From Training Exercise to OWASP Flagship

▶ Watch (1:38)

Björn Kimminich started teaching web application security at Kuehne+Nagel in 2007-2008. He used AltoroMutual, a fake banking site bundled with a commercial security scanner, then switched to BudgetStore, a companion to the ZAP proxy. Both were server-side rendered and covered only a handful of vulnerabilities.

In 2014 he built Juice Shop as a personal project to learn AngularJS and Node.js while creating something useful for training. Version 1.0 launched October 21, 2014. He submitted it to OWASP in 2016 and it was accepted immediately because it was already fully functional. It earned Flagship status in 2018.

107 Challenges Across Every OWASP Top 10 Category

▶ Watch (8:50)

Version 1.0 shipped 23 challenges: SQL injection, cross-site scripting, access control bypasses, and information leakage. Today Juice Shop has 107. Every OWASP Top 10 category ever published is covered except buffer overflow, which appeared only in the original list. Challenges added since include business logic flaws and secure design violations.

Those logic flaw challenges are the ones automated scanners miss. Scanners can’t flag them because they don’t understand business rules. Web3 challenges added in 2023 let users connect an Ethereum test wallet and attack smart contracts directly inside the app.

Coding Challenges and a Redesigned Scoreboard

▶ Watch (12:20)

In 2021 Juice Shop added coding challenges. After solving a hacking challenge, you view the actual vulnerable source code pulled live from the running server, select the buggy line, then pick among four proposed fixes. Getting it right earns extra points. 31 of the 107 hacking challenges include a paired coding challenge.

By 2023 the scoreboard had grown cluttered with difficulty stars, coding challenge buttons, and cheat sheet links. Yanik rebuilt it as a tile layout. Each challenge gets its own card, filters work by category and difficulty, and the table that required horizontal scrolling is gone.

CTF Export and MultiJuicer for Group Deployments

▶ Watch (18:01)

2016 added CTF export. A command-line tool reads Juice Shop’s challenge API and writes a file for CTFd, Facebook CTF, or RootTheBox. Hints can be free or cost points. Juice Shop runs in CTF mode so solved challenges print a flag code. Full setup takes about 30 minutes.

MultiJuicer, added in 2019, runs a Kubernetes cluster with a custom load balancer. Teams register, wait about 30 seconds, and get a live Juice Shop instance. A leaderboard shows which instance leads on points. Four Raspberry Pis in Kimminich’s Lego tower support 50 to 60 concurrent users.

Theming, Cheat Detection, and Monitoring

▶ Watch (22:56)

A YAML theming file lets trainers overwrite the app title, logo, color scheme, and all products without touching code. The purpose: show vulnerabilities to managers using an app that looks like something from their own company rather than a generic juice shop.

Juice Shop also ships cheat detection. It calculates a score based on how fast each challenge is solved relative to its difficulty and previous challenges. The automated test suite that exploits every challenge scores 97% cheat probability. Trainers can check this; there is no central authority to report it to.

82 Million Docker Pulls and Four Core Contributors

▶ Watch (31:30)

GitHub stars jumped when the project briefly trended and now sit just above 10,000. GitHub releases have 350,000 downloads, SourceForge mirrors add 70,000 more, and Docker Hub has served 82 million pulls across all images combined.

The core team is four people: Kimminich, Yanik, Teimo, and Shubam, who joined through Google Summer of Code in 2022 to rebuild the end-to-end test suite. The project has participated in GSoC since 2018 but skipped 2024 after most submissions arrived as obvious AI-generated content.

Q&A

Can others build their own Lego Juice Shop tower? Building instructions, a 3D model file, and an Excel parts list are in the OWASP swag repository on GitHub under projects/juice-shop/lego, with about 300 pages of instructions. ▶ Watch (38:09)

Does Juice Shop need special handling when redeploying on ephemeral hosts like Heroku? No persistent data migration is needed because Juice Shop wipes its database on every restart. ▶ Watch (38:49)

Notable Quotes

automated tools are really terrible at finding because they don’t understand the business logic Björn Kimminich · ▶ Watch (9:52)

I hope nobody deploys it in production and uses it as a real web shop Björn Kimminich · ▶ Watch (32:31)

easily spotted with the naked eye uh as AI generated Uh crap so Björn Kimminich · ▶ Watch (35:10)

Key Takeaways

  • Version 1.0 launched October 21, 2014 with 23 challenges; 10 years later it ships 107.
  • Logic flaw challenges target business rule violations that automated scanning tools cannot detect.
  • MultiJuicer runs a Kubernetes cluster so trainers can spin up dozens of instances without local installs.
  • The YAML theming system lets any organization skin Juice Shop to resemble their own applications.
  • 82 million Docker Hub pulls make Juice Shop the most-downloaded intentionally vulnerable web application.

About the Speaker

Bjoern Kimminich works as Product Group Lead Application Ecosystem at Kuehne + Nagel, responsible (among other things) for the Application Security program in corporate IT. He is an OWASP Lifetime Member, the project leader of the OWASP Juice Shop, and a co-chapter leader.