# OWASP Juice Shop ## Task 1 Open for business! Đơn giản là config vpn và access vô web ![](https://i.imgur.com/LDS4HTS.png) ## Task 2 Let's go on an adventure! ### Question #1: What's the Administrator's email address? ![](https://i.imgur.com/2PADw5A.png) `admin@juice-sh.op` ### Question #2: What parameter is used for searching? ![](https://i.imgur.com/f4GnXTq.png) `q` ### Question #3: What show does Jim reference in his review? ![](https://i.imgur.com/bqyDlOT.png) ![](https://i.imgur.com/01ey0mn.png) `Star Trek` ## Task 3 Inject the juice ### Question #1: Log into the administrator account! payload `' or 1=1 --` ![](https://i.imgur.com/aX1x4SF.png) ### Question #2: Log into the Bender account! payload `bender@juice-sh.op' --` ![](https://i.imgur.com/kd1iY7k.png) ## Task 4 Who broke my lock?! ### Question #1: Bruteforce the Administrator account's password! ![](https://i.imgur.com/23UlzRO.png) ![](https://i.imgur.com/7xXvKjL.png) ### Question #2: Reset Jim's password! ![](https://i.imgur.com/mORlViB.png) Trả lời câu hỏi `Your eldest siblings middle name?` gg search `jim Star Trek` ta thấy tên người anh cả là `Samuel` ![](https://i.imgur.com/etfOgAa.png) ![](https://i.imgur.com/YZ35yi8.png) ## Task 5 AH! Don't look! ### Question #1: Access the Confidential Document! Ở phần About us có link dẫn đến điều khoản ![](https://i.imgur.com/Ct31WSA.png) ![](https://i.imgur.com/DDq8AXN.png) thế nhưng xoá endpoint đi thì trả về folder ftp ![](https://i.imgur.com/y49pVK9.png) mở file `acquisitions.md` và quay lại web là ta được flag ![](https://i.imgur.com/VTrm40E.png) ![](https://i.imgur.com/nd6wp0q.png) ### Question #2: Log into MC SafeSearch's account! We now know the password to the mc.safesearch@juice-sh.op account is "Mr. N00dles" ![](https://i.imgur.com/GmYIeAV.png) ### Question #3: Download the Backup file! Download file `package.json.bak` nhưng bị chặn only .md and .pdf files can be downloaded. ![](https://i.imgur.com/4U2DKMP.png) Bypass bằng null byte `%00` -> urlencode -> `%2500` ![](https://i.imgur.com/af2h15Z.png) ![](https://i.imgur.com/7ucDl9G.png) ![](https://i.imgur.com/fQ6jhCu.png) k hiểu sao loài đây cái flag nữa :))) đem đi submit thì chả đúng cái nào ![](https://i.imgur.com/XUXcLn8.png) ## Task 6 Who's flying this thing? ### Question #1: Access the administration page! ![](https://i.imgur.com/nzCbXq0.png) ![](https://i.imgur.com/OxynDca.png) 403 là vì mình chưa đăng nhập, sau khi đăng nhập là có thể access ![](https://i.imgur.com/abZbGqB.png) ### Question #2: View another user's shopping basket! Dính idor nên ta đổi 1 thành 2 là đc ![](https://i.imgur.com/ogkIAgX.png) ![](https://i.imgur.com/LsnGKU9.png) ![](https://i.imgur.com/9QS5mgb.png) ### Question #3: Remove all 5-star reviews! ![](https://i.imgur.com/Pfs3xeS.png) ![](https://i.imgur.com/xj3IBT3.png) ## Task 7 Where did that come from? ### Question #1: Perform a DOM XSS! ```<iframe src="javascript:alert(`xss`)"> ``` ![](https://i.imgur.com/zF9kS9J.png) ### Question #2: Perform a persistent XSS! ở phần `last-login-ip` có ghi lại ip đăng nhập lần cuối ![](https://i.imgur.com/nJC4Dtn.png) bắt request và thêm header ![](https://i.imgur.com/zkTwjqB.png) ![](https://i.imgur.com/TybsdBw.png) ### Question #3: Perform a reflected XSS! ![](https://i.imgur.com/wOmSRqY.png) ta thay đổi id để xss ![](https://i.imgur.com/2bd8zz3.png) ## Task 8 Exploration! ![](https://i.imgur.com/WHMt7Yb.png)