It can be used in security trainings, awareness demos, CTFs and as a guinea pig for security tools! Juice Shop encompasses vulnerabilities from the entire OWASP Top Ten along with many other security flaws found in real-world applications! Juice Shop is written in Node.js, Express and Angular. It was the first application written entirely in JavaScript listed in the OWASP VWA Directory. The application contains a vast number of hacking challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. The hacking progress is tracked on a scoreboard. Finding this scoreboard is actually one of the (easy) challenges! Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a “guinea pig”-application to check how well their tools cope with JavaScript-heavy application frontends and REST APIs.

Features

  • Licensed under the MIT license with no hidden costs or caveats
  • Choose between node.js, Docker and Vagrant to run on Windows/Mac/Linux as well as all major cloud providers
  • Additional dependencies are pre-packaged or will be resolved and downloaded automatically
  • Hacking Instructor scripts with optional tutorial mode guide newcomers through several challenges while explaining the underlying vulnerabilities
  • The application notifies you on solved challenges and keeps track of successfully exploited vulnerabilities on a Score Board
  • Wiped clean and repopulated from scratch on every server startup while automatically persisting progress in your browser or via manual local backup

Project Samples

Project Activity

See All Activity >

Categories

Security

License

MIT License

Follow OWASP Juice Shop

OWASP Juice Shop Web Site

Other Useful Business Software
Forever Free Full-Stack Observability | Grafana Cloud Icon
Forever Free Full-Stack Observability | Grafana Cloud

Our generous forever free tier includes the full platform, including the AI Assistant, for 3 users with 10k metrics, 50GB logs, and 50GB traces.

Built on open standards like Prometheus and OpenTelemetry, Grafana Cloud includes Kubernetes Monitoring, Application Observability, Incident Response, plus the AI-powered Grafana Assistant. Get started with our generous free tier today.
Create free account
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of OWASP Juice Shop!

Additional Project Details

Operating Systems

Linux, Mac, Windows

Programming Language

JavaScript, TypeScript

Related Categories

JavaScript Security Software, TypeScript Security Software

Registered

2021-11-11