 or 443 and it's game over? That's often, that's kind of an eye-opening moment. **16:25 Chris Romeo:** After the break, we hear from Bjorn about what is CTF mode and how do we use it? The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. So Bjorn, what is CTF mode and how do we use it in the Juice Shop? **17:04 Björn Kimminich:** Okay, so yeah, CTF mode, that was actually an idea that Yannick and one other developer had. So they wanted to use the Juice Shop in, I think, at conferences to let people hack it and give out some small prizes for those for those who found the most vulnerabilities. So essentially what the Juice Shop offers is just a mode where you start it and the little notifications that pop up when you solve a challenge will then contain a long string which is basically your solution code. **17:42 Chris Romeo:** Okay. **17:43 Björn Kimminich:** For that challenge. So what you need then is an external CTF server, so basically a score server like CTFD, which is also open source, for example. **17:54 Chris Romeo:** Okay. **17:55 Björn Kimminich:** And then you can take that code and paste it into CTFD to solve the challenge over there. And then that's where basically the overall score is kept, right, for every participant in the CTF. **18:05 Chris Romeo:** Okay, so you only had to extend the Juice Shop a little bit to give up that code, and then it allowed you to kind of outsource the capture the flag management platform to the other open source project. **18:19 Björn Kimminich:** Exactly. But what we did, which is the real benefit coming from our side, we created a little side project which is a command line tool which you just run and then you answer a couple of questions like, hey, what CTF framework do you want to use? Can you give us the URL of your Jupyter instance you're running? Do you want hints to be available or not? In like 10 seconds, you can generate a zip file which you can then upload to one of these score servers and import it there. And it will basically generate and set up all the challenges and all the stuff over in the CTF framework. So you don't have to create the challenges manually. You don't have to deal with the— the codes will of course be the right ones that the Juice Shop creates and they will match the ones on the score server. **19:10 Chris Romeo:** Okay. **19:11 Björn Kimminich:** So everything will be— I'm always teasing that you can set up a complete CTF environment in 5 minutes if you're using these, these tools. **19:19 Chris Romeo:** No, that's nice. And that's— I, and I've seen that throughout your approach to Juice Shop. So, you know, I've actually used your one-click deploy on Heroku for the Juice Shop. **19:29 Björn Kimminich:** Yeah, that's, that's really sweet. **19:31 Chris Romeo:** Yeah, I mean, and so talk a little bit about that for people that might want to get started with the Juice Shop. I love the fact that you've made it so easy, but I'd rather have you tell that story. **19:38 Björn Kimminich:** Okay, so, um, yeah, you can, you can deploy the Juice Shop in different ways. So you can install it locally on your computer if you have no Node.js, that works. You can run it in a Docker container, that also works fine. And there's some options for cloud deployment. And the easiest one is actually with Heroku. So Heroku offers a little button that you can include into the README of your GitHub projects. And when you click that button, you are forwarded to Heroku and they actually— you only need to log in and click, I think, one or two buttons and they will spin up a machine for you, pull that Git repository, start the application, and give you back the URL where you can then reach it. And that is really quick, and it's totally convenient. So that's the easiest and quickest way to get a Juice Shop instance running, actually. **20:29 Chris Romeo:** Yeah, and then you also have a demo instance running as well, right? **20:32 Björn Kimminich:** Yes, exactly. I have a permanent Heroku instance which is running. for free, which is nice for open source projects. Yeah, yeah. **20:41 Chris Romeo:** And I've pointed people towards the demo instance as well as just one place to— if you want to experience it, you can just jump right into it and it's very easy. What's the URL for the demo? **20:53 Björn Kimminich:** The URL is juice-shop.herokuapp.com. **21:01 Chris Romeo:** Okay, we'll put that in the show notes as well. We want the action— call to action coming out of this is we want more people to go and use Juice Shop. **21:09 Björn Kimminich:** Yeah, somewhere in the README, I've written that people are not supposed to hack that instance, but for some reason, I always find some challenges solved there on the scoreboard. **21:19** So— **21:19 Björn Kimminich:** Yeah. The one important note, the Juice Shop is not built to be used by different users at the same time actually. So if someone is hacking on the demo machine, there might be some confusion with what other people also do at the same time. So in CTFs or also when you use it in trainings, every participant actually has to have their own Juice Shop instance. So they have their own score tracking, their own challenge solutions popping up and that kind of stuff. So that's the way how it works best. **21:53 Chris Romeo:** Yeah, and that's the one time that I've actually used this. We had a special training event for the OWASP Raleigh chapter that I'm a part of. **22:03 Björn Kimminich:** Uh-huh. **22:04 Chris Romeo:** We did it over lunchtime because we wanted to engage a particular population of developers. So, we spun up a Juice Shop instance on Heroku with the button, the easy button I'll call it, for each of the teams that was operating there. I had 8 teams running with about 4 developers and then 1 security person at each table. They were working together on solving the challenges from 1 laptop and collaborating back and forth. And so, that's just another use case that I've actually used firsthand that was really valuable. And I'll tell you what, I learned a lot. So, security people that are listening to this, set up one of these hackathons that I just described right there. Join one of the teams with a couple developers and just sit there quietly and watch them tear a web application apart with the tools and techniques that they have. **22:54** Yeah. **22:55 Chris Romeo:** My mind was blown. I thought I knew a pretty good amount about, you know, pen test, app pen testing and how web apps actually work. And these folks were just bringing out tools and just tearing this thing apart and looking at it in different perspectives. And I was just, so I think there's a lot of value for us as security people to learn from developers based on how they actually debug tools because it turns out all their debug methods are how they found most of the vulnerabilities that were in the Juice Shop. **23:24 Björn Kimminich:** Yeah, you can do a lot of stuff just with a browser and the DevTools. That's all I want to say. **23:31 Chris Romeo:** Yeah, it was very powerful to see that. **23:34 Björn Kimminich:** In trainings, I'm not teaching any hacking tools actually. So I'm not— because I think if the developers should learn actually how the vulnerabilities work, they should concentrate on that and use tools they actually know and not try to learn tools at the same time. So that's— you can essentially hack everything in the juice shop just with a browser and maybe some API client or API testing tool. So that's all you actually need, and you need some internet research, but that's it. **24:05 Chris Romeo:** Yeah, no, that's good. I'm glad that's your perspective as well because, you know, one of my passions is how do we— which I think is the same and I know is the same passion you share here as far as how do we reach developers and get them to focus in on security and putting their hands on the keyboard is priceless. **24:24 Björn Kimminich:** Yes. **24:25 Chris Romeo:** I can lecture for 8 hours about SQL injection, and they'll pay attention for about 15 minutes, and then the rest of the day is just them listening to me drone on about the history of SQL injection. But as soon as they put their fingers on that keyboard and start typing away, it's like, wow, now they're working the way they work, in their flow, in their process. That's where that true magic of learning happens from my perspective. And GShop does a great job, best thing I've seen out there as far as being able to tap into that whole experience-based learning. **24:58 Björn Kimminich:** Yeah, I guess it's good that it's actually a realistic application, right? So that's why it feels real. And so that many developers can actually relate to what they find and think about, hmm, maybe my own application has the same issue as well. **25:17 Chris Romeo:** Yeah, yeah. And so let's talk for a minute about 8.0. I know that just dropped a few days ago from the time that we're actually recording this interview. So what's new in 8.0, new and cool stuff? **25:30 Björn Kimminich:** So 8.0 is our latest major release. And basically, I could have called it the Google Summer of Code release because it contains the 2 student projects that that have been done. So the first one is a complete migration of the frontend. So previously, in everything up to 7 point something, we used AngularJS, so the old Angular framework. And we used Bootstrap for the layout. And this was completely rewritten into Angular, so the new Angular version 7 it is now. **26:11 Chris Romeo:** OK. **26:12 Björn Kimminich:** And using Google's Material Design for the layout now. So that was a big effort and complete rewrite in the end. And the second student project was a so-called challenge pack. So the student added 9 or 10 new hacking challenges, some of them really, really crazy difficult. So there's now something included which requires you to reverse engineer some malware that we actually created, which is not really malicious, but it fakes being malicious, to actually be able to solve a challenge, which is mind-blowingly crazy. So it's completely different. It doesn't have anything to do with web pentesting anymore. So it's basically reverse engineering now. So we try to include a lot of stuff. new remote code execution ways, there's race conditions, there's all kinds of things that are in the new version. Mostly very difficult challenges, but we also added some easy ones to give everyone a fresh new challenge to solve. **27:26 Chris Romeo:** That's one of the other things I like about Juice Shop is the fact that you have challenges at different levels of difficulty, because in my experience working with developers, some developers really dive headfirst into this and really get into it, and they'll die— they'll get into those harder challenges. **27:44 Björn Kimminich:** Yep. **27:45 Chris Romeo:** But others aren't— don't— just don't have that natural drive towards wanting to know everything about security. And so— and that's okay. We want to— we want— we want to capture both of those audiences and have them get value out of it. And so that's something I love about Juice Shop is that you've got something for the people who are just kind of scratching the surface, and you've got some stuff for people that are really diving in deep into this whole process. **28:08 Björn Kimminich:** Yeah, and that's also one thing I always ask my training attendees afterwards as feedback. Do you think that our difficulty rating is correct, or do you think one challenge needs to be rated higher or lower or something? So we try to adjust the ratings to something— not to what we think as the authors of the Juice Shop, but to what actually the users think how difficult something is. So that's I guess at the moment it's quite okay. Some things are a bit overrated maybe, but we can tune them down. At some point we had to actually add— we started with difficulty 1 to 5 stars, and now we have 6 because it didn't work any other way because there were so difficult new challenges we couldn't put them on the same level anymore. **29:00 Chris Romeo:** That's the benefit of being your own architect. **29:02 Björn Kimminich:** for your own solution. **29:03 Chris Romeo:** You'd be like, you know what, we're just going to add a 6-star and that's going to be okay because I'm the architect and I can do that if I want to. So, where's Two Shop going in the future here? You know, you're the project lead. What is your vision for the next couple of years with this project? **29:19 Björn Kimminich:** So, one thing I would really like to do, but I guess it's pretty hard to get that, is something like a guided a guided or assisted hacking mode. So there's a GitHub issue actually for that, which has some fake screenshots which I made. So the idea is that you get this annoying little helper like Clippy from some time ago. **29:50 Chris Romeo:** For those people that don't know who Clippy is, look it up on Google. It's a Microsoft thing, used to exist in Office, and we'll leave it at that. **29:58 Björn Kimminich:** It's awesome. Yes. And so this little helper or assistant guides you through some of the probably the easier challenges. So telling you, okay, hey, there's an input field and hey, type in your name and see how the application behaves. And when you did that, then it might tell you, hey, now try to put in some HTML tag along with your name and see what happens then. And then essentially over a few steps, the assistant shows you how to solve one of the easiest cross-site scripting challenges and maybe the same for some SQL injection and one or two other challenges. So you basically get going when you don't have a trainer in the room who actually teaches you all the stuff. So you can use the Juice Shop more alone in a room if you just want to play with it. **30:46 Chris Romeo:** Yeah. **30:47 Björn Kimminich:** So some people already struggle with finding the scoreboard because that's actually one of the 1-star challenges to actually find the scoreboard in the application because it doesn't have a visible link. Somewhere. But obviously, there's a hidden place where you can actually see it. And yeah, this is also something that this little assistant could actually help you with. Like, hey, click here and click View Source and then scroll down a bit and maybe you'll find something interesting. Yeah. That's one thing I think is nice. And it would be a nice change to just adding more difficult and even harder challenges to do something for the— for the newbies, basically, who have no prior experience and no one to teach them, actually, at the moment. So that's one of my goals. And otherwise, well, let's see how Google continues with Angular. So I hope I don't have to spend too much time doing frontend migrations anymore because that was not fun. **31:52 Chris Romeo:** No, I don't imagine it was. It doesn't sound like an enjoyable process. **31:56 Björn Kimminich:** No, no, no, definitely not. Yeah, other than that, at the moment our roadmap is quite empty with this latest major release. So we're always happy to get new ideas. One request that I often get is, hey, now you have all these great broken things in your application. Why don't you add some new mode where you can then fix those challenges? And actually, the Juice Shop rates if you fix it correctly or not. And that's something that I think will— that won't be possible easily because many of the challenges are built into the Juice Shop in a very dedicated way. So if I would just show the source code for that, it would look weird because it's just checking for some random condition and there's nothing really to fix. **32:51 Chris Romeo:** Right? Yeah. **32:52 Björn Kimminich:** So this is something that might end up at some point in a side project, for example, where you basically have the same challenges that the juice shop offers, but basically reverse them into fixing challenges. But I think I will not include that directly in the juice shop because it will break the concept and basically— put too much responsibility into that one place. But that could actually be a second application and the juice shop could link to that. If you solved a challenge, then there could be a button like, hey, do you want to solve the fixing challenge now? And then you jump over to the other application. **33:33 Chris Romeo:** Yeah. **33:34 Björn Kimminich:** But I'm not sure if I would want to be the project leader for that actually, so. **33:37 Chris Romeo:** That's another— it seems almost as big as the juice shop in general. **33:41 Björn Kimminich:** Yes, exactly. **33:42 Chris Romeo:** Yeah, so where can people get in touch with you? Online, what's the best way if somebody has feedback about Juice Shop or they have a new idea about some feature and they're like, we should— it would be really cool if Juice Shop did this. Where— how do you want them to reach out and connect with you? **33:56 Björn Kimminich:** So the easiest is to just check out our vanity domain, which is owasp-juice.shop, and that will redirect you to the official project wiki page, which has all the contact channels for the Juice Shop itself. So Juice Shop, of course, has its own Twitter, account. It has a Facebook page. It has— there's a Gitter chat, so— and where you can just join with your GitHub account and ask questions. We have a Slack channel on the OWASP— on the official OWASP Slack. And otherwise, everyone can, of course, write an email to me or just hit me on my own private Twitter account as well. So— **34:37 Chris Romeo:** Okay. **34:37 Björn Kimminich:** I think it's not hard to reach me. **34:40 Chris Romeo:** Yeah, I think you're like the most connected person in OWASP. here, given that you had just 12 different ways for people to contact you here, which is awesome because— **34:48 Björn Kimminich:** We even have a mailing list. I think it has 3 subscribers and that includes myself. So, I stopped promoting that at some point. **34:58 Chris Romeo:** Yeah, I can see why. It's about quality. It's quality postings, not about the quantity of subscribers that we have on that list. **35:09** at all. **35:09 Chris Romeo:** So Bjorn, thank you so much. From, you know, I don't know that I can speak for the whole community, but I'm going to anyway. Thank you for all the effort and time you put into GShop and your co-contributors there, the folks that were part of Google Summer of Code project and everything. We really appreciate it. And I know I use this tool as a teaching and training tool all the time, and I know a lot of other people that do too. And you put a lot of work into it, and I want you to know we really appreciate it, and just thank you for all that effort that you put in. **35:41 Björn Kimminich:** Yeah, you're welcome. I still enjoy doing that, so I will keep it up for a while. **35:45 Chris Romeo:** That's the best part. And folks, our call to action to you coming out of this is if you haven't used Juice Shop yet, go check it out and play with it and find— start finding those challenges, and I promise you, you'll have a good time with it. **36:03** Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Björn and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @appsecpodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/bjorn-kimminich-the-joy-of-the-vulnerable-web-juiceshop/