Skip to content
AppSec PodcastThe Application Security Podcast — home
37 min

Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop

With Björn Kimminich

OWASP ProjectsVulnerabilities and Exploits

Can an intentionally broken online shop help change an organization’s security culture? OWASP Juice Shop creator Björn Kimminich explains how a realistic application full of vulnerabilities gives developers, testers, and managers a shared way to experience security problems.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 17 chapters
  1. 00:00Learning security with Björn Kimminich and Juice ShopAudio
  2. 01:37Björn’s path from development into securityAudio
  3. 03:41Why Juice Shop was createdAudio
  4. 04:51What makes an intentionally broken applicationAudio
  5. 05:41Turning real vulnerabilities into challengesAudio

About this episode

Can an intentionally broken online shop help change an organization’s security culture? OWASP Juice Shop creator Björn Kimminich explains how a realistic application full of vulnerabilities gives developers, testers, and managers a shared way to experience security problems. He traces the project’s origins, describes how real incidents become challenges, and discusses the community that keeps adding new ideas. Chris asks about management awareness demonstrations, capture-the-flag events, deployment options, and the range of challenge difficulty. They also explore what was new in Juice Shop 8 and where Björn hoped to take the project next. The conversation shows how hands-on exploration can connect an abstract vulnerability to something people recognize in their own software, without requiring everyone to begin as an expert.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Björn Kimminich:
Björn Kimminich on GitHub
OWASP Juice Shop

Resources
Juice Shop project website
Juice Shop source code
Node.js

Actionable

From this conversation

  1. Teach vulnerabilities before tools

    I'm not— because I think if the developers should learn how the vulnerabilities work, they should concentrate on that and use tools they know and not try to learn tools at the same time.

    23:34
  2. Use the CTF setup tool

    But what we did, which is the real benefit coming from our side, we created a little side project which is a command line tool which you run and then you answer a couple of questions like, hey, what CTF framework do you want to use?

    18:19
  3. Test account-recovery questions

    If they choose to register with their Google account, there's a little bit more technical way to be that, but that's something that managers can understand if you show them because the Juice Shop behaves silly after doing a proper OAuth 2 authentication with Google.

    13:58
Transcript · 37 min conversation

0:00Chris RomeoHey folks, season 4, episode 17 of the AppSec Podcast. On this episode, we're joined by Bjorn Kimminich, the lead for the OWASP Juice Shop project. Juice Shop is a vulnerable web application written entirely in Node, and it is a great way to impact the security culture inside any organization by letting developers actually put their hands on and test a vulnerable web application to find problems and then really experience things like cross-site scripting, SQL injection. So we hope you enjoy this conversation with Bjorn where he gets into what is Juice Shop, and he also talks about the latest release and some of the cool things that are up and coming in the Juice Shop world. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. I am actually very excited today to be talking with one of the primary authors of one of my favorite OWASP projects called Juice Shop. And so joining us today is Bjorn, who is— are you the primary project lead, Bjorn, or are you— is there other people?

1:37Björn KimminichYes, I am.

1:37Chris RomeoYou're the primary one. Wow. This is the guy behind the Juice Shop. And so, but before we get into that, on the AppSec Podcast, we always start by asking people, what's your security origin story? If there was a comic book about Bjorn, What does episode 1 look like in regards to security?

1:55Björn KimminichOkay, yeah, so hi guys, um, my name is Björn, Björn Kimminich, and, um, well, my security origin story is mostly a developer origin story. So I started programming when I was like 12 years old or something and kept doing that for a big portion of my professional career. And at some point I basically went from developing web applications more into the architecture perspective. So right now I'm working for a big logistics company, and as an architect, you're somewhat also responsible for security topics. And I was for a couple of years responsible for the AppSec part of one of our biggest web applications. And from there, I basically went to teaching developers the, let's say, AppSec basics. And right now, I'm basically dealing with security most of my time, but completely focusing on AppSec. And I would still consider myself 100% of a builder, and I'm not a pentester, and I'm not certified in any security stuff or anything.

3:09Chris RomeoYeah. And you're actually based in Germany?

3:14Björn KimminichYes, I'm based in Germany, in Hamburg.

3:15Chris RomeoVery cool. Very cool. And that's— there's a strong OWASP presence in Germany as well, right?

3:20Björn KimminichYes, there is actually. So we have this little different setup than other countries do. So we only have one big OWASP chapter for the entire country. And then we have so-called Stammtisch segments in major cities. And they meet every month mostly and are pretty popular actually.

3:41Chris RomeoYeah, very cool. And so, you kind of made this journey from developer to architect to security, and I'm guessing that all of those things really contributed to kind of what made you kind of think about kicking off the Juice Shop. So, would you say that you were influenced by kind of wanting to solve this problem based on the background you had across, you know, kind of a diverse background?

4:08Björn KimminichWell, what I actually wanted to do is give my developers who attended my trainings a better exercise environment. Because in the past, I used— I don't know if you know it— the Budget Store, which is a really, really old vulnerable application. Yeah, I do. Also some online website. I think it was provided by a big company who sells security tools. I mean, that was just outdated at some point. So, I wanted to have something new, and I also never wrote any pure JavaScript applications, so I thought, okay, why not write my own little broken web app?

4:51Chris RomeoYeah. So, when we think about the juice shop, then we refer to it as a broken web app. What does that actually mean that it's a broken web app?

5:03Björn KimminichSo that means if you just use it in a nice and normal way, then it looks like a regular e-commerce application. So it's an actual working web shop where you can buy juice, obviously, and related products. So you can register. You can log in. You can put stuff into your shopping basket, everything that you would expect. And everything works except for the part where I send you the actual products. That is the only thing that doesn't happen. But everything else actually works. And, um, but in the behind the scenes, it's a complete disaster from a security perspective.

5:41Chris RomeoThat's a— that's a— I think that's a great way to describe a broken web application, just a complete disaster. So how much of this is based in real life? Like, like, you know, sometimes they have that made-for-TV movie that says it was influenced by, you know, a true story. Like, where is that? Is that how Juice Shop is? Is it based on things you've seen in the past that are like really bad?

6:03Björn KimminichYes, it definitely is. So, um, I mean, it has the obvious things that you would expect. So some, some classical cross-site scripting, SQL injection, that kind of stuff. But it also has a lot of, uh, more complex problems, uh, authorization issues and, and, and other things, uh, business logic flaws which you which you really cannot make up. So you really have to steal those from real experience or from things you saw on, on the news. So that's also something I like to do when I— when some new nice vulnerability is being, uh, published, then I try to integrate it somehow also into the Juice Shop.

6:44Chris RomeoYeah, so give us, give us an example of one that you've recently integrated that was based on something kind of in real life, a juicy new vulnerability.

6:53Björn Kimminichability. One of the newest ones is this— what is it called? Ziploc, this file upload thing where you could put commands or file traversal, path traversal into a zip library or zip archive. One developer on the Juice Shop actually made a challenge out of that, like, I guess, maybe 2 weeks after that was published. So that's what went into the Juice Shop really quickly. Another example is a supply chain attack. So basically not a vulnerability of the application itself, but a vulnerability in one of the libraries that only the developers typically get on their machines when they work on this application. And that is also vulnerable and could actually be exploited, or at least we make it look like it could be.

7:42Chris RomeoYeah, and that's one of the things I love about G-Shop is that you you, and I want to talk about the team as well. That's kind of— I know there's other people behind you that are helping to drive this, but one of the things that I love is the fact that you are constantly updating it and adding those new challenges to it, which makes the Juice Shop kind of a living vulnerable application environment versus something that just has, you know, 10 challenges and then, you know, it's not going to be updated for a number of years. So, who is the— when you talk about the team, What does the team actually look like as far as how many people are behind Juice Shop?

8:15Björn KimminichSo we are 3, let's say, core contributors. So that's me, and that's Timo and Yannick, also from Germany, from Hamburg or nearby Hamburg. So they contributed some major new features to the Juice Shop some time ago, so like a CTF mode and customization feature. So they are basically my my main support crew.

8:44Chris RomeoOkay.

8:45Björn KimminichAnd then the Juice Shop actually participated in the Google Summer of Code this year with the OWASP Foundation.

8:52Chris RomeoOkay.

8:53Björn KimminichSo we had 2 students from India, Shoaib and Ashish, and they both did big, big, big work towards the 8.0 release that we just put out.

9:07Chris RomeoVery cool.

9:07Björn KimminichAnd otherwise, I think in total we had, I think GitHub says we had like 40 contributors in total. Some of them small changes, some of them medium changes, but yeah. Those are the main contributors, I would say.

9:23Chris RomeoYeah, I think of Juice Shop outside of some of the big OWASP projects that are document-based like the top 10. I think of Juice Shop as one of the more active projects from across the community. And, and 40 contributors historically is, is a nice number of people that are, that are getting involved and getting behind it. So I think that's pretty cool.

9:42Björn KimminichEspecially because it's only, uh, started, uh, I think in 2014. So, and it didn't, it didn't even start as an OWASP project. So it started as a private project of my own and became an OWASP project 2015. So it's just 3 years in OWASP and already that many contributors and it already got promoted to flagship, which is really nice. So.

10:04Chris RomeoYeah, congratulations for that too. And that's a—

10:06Björn KimminichYeah, thanks.

10:07Chris RomeoThat just reinforces—

10:09Björn KimminichThat's pretty big.

10:09Chris RomeoAll the work that you put in. And I gotta tell you this, like, you seem to be the person who never sleeps because I see you on the OWASP channel, the GShop channel all the time. And I know some of those things are coming from build bots and stuff, but like, it seems like—

10:24Björn KimminichMost of it, yes.

10:25Chris RomeoBut a lot of the time it seems like you're working on this 24/7. So I guess the first question is, do you sleep? Or just work on this all the time?

10:31Björn KimminichWell, I have to squeeze off a lot of time from my otherwise, which I would otherwise probably use for gaming or other stuff.

10:38Chris RomeoAh, okay.

10:39Björn KimminichAnd sometimes my family also complains, but—

10:42Chris RomeoSo does your family, when they hear Juice Shop, is your family still impressed or are they like, ugh, more of this Juice Shop thing?

10:49Björn KimminichMy daughter actually is, and she actually contributed one of the images I'm using in the product list of the Juice Shop. Ah, that's cool. she drew a pretty picture of the Juice Shop logo, and we're actually selling that.

11:04Chris RomeoOkay, very cool. That's very awesome that she's getting involved with kind of this project here. So kind of stepping back again, I know I feel like we kind of really covered the what is Juice Shop quite well. I feel like I've got a lot better idea now. When we think about why, so why Juice Shop? I know you mentioned the fact that, you know, you wanted to give developers a better exercise environment, but Tell me more about the why behind this project.

11:32Björn KimminichMy goal was actually to have an application that immediately tells you when you did something right. In that case, it means when you broke something or when you found a vulnerability actually. The budget store did that, and basically that's where I stole the idea of having a scoreboard which shows you what you already practically solved. But the Juice Shop took that a little bit further with notifications popping up whenever you solved a challenge. So the main driver actually was trainings. And later, there were initial use cases we didn't really think about in the first place, like awareness sessions, for example. So I already used the Juice Shop in my own company and also at other places. to give awareness sessions for managers, for example, from IT management. That's one big other use case which might even more important than teaching developers about security. Yeah.

12:37Chris RomeoI think I saw the awareness sessions for managers, did that involve a YouTube video?

12:43Björn KimminichThere is a YouTube video which shows some pretty nasty cross-site scripting. Sometimes I show that, sometimes I don't. But it's pretty loud, actually. So the Juice Shop is starting to dance and the user interface is doing weird stuff.

13:03Chris RomeoYeah, that's the one I'm thinking of, yeah.

13:05Björn KimminichA keylogger is involved.

13:06Chris RomeoYeah, okay.

13:07Björn KimminichReally bad.

13:08Chris RomeoSo how do you use Juice Shop then as an awareness session for managers? I want to poke at that a little bit more. So what— like, how are you— What are you showing them that's making them aware?

13:18Björn KimminichYeah, so I have different levels depending on how technical the audience is. So on the highest level, what I show is, hey, this is just a regular webshop, and I show how it works and don't show any vulnerability actually. Then I ask them to, or ask one of them to actually register their own user and put some stuff into the shopping basket, so play around with it. What I afterwards do is, demonstrate how I can then break into their account. So the first thing I try is getting their password back from the password hash, which is happily exposed by the juice shop in different ways.

13:57Chris RomeoYeah.

13:58Björn KimminichThat in many cases doesn't work. So then I will go to check if they chose a stupid security question to answer and actually answered them truthfully. So like, what's your favorite pet's name? Typically, I cannot break that, but I can at least explain, hey, there's only so many names pets typically have in a given country. So it's like maybe if I would have the time to try 100 times, I would probably get it. But then in the end, I mostly show it with SQL injection. Like, okay, if I know your email address, I don't have to know your password, I get just in. So that's one way I like to show. If they choose to register with their Google account, there's a little bit more technical way to be that, but that's also something that managers can understand if you show them because the Juice Shop behaves really silly after doing a proper OAuth 2 authentication with Google. Okay.

14:56Chris RomeoAnd what are the results that you see? Like, how do managers respond to you when you show them these things? What are their feedback?

15:03Björn KimminichThey typically find it very interesting and often also very scary, especially when I tell them that, hey, in our company and probably in most other companies, we have also applications which behave like that. So if you look long enough or search long enough, then you wouldn't actually— you might not even need a juice shop because your own applications might be enough to show all those vulnerabilities because most of them are available in one application or the other.

15:32Chris RomeoYeah. And you find most of these people that you're showing this demo to, is this really their eye-opening moment? Like they didn't they didn't really understand the depth of vulnerabilities that exist in web apps before you showed them the demo?

15:46Björn KimminichYeah, it depends. So if someone comes in with a— let's say with more of an infrastructure background, so they understand the concept of a firewall and how that makes your network secure and that kind of stuff, so they understand how a VPN works, for example, then they often think, OK, I mean, we have all this expensive security equipment and Why does this guy tell us now that it actually doesn't make us really secure because there's a way to get through all this and just attack your whole nice IT equipment through port 80 or 443 and it's game over? That's often, that's kind of an eye-opening moment.

16:25Chris RomeoAfter the break, we hear from Bjorn about what is CTF mode and how do we use it? The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. So Bjorn, what is CTF mode and how do we use it in the Juice Shop?

17:04Björn KimminichOkay, so yeah, CTF mode, that was actually an idea that Yannick and one other developer had. So they wanted to use the Juice Shop in, I think, at conferences to let people hack it and give out some small prizes for those for those who found the most vulnerabilities. So essentially what the Juice Shop offers is just a mode where you start it and the little notifications that pop up when you solve a challenge will then contain a long string which is basically your solution code.

17:42Chris RomeoOkay.

17:43Björn KimminichFor that challenge. So what you need then is an external CTF server, so basically a score server like CTFD, which is also open source, for example.

17:54Chris RomeoOkay.

17:55Björn KimminichAnd then you can take that code and paste it into CTFD to solve the challenge over there. And then that's where basically the overall score is kept, right, for every participant in the CTF.

18:05Chris RomeoOkay, so you only had to extend the Juice Shop a little bit to give up that code, and then it allowed you to kind of outsource the capture the flag management platform to the other open source project.

18:19Björn KimminichExactly. But what we did, which is the real benefit coming from our side, we created a little side project which is a command line tool which you just run and then you answer a couple of questions like, hey, what CTF framework do you want to use? Can you give us the URL of your Jupyter instance you're running? Do you want hints to be available or not? In like 10 seconds, you can generate a zip file which you can then upload to one of these score servers and import it there. And it will basically generate and set up all the challenges and all the stuff over in the CTF framework. So you don't have to create the challenges manually. You don't have to deal with the— the codes will of course be the right ones that the Juice Shop creates and they will match the ones on the score server.

19:10Chris RomeoOkay.

19:11Björn KimminichSo everything will be— I'm always teasing that you can set up a complete CTF environment in 5 minutes if you're using these, these tools.

19:19Chris RomeoNo, that's nice. And that's— I, and I've seen that throughout your approach to Juice Shop. So, you know, I've actually used your one-click deploy on Heroku for the Juice Shop.

19:29Björn KimminichYeah, that's, that's really sweet.

19:31Chris RomeoYeah, I mean, and so talk a little bit about that for people that might want to get started with the Juice Shop. I love the fact that you've made it so easy, but I'd rather have you tell that story.

19:38Björn KimminichOkay, so, um, yeah, you can, you can deploy the Juice Shop in different ways. So you can install it locally on your computer if you have no Node.js, that works. You can run it in a Docker container, that also works fine. And there's some options for cloud deployment. And the easiest one is actually with Heroku. So Heroku offers a little button that you can include into the README of your GitHub projects. And when you click that button, you are forwarded to Heroku and they actually— you only need to log in and click, I think, one or two buttons and they will spin up a machine for you, pull that Git repository, start the application, and give you back the URL where you can then reach it. And that is really quick, and it's totally convenient. So that's the easiest and quickest way to get a Juice Shop instance running, actually.

20:29Chris RomeoYeah, and then you also have a demo instance running as well, right?

20:32Björn KimminichYes, exactly. I have a permanent Heroku instance which is running. for free, which is nice for open source projects. Yeah, yeah.

20:41Chris RomeoAnd I've pointed people towards the demo instance as well as just one place to— if you want to experience it, you can just jump right into it and it's very easy. What's the URL for the demo?

20:53Björn KimminichThe URL is juice-shop.herokuapp.com.

21:01Chris RomeoOkay, we'll put that in the show notes as well. We want the action— call to action coming out of this is we want more people to go and use Juice Shop.

21:09Björn KimminichYeah, somewhere in the README, I've written that people are not supposed to hack that instance, but for some reason, I always find some challenges solved there on the scoreboard.

21:19So—

21:19Björn KimminichYeah. The one important note, the Juice Shop is not built to be used by different users at the same time actually. So if someone is hacking on the demo machine, there might be some confusion with what other people also do at the same time. So in CTFs or also when you use it in trainings, every participant actually has to have their own Juice Shop instance. So they have their own score tracking, their own challenge solutions popping up and that kind of stuff. So that's the way how it works best.

21:53Chris RomeoYeah, and that's the one time that I've actually used this. We had a special training event for the OWASP Raleigh chapter that I'm a part of.

22:03Björn KimminichUh-huh.

22:04Chris RomeoWe did it over lunchtime because we wanted to engage a particular population of developers. So, we spun up a Juice Shop instance on Heroku with the button, the easy button I'll call it, for each of the teams that was operating there. I had 8 teams running with about 4 developers and then 1 security person at each table. They were working together on solving the challenges from 1 laptop and collaborating back and forth. And so, that's just another use case that I've actually used firsthand that was really valuable. And I'll tell you what, I learned a lot. So, security people that are listening to this, set up one of these hackathons that I just described right there. Join one of the teams with a couple developers and just sit there quietly and watch them tear a web application apart with the tools and techniques that they have.

22:54Yeah.

22:55Chris RomeoMy mind was blown. I thought I knew a pretty good amount about, you know, pen test, app pen testing and how web apps actually work. And these folks were just bringing out tools and just tearing this thing apart and looking at it in different perspectives. And I was just, so I think there's a lot of value for us as security people to learn from developers based on how they actually debug tools because it turns out all their debug methods are how they found most of the vulnerabilities that were in the Juice Shop.

23:24Björn KimminichYeah, you can do a lot of stuff just with a browser and the DevTools. That's all I want to say.

23:31Chris RomeoYeah, it was very powerful to see that.

23:34Björn KimminichIn trainings, I'm not teaching any hacking tools actually. So I'm not— because I think if the developers should learn actually how the vulnerabilities work, they should concentrate on that and use tools they actually know and not try to learn tools at the same time. So that's— you can essentially hack everything in the juice shop just with a browser and maybe some API client or API testing tool. So that's all you actually need, and you need some internet research, but that's it.

24:05Chris RomeoYeah, no, that's good. I'm glad that's your perspective as well because, you know, one of my passions is how do we— which I think is the same and I know is the same passion you share here as far as how do we reach developers and get them to focus in on security and putting their hands on the keyboard is priceless.

24:24Björn KimminichYes.

24:25Chris RomeoI can lecture for 8 hours about SQL injection, and they'll pay attention for about 15 minutes, and then the rest of the day is just them listening to me drone on about the history of SQL injection. But as soon as they put their fingers on that keyboard and start typing away, it's like, wow, now they're working the way they work, in their flow, in their process. That's where that true magic of learning happens from my perspective. And GShop does a great job, best thing I've seen out there as far as being able to tap into that whole experience-based learning.

24:58Björn KimminichYeah, I guess it's good that it's actually a realistic application, right? So that's why it feels real. And so that many developers can actually relate to what they find and think about, hmm, maybe my own application has the same issue as well.

25:17Chris RomeoYeah, yeah. And so let's talk for a minute about 8.0. I know that just dropped a few days ago from the time that we're actually recording this interview. So what's new in 8.0, new and cool stuff?

25:30Björn KimminichSo 8.0 is our latest major release. And basically, I could have called it the Google Summer of Code release because it contains the 2 student projects that that have been done. So the first one is a complete migration of the frontend. So previously, in everything up to 7 point something, we used AngularJS, so the old Angular framework. And we used Bootstrap for the layout. And this was completely rewritten into Angular, so the new Angular version 7 it is now.

26:11Chris RomeoOK.

26:12Björn KimminichAnd using Google's Material Design for the layout now. So that was a big effort and complete rewrite in the end. And the second student project was a so-called challenge pack. So the student added 9 or 10 new hacking challenges, some of them really, really crazy difficult. So there's now something included which requires you to reverse engineer some malware that we actually created, which is not really malicious, but it fakes being malicious, to actually be able to solve a challenge, which is mind-blowingly crazy. So it's completely different. It doesn't have anything to do with web pentesting anymore. So it's basically reverse engineering now. So we try to include a lot of stuff. new remote code execution ways, there's race conditions, there's all kinds of things that are in the new version. Mostly very difficult challenges, but we also added some easy ones to give everyone a fresh new challenge to solve.

27:26Chris RomeoThat's one of the other things I like about Juice Shop is the fact that you have challenges at different levels of difficulty, because in my experience working with developers, some developers really dive headfirst into this and really get into it, and they'll die— they'll get into those harder challenges.

27:44Björn KimminichYep.

27:45Chris RomeoBut others aren't— don't— just don't have that natural drive towards wanting to know everything about security. And so— and that's okay. We want to— we want— we want to capture both of those audiences and have them get value out of it. And so that's something I love about Juice Shop is that you've got something for the people who are just kind of scratching the surface, and you've got some stuff for people that are really diving in deep into this whole process.

28:08Björn KimminichYeah, and that's also one thing I always ask my training attendees afterwards as feedback. Do you think that our difficulty rating is correct, or do you think one challenge needs to be rated higher or lower or something? So we try to adjust the ratings to something— not to what we think as the authors of the Juice Shop, but to what actually the users think how difficult something is. So that's I guess at the moment it's quite okay. Some things are a bit overrated maybe, but we can tune them down. At some point we had to actually add— we started with difficulty 1 to 5 stars, and now we have 6 because it didn't work any other way because there were so difficult new challenges we couldn't put them on the same level anymore.

29:00Chris RomeoThat's the benefit of being your own architect.

29:02Björn Kimminichfor your own solution.

29:03Chris RomeoYou'd be like, you know what, we're just going to add a 6-star and that's going to be okay because I'm the architect and I can do that if I want to. So, where's Two Shop going in the future here? You know, you're the project lead. What is your vision for the next couple of years with this project?

29:19Björn KimminichSo, one thing I would really like to do, but I guess it's pretty hard to get that, is something like a guided a guided or assisted hacking mode. So there's a GitHub issue actually for that, which has some fake screenshots which I made. So the idea is that you get this annoying little helper like Clippy from some time ago.

29:50Chris RomeoFor those people that don't know who Clippy is, look it up on Google. It's a Microsoft thing, used to exist in Office, and we'll leave it at that.

29:58Björn KimminichIt's awesome. Yes. And so this little helper or assistant guides you through some of the probably the easier challenges. So telling you, okay, hey, there's an input field and hey, type in your name and see how the application behaves. And when you did that, then it might tell you, hey, now try to put in some HTML tag along with your name and see what happens then. And then essentially over a few steps, the assistant shows you how to solve one of the easiest cross-site scripting challenges and maybe the same for some SQL injection and one or two other challenges. So you basically get going when you don't have a trainer in the room who actually teaches you all the stuff. So you can use the Juice Shop more alone in a room if you just want to play with it.

30:46Chris RomeoYeah.

30:47Björn KimminichSo some people already struggle with finding the scoreboard because that's actually one of the 1-star challenges to actually find the scoreboard in the application because it doesn't have a visible link. Somewhere. But obviously, there's a hidden place where you can actually see it. And yeah, this is also something that this little assistant could actually help you with. Like, hey, click here and click View Source and then scroll down a bit and maybe you'll find something interesting. Yeah. That's one thing I think is nice. And it would be a nice change to just adding more difficult and even harder challenges to do something for the— for the newbies, basically, who have no prior experience and no one to teach them, actually, at the moment. So that's one of my goals. And otherwise, well, let's see how Google continues with Angular. So I hope I don't have to spend too much time doing frontend migrations anymore because that was not fun.

31:52Chris RomeoNo, I don't imagine it was. It doesn't sound like an enjoyable process.

31:56Björn KimminichNo, no, no, definitely not. Yeah, other than that, at the moment our roadmap is quite empty with this latest major release. So we're always happy to get new ideas. One request that I often get is, hey, now you have all these great broken things in your application. Why don't you add some new mode where you can then fix those challenges? And actually, the Juice Shop rates if you fix it correctly or not. And that's something that I think will— that won't be possible easily because many of the challenges are built into the Juice Shop in a very dedicated way. So if I would just show the source code for that, it would look weird because it's just checking for some random condition and there's nothing really to fix.

32:51Chris RomeoRight? Yeah.

32:52Björn KimminichSo this is something that might end up at some point in a side project, for example, where you basically have the same challenges that the juice shop offers, but basically reverse them into fixing challenges. But I think I will not include that directly in the juice shop because it will break the concept and basically— put too much responsibility into that one place. But that could actually be a second application and the juice shop could link to that. If you solved a challenge, then there could be a button like, hey, do you want to solve the fixing challenge now? And then you jump over to the other application.

33:33Chris RomeoYeah.

33:34Björn KimminichBut I'm not sure if I would want to be the project leader for that actually, so.

33:37Chris RomeoThat's another— it seems almost as big as the juice shop in general.

33:41Björn KimminichYes, exactly.

33:42Chris RomeoYeah, so where can people get in touch with you? Online, what's the best way if somebody has feedback about Juice Shop or they have a new idea about some feature and they're like, we should— it would be really cool if Juice Shop did this. Where— how do you want them to reach out and connect with you?

33:56Björn KimminichSo the easiest is to just check out our vanity domain, which is owasp-juice.shop, and that will redirect you to the official project wiki page, which has all the contact channels for the Juice Shop itself. So Juice Shop, of course, has its own Twitter, account. It has a Facebook page. It has— there's a Gitter chat, so— and where you can just join with your GitHub account and ask questions. We have a Slack channel on the OWASP— on the official OWASP Slack. And otherwise, everyone can, of course, write an email to me or just hit me on my own private Twitter account as well. So—

34:37Chris RomeoOkay.

34:37Björn KimminichI think it's not hard to reach me.

34:40Chris RomeoYeah, I think you're like the most connected person in OWASP. here, given that you had just 12 different ways for people to contact you here, which is awesome because—

34:48Björn KimminichWe even have a mailing list. I think it has 3 subscribers and that includes myself. So, I stopped promoting that at some point.

34:58Chris RomeoYeah, I can see why. It's about quality. It's quality postings, not about the quantity of subscribers that we have on that list.

35:09at all.

35:09Chris RomeoSo Bjorn, thank you so much. From, you know, I don't know that I can speak for the whole community, but I'm going to anyway. Thank you for all the effort and time you put into GShop and your co-contributors there, the folks that were part of Google Summer of Code project and everything. We really appreciate it. And I know I use this tool as a teaching and training tool all the time, and I know a lot of other people that do too. And you put a lot of work into it, and I want you to know we really appreciate it, and just thank you for all that effort that you put in.

35:41Björn KimminichYeah, you're welcome. I still enjoy doing that, so I will keep it up for a while.

35:45Chris RomeoThat's the best part. And folks, our call to action to you coming out of this is if you haven't used Juice Shop yet, go check it out and play with it and find— start finding those challenges, and I promise you, you'll have a good time with it.

36:03Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Björn and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @appsecpodcast or on the web at www.appsecpodcast.org.

5,956 words · transcript by assemblyai

More on OWASP Projects

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.