--- title: "Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit" url: https://appsecpodcast.com/bjorn-kimminich-the-new-juiceshop-gsoc-and-open-security-summit/ date: 2019-06-01 duration_seconds: 1712 guests: ["Björn Kimminich"] topics: ["OWASP Projects", "Conferences and Community"] audio: https://www.buzzsprout.com/1730684/episodes/8122642-bjorn-kimminich-the-new-juiceshop-gsoc-and-open-security-summit.mp3 transcript: true --- # Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit *June 1, 2019 · 29 min* with [Björn Kimminich](https://appsecpodcast.com/guests/bjorn-kimminich/) on [OWASP Projects](https://appsecpodcast.com/topics/owasp-projects/), [Conferences and Community](https://appsecpodcast.com/topics/conferences-and-community/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122642-bjorn-kimminich-the-new-juiceshop-gsoc-and-open-security-summit.mp3) ## Show notes How do you keep an intentionally vulnerable application useful while its underlying frameworks keep fixing bugs? Björn Kimminich returns with an update on OWASP Juice Shop and the work required to maintain realistic security challenges. He describes new exercises involving promotional content, coupons, privacy, and two-factor authentication, then explains what happens when dependency or browser changes accidentally remove a vulnerability. The conversation also covers customization for different audiences, contributions through Google Summer of Code, and the balance between welcoming help and reviewing it carefully. Björn closes with plans for collaborative work at the 2019 Open Security Summit. This archive episode shows both the technical craft and community effort behind a widely used application security learning project. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Björn Kimminich: → [Björn Kimminich on GitHub](https://github.com/bkimminich) Mentioned in this episode: → [OWASP Juice Shop](https://owasp.github.io/www-project-juice-shop/) → [Open Security Summit](https://open-security-summit.org/) Chapters: 00:00 What was new in OWASP Juice Shop 02:25 New features and hacking challenges 05:19 Working two-factor authentication with TOTP 07:21 Keeping the right parts intentionally vulnerable 08:15 When dependency updates remove a challenge 09:43 Privacy features and GDPR-related exercises 11:16 Customizing Juice Shop for different audiences 13:05 Google Summer of Code contributions 16:14 Reviewing contributions and sharing maintenance 17:09 Getting help and giving feedback 19:22 Introducing the 2019 Open Security Summit 21:42 Planned Juice Shop working sessions 24:50 Adapting the summit around participants’ needs 26:30 Where to find Juice Shop resources ## Transcript *4,199 words · assemblyai* **0:00 Chris Romeo:** Bjorn Kimminich is the project lead for OWASP Juice Shop. This is his second visit to the podcast, and we discuss new features in Juice Shop, including cross-site scripting in jingle promo video, marketing campaign coupon hacking, GDPR-related features and challenges, working 2-factor authentication, and the DLP failure challenges. Then we get into the cool new things that will come as a result of the Google Summer of Code, where a developer will add new functionality to the Juice Shop where new vulnerabilities can be hidden. We end discussing the upcoming Open Security Summit from OWASP. We hope you enjoy. I wanna take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. The Application Security Podcast. Here we go. **1:53 Robert Hurlbut:** Hello folks, and welcome to another episode of the Application Security Podcast. This is Robert. one of your co-hosts for the podcast, and I'm joined here by Chris. **2:04 Chris Romeo:** Hey folks, this is Chris Romeo, CEO of Security Journey and co-host of the Application Security Podcast. **2:10 Robert Hurlbut:** And today we have a special guest with us, Bjorn Kimminich. Welcoming him back to the podcast. Welcome. **2:21 Björn Kimminich:** Thank you. Hi guys, good to be back. **2:25 Robert Hurlbut:** Glad to have you back. In fact, today we're going to be talking about Juice Shop, the project that's an OWASP project that he's been working on. Tell us what's new. I know the last time we got an introduction to you and to the project, but tell us what's new in the project these days. **2:44 Björn Kimminich:** When we last spoke, I think we covered all the basics and we covered the capture the flag features of the Juice Shop. We also talked about the complete new frontend that was completely refactored. That was the major release 8. Since then, we had 5 minor releases and are working on the 6th one. We added a lot of new stuff. No groundbreaking refactorings this time, but some really cool new challenges and features. For example, we have a very, very mean cross-site scripting which is now in the Juice Shop. I think it's number 6 or even 7, which is where you actually have to inject JavaScript into subtitles of a promotion video. So the Juice Shop has its own jingle and we made a little video for that and that's something you can find in the application. Of course, it's not promoted publicly, so you have to dig it up basically. Then you can, if you're really putting some effort in, you can actually inject into the subtitles of the video some JavaScript. We also added some to our existing coupon codes. The famous coupon code tweets that I do monthly, So those are now automated. So there's a little bot that is running every month and is tweeting the coupon codes now. And apart from those regular monthly coupons, we also added some marketing campaigns. So on special occasions, there are one-day events, and of course all of those are expired. So, and you have to then try to still get the discount from that. from that marketing campaign. Yeah, on the functional side, we added some, some great security feature actually, which is 2-factor authentication. So you can set up your Google Authenticator or whatever app you're using for real 2-factor authentication in the Juice Shop. Of course, we did some mistakes, so it's actually possible to bypass or sneak around the, the 2-factor authentication with some, with some tricks. But actually, if you just use it normally, then it looks really, really secure now. **5:19 Chris Romeo:** What are you using, Björn, under the hood? What are you using for the, uh, for the 2-factor authentication? **5:25 Björn Kimminich:** Uh, time-based tokens. So just the, the normal TOTP stuff. And of course, we are storing the private secrets in a not so perfect way. So yeah, you can actually just— you get a QR code displayed like you would know it from real websites, and then you can scan it with your Google Authenticator and you get an actual 2-factor time-based token generator in that app. **5:56 Chris Romeo:** Now, do you build those— do you build that code custom or is this something that you got from a library that carried 90% of the way? **6:04 Björn Kimminich:** No, we completely built it based on a library. So the only thing we are doing is storing the secrets in a bad way. **6:12 Robert Hurlbut:** Okay. **6:12 Björn Kimminich:** So the implementation, at least I hope, is not broken. So because we just use existing popular libraries for that, for Node.js. If someone finds a bug in the library we used, then please tell me, then we can make a new 6-star super heavy challenge out of that, like a zero-day challenge maybe. **6:34 Robert Hurlbut:** Yeah, what I remember, I remember looking at Juice Shop, I guess it was a couple of years ago when it was one of the— and we'll talk about the Open Security Summit here shortly, but I remember one of the first ones that they had, they were doing a threat model of Juice Shop and I was part of that remotely at the time. But it was really fascinating just to see the design behind the scenes, what was going on, and all the thought that was put into the design of an intentional broken application, even though a lot of stuff underneath was obviously done really, really well. So very impressed by it. And so I'm sure, you know, from what you just said, yeah, that you put it together the right way, but you then have to break it. **7:21 Björn Kimminich:** Intentionally. Yeah, the Juice Shop has to be broken in the places where it should be broken, but in no other places. That's my goal, which is not so easy always because we are depending on some libraries which are quite flaky, let's say. So there's some compiled C code needed in the background, and if that's not possible to build, then you have some big problems sometimes. So that's Yeah, it's not an easy task to actually keep it running properly, especially when new releases of Node.js, for example, or of Angular come out. That makes it even more difficult then to keep up. But that's the same problem that every application developer who basically maintains their application properly has. So why should it be different? **8:14 Robert Hurlbut:** Right. Of course. **8:15 Chris Romeo:** Have you ever had a situation where, like, library update fixes or prevents some of the Juice Shop vulnerabilities from being present anymore? **8:27 Björn Kimminich:** Yes, we actually had that just recently. There was an update of the Sequelize library which we are using to access the database in the background. So, and they updated and fixed or removed a feature where you could easily inject into selectors and queries. So, and you couldn't use that anymore. And one of our challenges actually relied on that. So, um, we— I just decided to take out that challenge then because, uh, building your way around that and faking the vulnerability, that's nothing that we are so, so happy doing because then it gets unrealistic and very, very expensive to maintain at some point. **9:10 Chris Romeo:** Yeah, I had the same experience with Google Chrome. the other day. I was using Juice Shop. I was trying to demonstrate one of the reflective cross-site scripting attacks real quick for somebody. And Chrome, all of a sudden, I went to do it, I went to run it, it didn't work. And I'm like, what's going on here? I look in the JavaScript console, Google Chrome has blocked your cross-site scripting. **9:32 Björn Kimminich:** Yeah. **9:33 Chris Romeo:** And I'm like, that's a good thing. Like, I should be happy, but I'm not happy. **9:37 Björn Kimminich:** So, back to Internet Explorer then. **9:39 Chris Romeo:** I'm digging it back out of the of the archive? **9:43 Björn Kimminich:** So we actually added some completely new category as well of challenges and also features. So it's all about data privacy. So we have some— so the Juice Shop is now trying to be compliant with GDPR laws, so the European data regulations that you probably like as well. So, and the Juice Shop is now offering a privacy policy that you can use, that you have to read, and there's some ways to lose your personal data, and you can of course request with the upcoming release, you can request to have your account deleted because of your right to be forgotten. So, but of course, the juice shop doesn't really delete your account properly, so you can still log in with an erased account. And that's also one of the new challenges upcoming. And we also do some crazy stuff with, with Pastebin. So we have We put actually some— we created 2 challenges which are based on things you have to find on Pastebin. I'm still not sure if those are actually possible to solve because I don't really understand how Pastebin search works. I think we have to wait a few years until Google actually indexed our pastes. Maybe those need to be removed again because it might not be possible to solve them, or we have to do it in a different way with GitHub Gists or something like that, which is easier to find. But those are also quite fun. **11:16 Robert Hurlbut:** Very cool. Another thing it looks like you've added is customization. **11:21 Björn Kimminich:** Yeah, that's actually almost an old feature. That's something that Timo, one of my colleagues here from OWASP in Hamburg, created some years ago because he worked at an insurance company. Provided awareness trainings and he realized that, well, the people didn't respond so well to this whole juice shop theme and this whole juice shop context. So they didn't really get the jokes, I guess. And so what he then did, he basically rewrote or he basically made the products configurable and also the layout. So you can switch the color theme, you can change the project or the application title, you can change all logos, you can completely rewrite the entire product list to actually fit whatever business you want to represent. I mean, it's still a webshop. That's something we cannot change on the fly. But what you can actually buy is completely up to you. And it's, it's, it's a very convenient configuration process where you just have to use a— or you just have to provide a YAML file with the customizations you want and all the rest will just stay as it is. in the original Juice Shop. So you can do small changes or you can do a complete UI rewrite. Actually, the Juice Shop comes with, I think it's 3 different quite sophisticated examples of customizations. So it's quite easy to pick up and to copy from those and see how that works. **13:01 Robert Hurlbut:** Okay. So some rebranding there if somebody wanted to. **13:04 Björn Kimminich:** Yeah, rebranding feature. **13:05 Robert Hurlbut:** Yeah. So tell me about the Google Season of Code. What's going on there? **13:09 Björn Kimminich:** Yeah. So last year in 2018, the Juleshop for the first time participated in Summer of Code with 2 students. And we again have this time 1 student working in Summer of Code this year. Last year we did a challenge pack, so new hacking exercises and also the whole Angular migration part. This year we decided to add a feature pack instead. There will be no new hacking challenges, but instead the student will add new functional features and then they can be— because we actually need some extra room to put more challenges in. You can imagine it's similar to an escape room. You can only put so many riddles into one room, I guess. At some point you have so many riddles in one room that you do not find your way around anymore. We want to prevent that by having new features that can then be broken with vulnerabilities. For example, we will add stock inventory so you cannot order products anymore which are not available. We will add something about payments, so like the juice shop might get its own wallet. It will get some payment gateway where you can Choose delivery address and all that stuff, so make it a bit more realistic as well. You can also choose between different delivery modes, so like fast and normal, for example. And of course, that it's likely to to to end up with a challenge where you need to get the fast mode without paying anything extra. And we also plan something like a Juice Shop Prime membership so that you actually get more bonus points and free fast delivery and other benefits. So yeah, there's a big package with some really cool ideas that our student Arpit provided, and he already committed a lot of code to the, to the juice shop before the Summer of Code started, and he's already working on, on things although the coding phase didn't even start yet. So that's really great. And we are mentoring him with 3 mentors. So apart from myself, Yannick from Hamburg and Shoaib from India as well, who was one of the students from last year. So actually we are, we are getting a little our core team is getting a little bigger, so which is very, very appreciated, especially. Yeah, Chris, we talked about my lack of time last, uh, in the last interview, so maybe that's getting— it might get a little bit better with the team growing. **16:12 Robert Hurlbut:** Definitely more hands help, certainly. **16:14 Björn Kimminich:** Yeah, absolutely. Although if you have too many pull requests and reviewing those and ensuring quality is then a burden on its own, so it's It's, uh, well, it's that balance, right? **16:26 Robert Hurlbut:** It's that balance. If you can, if you can. Yeah. **16:28 Björn Kimminich:** But it's important to have some people on board who are also able to review pull requests with the similar, uh, quality mindset that I have. So, and that's— we are definitely there. So that's, uh, pretty good. So I don't have to review everything. I'm not the Linus Torvalds of the Ju Shop, which is quite quite good, I think. **16:52 Robert Hurlbut:** Yeah, that's a great place to be if you have some confidence in the skill sets and others think similar way and understand your perspective and design philosophy and so forth. It's a really good place to be. **17:07 Björn Kimminich:** Yeah, absolutely. **17:09 Robert Hurlbut:** In terms of— this is just kind of a side question, I think— is in terms of getting feedback on Juice Shop, I know there are a lot more people that are using it. I always hear more and more people that are talking about it. They've discovered it, they're using it, they really like it. But what about, you said pull requests and other kinds of feedback. I mean, how does that— how would somebody, if they were, let's say they were using it the first time and they're trying to do a few things, but they have some questions and/or they also have some recommendations. I mean, what is the— what are the steps that somebody needs to go through with either one of those, getting some help and/or giving some feedback? **17:52 Björn Kimminich:** Yeah. For getting help, we actually offer lots of different options which are all actively monitored. First of all, we try to have the README as good as possible so that people actually can install it on their own. But then sometimes when they run into issues, we of course take GitHub issues. But if it's just a quick question, for example, then our GitHub chat is more useful, or our Slack channel on the OWASP Slack instance. We now also have a Reddit subreddit which is more for fun and for distributing coupon codes, but I will also answer questions there, of course. And we also have a Google Group now since OWASP migrated the old mailing lists where I had like 3 subscribers, I think. to Google Groups so that you can also ask questions there and they are publicly accessible and searchable. So I think we have pretty, pretty good resources. And also again here, the benefit that I'm not the only one who can answer a lot of questions. So we have a good, good user base now where they can also just answer questions themselves or one of our, our core team members actually answers. questions. So actually, I think the response time is pretty good for an open source project which we can offer. **19:22 Robert Hurlbut:** Great. So one of the things I mentioned earlier was the version of the Open Security Summit a couple of years ago. There's one coming up again in June for 2019. So tell us about, first of all, what is the Open Security Summit? Maybe somebody doesn't know about it, maybe the first time they're hearing about it. What is that? **19:46 Björn Kimminich:** Okay, so I'm not on this, on the organization team, so I'll do my best to sum it up. So the Security Summit is a gathering of security professionals. It's not a conference, so there will be no frontal presentations all day long. It's a full week from Monday to Friday, really exhausting event actually where where working sessions take place from day to late afternoon and then sometimes even additional evening sessions where you do coding or documentation or other things. The good thing about the Security Summit is that it's very output-driven. They don't just want people to sit around and discuss and nothing gets done. The idea is to prepare your sessions properly and to actually make sure that your working sessions on-site then actually produce a good outcome. And so to make sure that nobody's distracted, this takes place in a wood near London where there's definitely nothing else to do, which is pretty nice. **21:02 Robert Hurlbut:** And yeah, I think if I remember correctly, there is some sightseeing, right? There is the Enigma machine, a few other things that you could Yeah, that's Bletchley Park, right nearby. **21:14 Björn Kimminich:** Yes. So, but that's then one evening activity maybe. **21:17 Robert Hurlbut:** Right, of course. **21:17 Björn Kimminich:** See it yet. Yeah. Which, and that's really worth your time. So taking one evening to visit that place and actually get a tour through the computer museum, that's really amazing. So you can see some really nice World War II computers and other fancy machinery. So. Really, really recommend it. **21:40 Robert Hurlbut:** Yeah, definitely. **21:42 Björn Kimminich:** Yeah, and the last 2 years JUCE Shop was present in the summit, and this year we will again have a dedicated track for the project, which means we have a series of different working and user sessions. So one thing that I planned is to to offer a session about refactoring the challenges. So, I mean, we covered that slightly already, that sometimes library updates or just time passing by make challenges kind of obsolete or kind of weird. And I would actually like to, to get some feedback on how to, how to refactor the JooShop challenges in a way that it it still is as realistic as it was supposed to be originally. So that could also mean throwing out a few things. I'm personally— I like the, the not so serious challenges a lot, so like the Easter eggs and, and all that fun stuff. But I have no idea if those are actually useful for, for others as well. So they're good for a laugh, but sometimes they're not very, not very, very realistic. So I would like to get some feedback on that and work out some some plan on how to keep the challenges good. And then we will do a lot of coding sessions. So I called them Hack and Code this time because I, I hope not only to attract developers who work on issues or, or challenges in the evenings, but also some security people who then actually can be the guinea pigs for new challenges or just help improve overall quality and give feedback and, and all that stuff. So let's, let's see if that works out. So I hope to have some hackers and some coders in the same room, and then let's see what, what happens out of that. And that's planned for all evenings of the entire, of the entire week. And of course, I'll also offer some introduction sessions. So if someone has never heard anything about the Juice Shop and doesn't listen to this or any other podcast, then we will pick them up with some, some basic introduction and some Q&A sessions and that kind of stuff. So it will be a full week, let's say, very, very intense week. **24:12 Robert Hurlbut:** Yeah, I remember when I was doing that remotely, I did get up early and I found that it went even late at night. I said, geez, I wonder what it's like over there because it was a long day for me. I have to imagine it was a long day for everyone that was there on site as well. **24:29 Björn Kimminich:** It's definitely no vacation. So when you, when you come back home, then you might actually need a few days of vacation afterwards. But it's definitely— if someone says, oh, you're just going on vacation because it's in a, in a center park, uh, no, we are not. **24:45 Robert Hurlbut:** No, it's definitely a lot of work. Yeah, definitely hard work. Well, good. **24:50 Björn Kimminich:** And especially, it's especially, um, interesting, I think, that, that The whole organizational part is very agile at this summit. So it might be that you completely change the structure of the schedule for next day based on feedback from the day before. So it's not fixed and set in stone before, which I think is really a good idea. So it's actually very, very agile and flexible. **25:18 Robert Hurlbut:** Definitely fluid in terms of just where are we, what are we learning, what do we need to learn more, what do we need to work on more. Very good. **25:27 Björn Kimminich:** If nobody registers for your session that you planned, well then you just drop that session and join another one which might also need some help. That's also quite good. You shouldn't go to the summit with a fixed plan of exactly what you want to do. You should have an idea what you want to achieve, but don't make plans for exact days. So it's best to take the whole week and be there for the entire time because you never know if a very interesting session might pop up on the last day out of nowhere. **26:07 Robert Hurlbut:** Right. Okay. Well, we can provide a link to it, but it's open-security-summit.org if any of our listeners may be interested in checking it out. I think there are still some tickets left, but definitely get on that quickly because that's coming up. I believe it's mid-June or something like that, or maybe even earlier. **26:29 Björn Kimminich:** It's actually beginning of June. **26:30 Robert Hurlbut:** Beginning of June. Okay, my bad. Good. So then, yeah, they need to move quick. Okay, great. Well, we hope it's another successful event. I'm sure it will be. I've watched them in the past and they've been really, really need opportunities. So I'm hoping that, you know, a lot of things will come out of it. I'm sure it will. Again, well, Bjorn, thank you for joining us today. We really appreciate it. Are there any other thoughts in terms of just maybe one last thing to talk to our listeners about Juice Shop? How to get it? How to find it? Anything like that? **27:08 Björn Kimminich:** Yeah, so to find the Juice Shop, the easiest Way to do it is to go to owasp-juice.shop, which is our vanity URL, and it will just redirect you to the to the corresponding wiki page on owasp.org. And there you find all the links to the GitHub repositories, to our documentation, to the to the ebook, to Slack channel, Gitter chat, and everything. So it's all it's all collected there at the OWASP. the OWASP Wiki page. If you go to GitHub directly, you can just type OWASP Juice Shop on Google and then you should basically have the GitHub repo as one of the first hits as well. So, it's pretty easy to find these days, I would say. **27:58 Chris Romeo:** Thanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Björn and TJ, and our outro music is Southern Delight by Stefan Kartenberg. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/bjorn-kimminich-the-new-juiceshop-gsoc-and-open-security-summit/