OWASP Juice Shop CTF
data:image/s3,"s3://crabby-images/1d4d4/1d4d43b82a4c096d3268982263ac92324277ca86" alt="Twitter Follow"
data:image/s3,"s3://crabby-images/bbcb7/bbcb739f1b57467a8c530cb165fd77df7327631a" alt="Greenkeeper badge"
The NPM package
juice-shop-ctf-cli
lets you create a ZIP-archive compatible with CTFd's
data backup format to conveniently populate the platform for a
Capture the Flag
event against
OWASP Juice Shop.
data:image/s3,"s3://crabby-images/0cf7c/0cf7c525202a5cb0e581287d620e3e3521e946de" alt="CLI in action"
:information_source: The data format generated by v4.x
of this utility
has been tested for schema-compatibility with
CTFd ≥v1.1.0
.
Setup
data:image/s3,"s3://crabby-images/626c3/626c37aadb3fa4dc15130b793c82f6107e64fd39" alt="npm"
npm install -g juice-shop-ctf-cli
Usage
Interactive Mode
Open a command line and run:
juice-shop-ctf
Then follow the instructions of the interactive command line tool.
Configuration File
Instead of answering questions in the CLI you can also provide your desired configuration in a file with the following format:
juiceShopUrl: https://juice-shop.herokuapp.com
ctfKey: https://raw.githubusercontent.com/bkimminich/juice-shop/master/ctf.key
insertHints: none | free | paid
insertHintUrls: none | free | paid
You can then run the generator with:
juice-shop-ctf --config myconfig.yml
Optionally you can also choose the name of the output file:
juice-shop-ctf --config myconfig.yml --output challenges.zip
Docker Container
data:image/s3,"s3://crabby-images/bfb75/bfb754c84caa600ef71030b835fdbb30ab493cb6" alt=""
Share your current directory with the /data
volume of your bkimminich/juice-shop-ctf
Docker container and run the interactive mode with:
docker run -ti --rm -v $(pwd):/data bkimminich/juice-shop-ctf
Alternatively you can provide a configuration file via:
docker run -ti --rm -v $(pwd):/data bkimminich/juice-shop-ctf --config myconfig.yml
Choosing the name of the output file is also possible:
docker run -ti --rm -v $(pwd):/data bkimminich/juice-shop-ctf --config myconfig.yml --output challenges.zip
For detailed step-by-step instructions and examples please refer to
the Setting up CTFd for Juice Shop in the Hosting a CTF event chapter
of our (free) companion guide ebook.
Screenshots
data:image/s3,"s3://crabby-images/7f394/7f3945f7684bbaba57aee6a52243ab5ce1ed9e4c" alt="CTFd challenge overview"
data:image/s3,"s3://crabby-images/6ef70/6ef709fc60139ade873f3f0d3e85ef4f1e012838" alt="CTFd challenge details"
Troubleshooting data:image/s3,"s3://crabby-images/a423c/a423cd53df837e0be9a49c60f9928c541afbb64c" alt="Gitter"
If you need help with the application setup please check the
Troubleshooting section below or post your specific problem or
question in the
official Gitter Chat.
- If using Docker Toolbox on Windows make sure that you also enable port
forwarding for all required ports from Host
127.0.0.1:XXXX
to
0.0.0.0:XXXX
for TCP in the default
VM's network adapter in
VirtualBox. For CTFd you need to forward port 8000
.
Contributing
data:image/s3,"s3://crabby-images/6069b/6069beef018bc949c7d1ee9f16f0efa778b57853" alt="Stories in Ready"
Found a bug? Got an idea for enhancement? Improvement for cheating
prevention?
Feel free to
create an issue
or
post your ideas in the chat!
Pull requests are also highly welcome - please refer to
CONTRIBUTING.md for details.
Donations
PayPal data:image/s3,"s3://crabby-images/1b47c/1b47cf9a26e146334f99a2a10df8c504288c58f3" alt="PayPal"
PayPal donations via above button go to the OWASP Foundations and are
earmarked for "Juice Shop". This is the preferred and most convenient
way to support the project.
Credit Card (through RegOnline)
OWASP hosts a
donation form on RegOnline.
Refer to the
Credit card donation step-by-step
guide for help with filling out the donation form correctly.
Crypto Currency
data:image/s3,"s3://crabby-images/9a615/9a61504a22ff08cf25882e12a5d1d96dcea67cb4" alt="Ether"
Contributors
Collaborators
Code Contributors
Based on GitHub commits.
Ordered by added lines of code as of Mon, 11 Dec 2017 on master
.
Licensing data:image/s3,"s3://crabby-images/5ce21/5ce21ecc5c7c0f1c6358cbf1bb486c5f4959e9ee" alt="license"
This program is free software: you can redistribute it and/or modify it
under the terms of the MIT license. OWASP Juice Shop and any
contributions are Copyright © by Bjoern Kimminich 2016-2018.
data:image/s3,"s3://crabby-images/0393f/0393fdbce12be18a710d4c6ec3e43eaef344d5ad" alt="Juice Shop CTF Logo"