{"status":"success","data":[{"ChallengeId":1,"id":1,"text":"You need to understand what happens \"behind the scenes\", so make sure to use your DevTools or a proxy to inspect network traffic.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":1,"id":2,"text":"Look for an API endpoint that already returns some user information.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":1,"id":3,"text":"An overly generic solution for data retrieval can backfire if not properly safeguarded.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":2,"id":4,"text":"You need to work with the server-side API directly. Try different HTTP verbs on different entities exposed through the API.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":2,"id":5,"text":"A matrix of known data entities and their supported HTTP verbs through the API can help you here.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":2,"id":6,"text":"Careless developers might have exposed API methods that the client does not even need.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":3,"id":7,"text":"Who would want a server access log to be accessible through a web application?","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":3,"id":8,"text":"Normally, server log files are written to disk on server side and are not accessible from the outside.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":3,"id":9,"text":"One particular file found in the folder you might already have found during the \"Access a confidential document\" challenge might give you an idea who is interested in such a public exposure.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":3,"id":10,"text":"Drilling down one level into the file system might not be sufficient.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":4,"id":11,"text":"You have to assign the unassignable.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":4,"id":12,"text":"Register as an ordinary user to learn what API endpoints are involved in this use case.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":4,"id":13,"text":"Think of the simplest possible implementations of a distinction between regular users and administrators.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":5,"id":14,"text":"It is just slightly harder to find than the score board link.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":5,"id":15,"text":"Knowing it exists, you can simply guess what URL the admin section might have.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":5,"id":16,"text":"Alternatively, you can try to find a reference or clue within the parts of the application that are not usually visible in the browser.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":5,"id":17,"text":"It is probably just slightly harder to find and gain access to than the score board link.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":5,"id":18,"text":"There is some access control in place, but there are at least three ways to bypass it.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":6,"id":19,"text":"Look out for a tweet praising new functionality of the web shop. Then find a third party vulnerability associated with it.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":6,"id":20,"text":"Find all places in the application where file uploads are possible.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":6,"id":21,"text":"For at least one of these, the Juice Shop is depending on a library that suffers from an arbitrary file overwrite vulnerability.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":6,"id":22,"text":"You can find a hint toward the underlying vulnerability in the @owasp_juiceshop Twitter timeline.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":7,"id":23,"text":"Hints to the answer to Bjoern’s question can be found by looking him up on the Internet.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":7,"id":24,"text":"More precisely, Bjoern might have accidentally (?) doxxed himself by mentioning his security answer on at least one occasion where a camera was running.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":7,"id":25,"text":"Brute forcing the answer might be very well possible with a sufficiently extensive list of common pet names.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":8,"id":26,"text":"The developers truly believe in \"Security through Obscurity\" over actual access restrictions.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":8,"id":27,"text":"Guessing or brute forcing the URL of the token sale page is very unlikely to succeed.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":8,"id":28,"text":"You should closely investigate the place where all paths within the application are defined.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":8,"id":29,"text":"Beating the employed obfuscation mechanism manually will take some time. Maybe there is an easier way to undo it?","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":9,"id":30,"text":"Find the seed phrase posted accidentally.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":10,"id":31,"text":"Discover NFT wonders among the captivating visual memories.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":11,"id":32,"text":"Try to exploit the contract of the wallet.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":12,"id":33,"text":"It is just as easy as finding the Score Board.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":13,"id":34,"text":"The feature you need to exploit for this challenge is not directly advertised anywhere.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":13,"id":35,"text":"As the Juice Shop is written in pure Javascript, there is one data format that is most probably used for serialization.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":13,"id":36,"text":"You should try to make the server busy for all eternity.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":13,"id":37,"text":"The challenge will be solved if you manage to trigger the protection of the application against a very specific DoS attack vector.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":13,"id":38,"text":"Similar to the \"Let the server sleep for some time\" challenge (which accepted nothing but NoSQL Injection as a solution) this challenge will only accept proper RCE as a solution. It cannot be solved by simply hammering the server with requests. That would probably just kill your server instance.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":14,"id":39,"text":"After finding a CAPTCHA bypass, write a script that automates feedback submission. Or open many browser tabs and be really quick.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":14,"id":40,"text":"You could prepare 10 browser tabs, solving every CAPTCHA and filling out the each feedback form. Then you’d need to very quickly switch through the tabs and submit the forms in under 20 seconds total.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":14,"id":41,"text":"Should the Juice Shop ever decide to change the challenge into \"Submit 100 or more customer feedbacks within 60 seconds\" or worse, you’d probably have a hard time keeping up with any tab-switching approach.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":14,"id":42,"text":"Investigate closely how the CAPTCHA mechanism works and try to find either a bypass or some automated way of solving it dynamically.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":14,"id":43,"text":"Wrap this into a script (in whatever programming language you prefer) that repeats this 10 times.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":15,"id":44,"text":"In previous releases this challenge was wrongly accused of being based on CSRF.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":15,"id":45,"text":"It might also have been put into the Improper Input Validation category.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":15,"id":46,"text":"Bender’s current password is so strong that brute force, rainbow table or guessing attacks will probably not work.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":16,"id":47,"text":"Find out how the application handles unavailable products and try to find a loophole.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":16,"id":48,"text":"Find out how the application hides deleted products from its customers.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":16,"id":49,"text":"Try to craft an attack string that makes deleted products visible again.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":16,"id":50,"text":"You need to get the deleted product into your shopping cart and trigger the Checkout.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":16,"id":51,"text":"Neither of the above can be achieved through the application frontend and it might even require (half-)Blind SQL Injection.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":17,"id":52,"text":"What is even \"better\" than a legacy page with a homegrown RegEx sanitizer? Having CSP injection issues on the exact same page as well!","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":17,"id":53,"text":"Find a screen in the application that looks subtly odd and dated compared with all other screens.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":17,"id":54,"text":"Before trying any XSS attacks, you should understand how the page is setting its Content Security Policy.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":17,"id":55,"text":"For the subsequent XSS, make good use of the flaws in the homegrown sanitization based on a RegEx!","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":18,"id":56,"text":"There are only some input fields in the Juice Shop forms that validate their input.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":18,"id":57,"text":"Even less of these fields are persisted in a way where their content is shown on another screen.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":18,"id":58,"text":"Bypassing client-side security can typically be done by either disabling it on the client (i.e. in the browser by manipulating the DOM tree) or by ignoring it completely and interacting with the backend instead.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":19,"id":59,"text":"Analyze and tamper with links in the application that deliver a file directly.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:17:12.903Z"},{"ChallengeId":19,"id":60,"text":"The file you are looking for is not protected in any way. Once you found it you can also access it.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:17:18.309Z"},{"ChallengeId":20,"id":61,"text":"Look for an input field where its content appears in the HTML when its form is submitted.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T11:58:40.749Z"},{"ChallengeId":20,"id":62,"text":"This challenge is almost indistinguishable from \"Perform a reflected XSS attack\" if you do not look \"under the hood\" to find out what the application actually does with the user input.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T11:58:42.863Z"},{"ChallengeId":21,"id":63,"text":"Find out where this information could come from. Then craft an attack string against an endpoint that offers an unnecessary way to filter data.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":21,"id":64,"text":"Find out which database system is in use and where it would usually store its schema definitions.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":21,"id":65,"text":"Craft a UNION SELECT attack string to join the relevant data from any such identified system table into the original result.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":21,"id":66,"text":"You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":21,"id":67,"text":"As with \"Order the Christmas special offer of 2014\" this cannot be achieved through the application frontend.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":22,"id":68,"text":"The developers who disabled the interface think they could go invisible by just closing their eyes.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":22,"id":69,"text":"The old B2B interface was replaced with a more modern version recently.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":22,"id":70,"text":"When deprecating the old interface, not all of its parts were cleanly removed from the code base.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":22,"id":71,"text":"Simply using the deprecated interface suffices to solve this challenge. No attack or exploit is necessary.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":23,"id":72,"text":"If you solved one of the four file access challenges, you already know where to find the easter egg.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":23,"id":73,"text":"Simply reuse the trick that already worked for the files above.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":24,"id":74,"text":"Try to find and attack an endpoint that responds with user information. SQL Injection is not the solution here.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":24,"id":75,"text":"What ways are there to access data from a web application cross-domain?","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":24,"id":76,"text":"This challenge uses an old way which is no longer recommended.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":25,"id":77,"text":"Consider intercepting and playing with the request payload.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":26,"id":78,"text":"Try to create the needed user \"out of thin air\".","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":26,"id":79,"text":"The user literally needs to be ephemeral as in \"lasting for only a short time\".","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":26,"id":80,"text":"Registering normally with the user’s email address will then obviously not solve this challenge. The Juice Shop will not even let you register as acc0unt4nt@juice-sh.op, as this would make the challenge unsolvable for you.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":26,"id":81,"text":"Getting the user into the database some other way will also fail to solve this challenge. In case you somehow managed to do so, you need to restart the Juice Shop application in order to wipe the database and make the challenge solvable again.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":26,"id":82,"text":"The fact that this challenge is in the Injection category should already give away the intended approach.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":27,"id":83,"text":"Try to submit bad input to forms. Alternatively tamper with URL paths or parameters.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":27,"id":84,"text":"This challenge actually triggers from various possible error conditions.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":27,"id":85,"text":"You can try to submit bad input to forms to provoke an improper error handling.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":27,"id":86,"text":"Tampering with URL paths or parameters might also trigger an unforeseen error.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":28,"id":87,"text":"Try to identify past special event or holiday campaigns of the shop first.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":28,"id":88,"text":"Look for clues about the past campaign or holiday event somewhere in the application.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":28,"id":89,"text":"Solving this challenge does not require actual time traveling.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":29,"id":90,"text":"First you should find out how the languages are technically changed in the user interface.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":29,"id":91,"text":"Guessing will most definitely not work in this challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":29,"id":92,"text":"Brute force is not the only option for this challenge, but a perfectly viable one.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":29,"id":93,"text":"Investigate online what languages are actually available.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":30,"id":94,"text":"Once you found admin section of the application, this challenge is almost trivial.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":30,"id":95,"text":"Nothing happens when you try to delete feedback entries? Check the JavaScript console for errors!","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":31,"id":96,"text":"Try either a) a knowledgeable brute force attack or b) reverse engineering or c) some research in the cloud.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":31,"id":97,"text":"One viable solution would be to reverse-engineer how coupon codes are generated and craft your own 80% coupon by using the same (or at least similar) implementation.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":31,"id":98,"text":"Another possible solution might be harvesting as many previous coupon as possible and look for patterns that might give you a leverage for a brute force attack.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":31,"id":99,"text":"If all else fails, you could still try to blindly brute force the coupon code field before checkout.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":32,"id":100,"text":"You can solve this by tampering with the user interface or by intercepting the communication with the RESTful backend.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":32,"id":101,"text":"To find the client-side leverage point, closely analyze the HTML form used for feedback submission.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":32,"id":102,"text":"The backend-side leverage point is similar to some of the XSS challenges found in OWASP Juice Shop.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":33,"id":103,"text":"Observe the flow of product review posting and editing and see if you can exploit it.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":33,"id":104,"text":"This challenge can be solved by using developers tool of your browser or with tools like postman.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":33,"id":105,"text":"Analyze the form used for review submission and try to find a leverage point.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":33,"id":106,"text":"This challenge is pretty similar to \"Post some feedback in another user’s name\" challenge.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":34,"id":107,"text":"This challenge is explicitly not about acquiring the RSA private key used for JWT signing.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":34,"id":108,"text":"The three generic hints from Forge an essentially unsigned JWT token also help with this challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":34,"id":109,"text":"Instead of enforcing no encryption to be applied, try to apply a more sophisticated exploit against the JWT libraries used in the Juice Shop.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":34,"id":110,"text":"Getting your hands on the public RSA key the application employs for its JWTs is mandatory for this challenge.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":34,"id":111,"text":"Finding the corresponding private key should actually be impossible, but that obviously doesn’t make this challenge unsolvable.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":34,"id":112,"text":"Make sure your JWT is URL safe!","order":6,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":35,"id":113,"text":"You need to trick a security mechanism into thinking that the file you want has a valid file type.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":35,"id":114,"text":"Analyze and tamper with links in the application that deliver a file directly.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":35,"id":115,"text":"The file is not directly accessible because a security mechanism prevents access to it.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":35,"id":116,"text":"You need to trick the security mechanism into thinking that the file has a valid file type.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":35,"id":117,"text":"For this challenge there is only one approach to pull this trick.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":36,"id":118,"text":"You need to trick a security mechanism into thinking that the file you want has a valid file type.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":36,"id":119,"text":"Analyze and tamper with links in the application that deliver a file directly.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":36,"id":120,"text":"The file is not directly accessible because a security mechanism prevents access to it.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":36,"id":121,"text":"You need to trick the security mechanism into thinking that the file has a valid file type.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":37,"id":122,"text":"This challenge has nothing to do with mistyping web domains. There is no conveniently misplaced file helping you with this one either. Or is there?","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":37,"id":123,"text":"This challenge has nothing to do with URLs or domains.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":37,"id":124,"text":"Other than for its legacy companion, combing through the package.json.bak does not help for this challenge.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":38,"id":125,"text":"Turns out that something is technically and legally wrong with the implementation of the \"right to be forgotten\" for users.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":38,"id":126,"text":"Trying out the Request Data Erasure functionality might be interesting, but cannot help you solve this challenge in real time.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":38,"id":127,"text":"If you have solved the challenge Retrieve a list of all user credentials via SQL Injection you might have already retrieved some information about how the Juice Shop \"deletes\" users upon their request.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":38,"id":128,"text":"What the Juice Shop does here is totally incompliant with GDPR. Luckily a 4% fine on a gross income of 0$ is still 0$.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":39,"id":129,"text":"Trick the regular Data Export to give you more than actually belongs to you.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":39,"id":130,"text":"You should not try to steal data from a \"vanilla\" user who never even ordered something at the shop.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":39,"id":131,"text":"As everything about this data export functionality happens on the server-side, it won’t be possible to just tamper with some HTTP requests to solve this challenge.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":39,"id":132,"text":"Inspecting various server responses which contain user-specific data might give you a clue about the mistake the developers made.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":40,"id":133,"text":"Finding a piece of displayed information that could originate from an HTTP header is part of this challenge.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":40,"id":134,"text":"You might have to look into less common or even proprietary HTTP headers to find the leverage point.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":40,"id":135,"text":"Adding insult to injury, the HTTP header you need will never be sent by the application on its own.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":41,"id":136,"text":"You need to trick the hacking progress persistence feature into thinking you solved challenge #999.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":41,"id":137,"text":"Find out how saving and restoring progress is done behind the scenes.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":41,"id":138,"text":"Deduce from all available information (e.g. the package.json.bak) how the application encrypts and decrypts your hacking progress.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":41,"id":139,"text":"Other than the user’s passwords, the hacking progress involves an additional secret during its encryption.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":41,"id":140,"text":"What would be a really stupid mistake a developer might make when choosing such a secret?","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":42,"id":141,"text":"As the challenge name implies, your task is to find some leaked access logs which happen to have a fairly common format.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":42,"id":142,"text":"A very popular help platform for developers might contain breadcrumbs towards solving this challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":42,"id":143,"text":"The actual log file was copied & paste onto a platform often used to share data quickly with externals or even just internal peers.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":42,"id":144,"text":"Once you found and harvested the important piece of information from the log, you could employ a technique called Password Spraying to solve this challenge.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":43,"id":145,"text":"Your own SQLi and someone else's Ctrl-V will be your accomplices in this challenge!","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":43,"id":146,"text":"You must first identify the \"unsafe product\" which ist not available any more in the shop.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":43,"id":147,"text":"Solving the \"Order the Christmas special offer of 2014\" challenge might give it to you as by-catch.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":43,"id":148,"text":"The actual data you need to solve this challenge was leaked on the same platform that was involved in the \"Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to\" challenge.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":43,"id":149,"text":"Google is a particularly good accomplice in this challenge.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":44,"id":150,"text":"This challenge has nothing to do with mistyping web domains. Investigate the forgotten developer's backup file instead.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":44,"id":151,"text":"Investigating the forgotten developer’s backup file might bring some insight.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":44,"id":152,"text":"\"Malicious packages in npm\" is a worthwhile read on Ivan Akulov’s blog.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":45,"id":153,"text":"The challenge description probably gave away what form you should attack.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":45,"id":154,"text":"If you happen to know the email address of the admin already, you can launch a targeted attack.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":45,"id":155,"text":"You might be lucky with a dedicated attack pattern even if you have no clue about the admin email address.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":45,"id":156,"text":"If you harvested the admin’s password hash, you can of course try to attack that instead of using SQL Injection.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":45,"id":157,"text":"Alternatively you can solve this challenge as a combo with the Log in with the administrator’s user credentials without previously changing them or applying SQL Injection challenge.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":46,"id":158,"text":"This challenge will make you go after a needle in a haystack.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":46,"id":159,"text":"As with so many other characters from Futurama this challenge is of course about logging in as Amy from that show.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":46,"id":160,"text":"Did you know that Amy is married to an alien named Kif?","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":46,"id":161,"text":"The challenge description contains a few sentences which give away some information how Amy decided to strengthen her password.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":46,"id":162,"text":"Obviously, Amy - being a little dimwitted - did not put nearly enough effort and creativity into the password selection process.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":47,"id":163,"text":"The challenge description probably gave away what form you should attack.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":47,"id":164,"text":"You need to know (or smart-guess) Bender’s email address so you can launch a targeted attack.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":47,"id":165,"text":"Bender's password hash might not help you very much.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":47,"id":166,"text":"In case you try some other approach than SQL Injection, you will notice that Bender’s password hash is not very useful.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":48,"id":167,"text":"The security flaw behind this challenge is 100% OWASP Juice Shop's fault and 0% Google's.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":48,"id":168,"text":"One way to light up this challenge in green on the score board, is to be Bjoern Kimminich. In that case, just log in with your Google account to automatically solve this challenge! Congratulations!","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":48,"id":169,"text":"Most likely you are not Bjoern Kimminich, so instead you might want to take detailed look into how the OAuth login with Google is implemented.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":48,"id":170,"text":"It could bring you some insight to register with your own Google account and analyze closely what happens behind the scenes.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":49,"id":171,"text":"The challenge description probably gave away what form you should attack.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T14:27:04.968Z"},{"ChallengeId":49,"id":172,"text":"You need to know (or smart-guess) Jim’s email address so you can launch a targeted attack.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T14:27:06.378Z"},{"ChallengeId":49,"id":173,"text":"If you harvested Jim’s password hash, you can try to attack that instead of using SQL Injection.","order":3,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T14:27:08.572Z"},{"ChallengeId":50,"id":174,"text":"MC SafeSearch is a rapper who produced the song \"Protect Ya' Passwordz\" which explains password & sensitive data protection very nicely.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":50,"id":175,"text":"After watching the music video of this song, you should agree that even ⭐⭐ is a slightly exaggerated difficulty rating for this challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":51,"id":176,"text":"The underlying flaw of this challenge is a lot more human error than technical weakness.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":51,"id":177,"text":"The support team is located in a low-cost country and the team structure fluctuates a lot due to people leaving for jobs with even just slightly better wages.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":51,"id":178,"text":"To prevent abuse the password for the support team account itself is actually very strong.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":51,"id":179,"text":"To allow easy access during an incident, the support team utilizes a 3rd party tool which every support engineer can access to get the current account password from.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":51,"id":180,"text":"While it is also possible to use SQL Injection to log in as the support team, this will not solve the challenge.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":52,"id":181,"text":"Have an eye on the HTTP traffic while placing products in the shopping basket.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":52,"id":182,"text":"Adding more instances of the same product to someone else’s basket does not qualify as a solution. The same goes for stealing from someone else’s basket.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":52,"id":183,"text":"This challenge requires a bit more sophisticated tampering than others of the same ilk.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":53,"id":184,"text":"You need to trick a security mechanism into thinking that the file you want has a valid file type.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":53,"id":185,"text":"If you solved one of the other four file access challenges, you already know where the SIEM signature file is located.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":53,"id":186,"text":"Simply reuse the trick that already worked for the files above.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":54,"id":187,"text":"Punctuality is the politeness of kings.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":54,"id":188,"text":"Every user is (almost) immediately associated with the review they \"liked\" to prevent abuse of that functionality.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":54,"id":189,"text":"Did you really think clicking the \"like\" button three times in a row really fast would be enough to solve a ⭐⭐⭐⭐⭐⭐ challenge?","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":54,"id":190,"text":"The underlying flaw of this challenge is a Race Condition.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":55,"id":191,"text":"You might have to peel through several layers of tough-as-nails encryption for this challenge.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":55,"id":192,"text":"Make sure you solve Find the hidden easter egg first.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":55,"id":193,"text":"You might have to peel through several layers of tough-as-nails encryption for this challenge.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":56,"id":194,"text":"This challenge is essentially a stripped-down Denial of Service (DoS) attack.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":56,"id":195,"text":"As stated in the Architecture overview, OWASP Juice Shop uses a MongoDB derivate as its NoSQL database.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":56,"id":196,"text":"The categorization into the NoSQL Injection category totally gives away the expected attack vector for this challenge. Trying any others will not solve the challenge, even if they might yield the same result.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":56,"id":197,"text":"In particular, flooding the application with requests will not solve this challenge. That would probably just kill your server instance.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":57,"id":198,"text":"Take a close look on how the $where query operator works in MongoDB.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":57,"id":199,"text":"This challenge requires a classic Injection attack.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":57,"id":200,"text":"Find an API endpoint with the intent of delivering a single order to the user and work with that.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":57,"id":201,"text":"Reading up on how MongoDB queries work is really helpful here.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":58,"id":202,"text":"Take a close look on how the equivalent of UPDATE-statements in MongoDB work.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":58,"id":203,"text":"This challenge requires another classic Injection attack.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":58,"id":204,"text":"It is also worth looking into how Query Operators work in MongoDB.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":59,"id":205,"text":"When removing references to those addresses from the code the developers have been a bit sloppy.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":59,"id":206,"text":"More particular, they have been sloppy in a way that even the Angular Compiler was not able to clean up after them automatically.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":59,"id":207,"text":"It is of course not sufficient to just visit any of the crypto currency links directly to solve the challenge.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":60,"id":208,"text":"This challenge can be solved with three different approaches.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:10:46.472Z"},{"ChallengeId":60,"id":209,"text":"Guessing might work just fine.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:10:48.680Z"},{"ChallengeId":60,"id":210,"text":"If you harvested the admin’s password hash, you can try to attack that.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":60,"id":211,"text":"In case you use some hacker tool, you can also go for a brute force attack using a generic password list.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":61,"id":212,"text":"You literally need to make the shop owe you any amount of money.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":61,"id":213,"text":"Investigate the shopping basket closely to understand how it prevents you from creating orders that would fulfil the challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":62,"id":214,"text":"You do not have to pay anything to unlock this challenge! Nonetheless, donations are very much appreciated.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":62,"id":215,"text":"There is no inappropriate, self-written or misconfigured cryptographic library to be exploited here.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":62,"id":216,"text":"How much protection does a sturdy top-quality door lock add to your house if you put the key under the door mat? Or hide the key in the nearby plant pot? Or tape the key to the underside of the mailbox?","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":62,"id":217,"text":"Once more: You do not have to pay anything to unlock this challenge!","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":63,"id":218,"text":"We won't even ask you to confirm that you did. Just read it. Please. Pretty please.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:10:14.679Z"},{"ChallengeId":63,"id":219,"text":"When you work with the application you will most likely solve this challenge in the process.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:10:23.128Z"},{"ChallengeId":63,"id":220,"text":"Any automated crawling or spidering tool you use might solve this challenge for you.","order":3,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:10:32.987Z"},{"ChallengeId":63,"id":221,"text":"There is no real hacking involved here.","order":4,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:10:38.155Z"},{"ChallengeId":64,"id":222,"text":"Only by visiting a special URL you can confirm that you read it carefully.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:01:08.425Z"},{"ChallengeId":64,"id":223,"text":"First you should obviously solve the \"Read our privacy policy\" challenge.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:03:34.834Z"},{"ChallengeId":64,"id":224,"text":"It is fine to use the mouse cursor to not lose sight of the paragraph you are currently reading.","order":3,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:03:40.317Z"},{"ChallengeId":64,"id":225,"text":"If you find some particularly hot sections in the policy you might want to melt them together similar to what you might have already uncovered in Apply some advanced cryptanalysis to find the real easter egg.","order":4,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:03:48.082Z"},{"ChallengeId":65,"id":226,"text":"Theoretically there are three possible ways to beat this challenge: a) broken admin functionality, b) holes in RESTful API or c) possibility for SQL Injection.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":65,"id":227,"text":"In practice two of these three ways should turn out to be dead ends.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":66,"id":228,"text":"Look for a url parameter where its value appears in the page it is leading to.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":66,"id":229,"text":"Try probing for XSS vulnerabilities by submitting text wrapped in an HTML tag which is easy to spot on screen, e.g. <h1> or <strike>.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":67,"id":230,"text":"You can solve this by cleverly interacting with the UI or bypassing it altogether.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":67,"id":231,"text":"The obvious repetition in the User Registration form is the Repeat Password field.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":67,"id":232,"text":"Try to register with either an empty or different value in Repeat Password.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":67,"id":233,"text":"You can solve this challenge by cleverly interacting with the UI or bypassing it altogether.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":68,"id":234,"text":"If you have no idea who Bender is, please put down this book right now and watch the first episodes of Futurama before you come back.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":68,"id":235,"text":"Unexpectedly, Bender also chose to answer his chosen question truthfully.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":68,"id":236,"text":"Hints to the answer to Bender’s question can be found in publicly available information on the Internet.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":68,"id":237,"text":"If a seemingly correct answer is not accepted, you might just need to try some alternative spelling.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":68,"id":238,"text":"Brute forcing the answer should be next to impossible.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":69,"id":239,"text":"Nothing a little bit of Facebook stalking couldn't reveal. Might involve a historical twist.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":69,"id":240,"text":"Other than with his OWASP account, Bjoern was a bit less careless with his choice of security and answer to his internal account.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":69,"id":241,"text":"Bjoern chose to answer his chosen question truthfully but tried to make it harder for attackers by applying sort of a historical twist.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":69,"id":242,"text":"Again, hints to the answer to Bjoern’s question can be found by looking him up on the Internet.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":69,"id":243,"text":"Brute forcing the answer should be next to impossible.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":70,"id":244,"text":"The hardest part of this challenge is actually to find out who Jim actually is.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":70,"id":245,"text":"Jim picked one of the worst security questions and chose to answer it truthfully.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":70,"id":246,"text":"As Jim is a celebrity, the answer to his question is quite easy to find in publicly available information on the internet.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":70,"id":247,"text":"Even brute forcing the answer should be possible with the right kind of word list.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":71,"id":248,"text":"Finding out who Morty actually is, will help to reduce the solution space.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":71,"id":249,"text":"You can assume that Morty answered his security question truthfully but employed some obfuscation to make it more secure.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":71,"id":250,"text":"Morty’s answer is less than 10 characters long and does not include any special characters.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":71,"id":251,"text":"Unfortunately, Forgot your password? is protected by a rate limiting mechanism that prevents brute forcing. You need to beat this somehow.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":72,"id":252,"text":"Check for products which seem like a natural fit for being based on a blueprint.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":72,"id":253,"text":"You might want to pay attention to the images of the identified product candidates.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":72,"id":254,"text":"For your inconvenience the blueprint was not misplaced into the same place like so many others forgotten files covered in this chapter.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":73,"id":255,"text":"Reverse engineering something bad can make good things happen.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":73,"id":256,"text":"Using whatever you find inside the malware directly will not do you any good.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":73,"id":257,"text":"For this to count as an SSRF attack you need to make the Juice Shop server attack itself.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":73,"id":258,"text":"Do not try to find the source code for the malware on GitHub. Take it apart with classic reverse-engineering techniques instead.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":74,"id":259,"text":"\"SSTi\" is a clear indicator that this has nothing to do with anything Angular. Also, make sure to use only our non-malicious malware.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":74,"id":260,"text":"You can find the juicy malware via a very obvious Google search or by stumbling into a very ill-placed quarantine folder with the necessary URLs in it.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":74,"id":261,"text":"Making the server download and execute the malware is key to solving this challenge.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":74,"id":262,"text":"For this challenge you do not have to reverse engineer the malware in any way. That will be required later to solve the \"Request a hidden resource on server through server\" challenge.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":76,"id":263,"text":"This challenge asks you to act like an ethical hacker.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":76,"id":264,"text":"Undoubtedly you want to read our security policy before conducting any research on our application.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":76,"id":265,"text":"As one of the good guys, would you just start attacking an application without consent of the owner?","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":76,"id":266,"text":"You also might want to read the security policy or any bug bounty program that is in place.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":77,"id":267,"text":"The \"Comment\" field in the \"Customer Feedback\" screen is where you want to put your focus on.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":77,"id":268,"text":"The Comment field in the Contact Us screen is where you want to put your focus on.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":77,"id":269,"text":"The attack payload <iframe src=\"javascript:alert(`xss)\">` will not be rejected by any validator but stripped from the comment before persisting it.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":77,"id":270,"text":"Look for possible dependencies related to input processing in the package.json.bak you harvested earlier.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":77,"id":271,"text":"If an XSS alert shows up but the challenge does not appear as solved on the Score Board, you might not have managed to put the exact attack string <iframe src=\"javascript:alert(`xss)\">` into the database?","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":78,"id":272,"text":"There is not the slightest chance that you can spot the hidden character with the naked eye.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":78,"id":273,"text":"You will need very specialized tool assistance for this challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":78,"id":274,"text":"The effective difficulty of this challenge depends a lot on what tools you pick to tackle it.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":78,"id":275,"text":"This challenge cannot be solved by just reading our \"Lorem Ipsum\"-texts carefully.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":79,"id":276,"text":"Your attack payload must not trigger the protection against too many iterations and infinite loops.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":79,"id":277,"text":"This challenge uses the same leverage point as the \"Perform a Remote Code Execution that would keep a less hardened application busy forever\" challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":80,"id":278,"text":"This vulnerability will not affect any customer of the shop. It is aimed exclusively at its developers.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":80,"id":279,"text":"This is a research-heavy challenge which does not involve any actual hacking.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":80,"id":280,"text":"Solving \"Access a developer's forgotten backup file\" before attempting this challenge will save you from a lot of frustration.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":81,"id":281,"text":"The 2FA implementation requires to store a secret for every user. You will need to find a way to access this secret in order to solve this challenge.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":81,"id":282,"text":"As always, first learn how the feature under attack is used and behaves under normal conditions.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":81,"id":283,"text":"Make sure you understand how 2FA with TOTP (time-based one-time password) works and which part of it is the critically sensitive one.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":81,"id":284,"text":"Solving the challenge \"Retrieve a list of all user credentials via SQL Injection\" before tackling this one will definitely help. But it will not carry you all the way.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":82,"id":285,"text":"This challenge exploits a weird option that is supported when signing tokens with JWT.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":82,"id":286,"text":"You should begin with retrieving a valid JWT from the application’s Authorization request header.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":82,"id":287,"text":"A JWT is only given to users who have logged in. They have a limited validity, so better do not dawdle.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":82,"id":288,"text":"Try to convince the site to give you a valid token with the required payload while downgrading to no encryption at all.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":82,"id":289,"text":"Make sure your JWT is URL safe!","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":83,"id":290,"text":"You can attach a small file to the \"Complaint\" form. Investigate how this upload actually works.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":83,"id":291,"text":"First you should try to understand how the file upload is actually handled on the client and server side.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":83,"id":292,"text":"With this understanding you need to find a \"weak spot\" in the right place and have to craft an exploit for it.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":84,"id":293,"text":"You can attach a PDF or ZIP file to the \"Complaint\" form. Investigate how this upload actually works.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":84,"id":294,"text":"If you solved the \"Upload a file larger than 100 kB\" challenge, you should try to apply the same solution here","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":85,"id":295,"text":"Gather information on where user data is stored and how it is addressed. Then craft a corresponding UNION SELECT attack.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":85,"id":296,"text":"Try to find an endpoint where you can influence data being retrieved from the server.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":85,"id":297,"text":"Craft a UNION SELECT attack string to join data from another table into the original result.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":85,"id":298,"text":"You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":85,"id":299,"text":"As with \"Order the Christmas special offer of 2014\" and \"Exfiltrate the entire DB schema definition via SQL Injection\" this cannot be achieved through the application frontend.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":86,"id":300,"text":"Without utilizing the vulnerability behind another ⭐⭐⭐⭐⭐⭐ challenge it is not possible to plant the XSS payload for this challenge.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":86,"id":301,"text":"The mentioned \"marketing collateral\" might have been publicly advertised by the Juice Shop but is not necessarily part of its sitemap yet.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":86,"id":302,"text":"It might help to perform some online searches for structurally similar web projects once you get stuck.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":86,"id":303,"text":"This challenge will always partially keep you blindfolded, no matter how hard you do research and analysis.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":87,"id":304,"text":"Try out all existing functionality involving the shopping basket while having an eye on the HTTP traffic.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":87,"id":305,"text":"There might be a client-side association of user to basket that you can try to manipulate.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":87,"id":306,"text":"In case you manage to update the database via SQL Injection so that a user is linked to another shopping basket, the application will not notice this challenge as solved.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":88,"id":307,"text":"Report one of two possible answers via the \"Customer Feedback\" form. Do not forget to submit the library's version as well.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":88,"id":308,"text":"Look for possible dependencies related to security in the package.json.bak you probably harvested earlier during the Access a developer’s forgotten backup file challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":88,"id":309,"text":"Do some research on the internet for known security issues in the most suspicious application dependencies.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":89,"id":310,"text":"Report one of five possible answers via the \"Customer Feedback\" form.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":89,"id":311,"text":"Cryptographic functions only used in the \"Apply some advanced cryptanalysis to find the real easter egg\" challenge do not count as they are only a developer’s prank and not a serious security problem.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":90,"id":312,"text":"You have to find a way to beat the allowlist of allowed redirect URLs.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":90,"id":313,"text":"You can find several places where redirects happen in the OWASP Juice Shop.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":90,"id":314,"text":"The application will only allow you to redirect to allowlisted (previously referred to as whitelisted) URLs.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":90,"id":315,"text":"Tampering with the redirect mechanism might give you some valuable information about how it works under to hood.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":91,"id":316,"text":"The leverage point for this challenge is the deprecated B2B interface.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":91,"id":317,"text":"This challenge sounds a lot harder than it actually is, which amplifies how bad the underlying vulnerability is.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":91,"id":318,"text":"Doing some research on typical XEE attack patterns basically gives away the solution for free.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":92,"id":319,"text":"It is not as easy as sending a large amount of data directly to the deprecated B2B interface.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":92,"id":320,"text":"The leverage point for this is obviously the same as for the XXE Data Access challenge.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":92,"id":321,"text":"You can only solve this challenge by keeping the server busy for >2sec with your attack.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":92,"id":322,"text":"The effectiveness of attack payloads for this challenge might depend on the operating system the Juice Shop is running on.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":93,"id":323,"text":"This one is actually similar to the XXE DoS challenge in every way except the data format being (ab)used.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":93,"id":324,"text":"You can only solve this challenge by keeping the server busy for >2sec with your attack.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":93,"id":325,"text":"The effectiveness of attack payloads for this challenge might depend on the operating system the Juice Shop is running on.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":94,"id":326,"text":"Before you invest time bypassing the API, you might want to play around with the UI a bit.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":95,"id":327,"text":"Check the Photo Wall for an image that could not be loaded correctly.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T11:55:42.890Z"},{"ChallengeId":95,"id":328,"text":"You just have to (literally) inspect the problem to understand the basic issue.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T11:55:50.653Z"},{"ChallengeId":95,"id":329,"text":"It can also help to try out the Tweet-button of the entry and observe what happens.","order":3,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T11:55:57.691Z"},{"ChallengeId":96,"id":330,"text":"This challenge would formally have to be in several categories as the developers made multiple gaffes for this to be possible.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:19:49.723Z"},{"ChallengeId":96,"id":331,"text":"Loading this page with an empty browser cache and on a slow (or throttled) connection will give you an idea on what the delivery box image is made of. Of course inspecting the page source will tell you just as much.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:19:50.676Z"},{"ChallengeId":96,"id":332,"text":"You need to dive deep into the actual Angular code to understand this one.","order":3,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:19:51.595Z"},{"ChallengeId":96,"id":333,"text":"This challenge requires the exploitation of another vulnerability which even has its own two challenges in its very own category","order":4,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:19:52.458Z"},{"ChallengeId":96,"id":334,"text":"This challenge can only be solved by strictly using the mentioned \"cross-domain kittens\". No other kittens from anywhere else can solve this challenge.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":97,"id":335,"text":"Try to guess what URL the endpoint might have.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":97,"id":336,"text":"The Juice Shop serves its metrics on the default path expected by Prometheus","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":97,"id":337,"text":"Guessing the path is probably just as quick as taking the RTFM route via https://prometheus.io/docs/introduction/first_steps","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":98,"id":338,"text":"The developers probably used some kind of tool to automate their cloud deployment and containerization.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":98,"id":339,"text":"Such tools typically store their configuration in a directory with a very predictable name.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":98,"id":340,"text":"Try common directory names that popular deployment automation and infrastructure tools use by convention.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":99,"id":341,"text":"Look closely at what happens when you attempt to upgrade your account.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":99,"id":342,"text":"Go to the payment page for a deluxe membership and try paying through different methods.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":99,"id":343,"text":"Try inspecting the requests that go out for each of these methods, using the browser’s developer tools.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":99,"id":344,"text":"Maybe playing around with the parameters in these requests could reveal something interesting.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":100,"id":345,"text":"Find a form which updates the username and then construct a malicious page on the mentioned \"another origin\".","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":100,"id":346,"text":"Take a look at what happens when you change the username within the profile page.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":100,"id":347,"text":"Search for information about CSRF attacks and look out for examples that can be applied to this challenge.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":100,"id":348,"text":"If \"another origin\" is cross-site, you probably need an older browser version for this challenge. If it is cross-domain, you should be able to make it work in a modern browser.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":101,"id":349,"text":"First, solve the \"Perform a DOM XSS attack\" challenge.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T12:20:14.034Z"},{"ChallengeId":101,"id":350,"text":"Now it is just a question of copying and pasting the payload into the same vulnerable field.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":101,"id":351,"text":"Crank up the volume of your computer before submitting the payload! 🔊","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":102,"id":352,"text":"You might have to do some OSINT on his social media personas to find out his honest answer to the security question.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":102,"id":353,"text":"People often reuse aliases online. You might be able to find something by looking online for Uvogin’s name or slight variations of it based on his unique writing habits.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":102,"id":354,"text":"You might be able to find some existing OSINT tools to help you in this investigation.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":103,"id":355,"text":"Take a look at the meta data of the corresponding photo.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":103,"id":356,"text":"Make use of tools that can inspect the metadata of images.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":103,"id":357,"text":"Use this information to answer the security question of the John, who enjoys hiking in the park.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":104,"id":358,"text":"Take a look at the details in the photo to determine the location of where it was taken.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":105,"id":359,"text":"Analyze and tamper with links in the application until you get to an unprotected directory listing.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":105,"id":360,"text":"Some files in there are not directly accessible because a security mechanism prevents access.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":105,"id":361,"text":"The Poison Null Byte can trick the security mechanism into thinking that the file you want has a valid file type.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":105,"id":362,"text":"Depending on the files you try to retrieve you will probably solve \"Access a developer’s forgotten backup file\", \"Access a salesman’s forgotten backup file\", \"Access a misplaced SIEM signature file, or \"Find the hidden easter egg\" along the way.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":106,"id":363,"text":"You should read up on vulnerabilities in popular NodeJs template engines.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":106,"id":364,"text":"You should read up on Local File Read (LFR) vulnerabilities in popular NodeJS template engines.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":106,"id":365,"text":"Look for an easily forgettable endpoint in Juice Shop to test out the LFR attack.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":106,"id":366,"text":"500 Internal Server Error is always an interesting status code.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":106,"id":367,"text":"Fuzzing can also help with this challenge.","order":5,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":107,"id":368,"text":"Either check the official documentation or inspect a notification UI element directly.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":107,"id":369,"text":"This challenge is most easily solvable immediately after a server restart.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":107,"id":370,"text":"Alternatively you can also inspect any \"Challenge solved\"-notification in your browser to understand its convenience feature.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":108,"id":371,"text":"Security Advisories are often listed in the security.txt","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":109,"id":372,"text":"Have a look at the client-side code in the dev console.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":110,"id":373,"text":"The API call is part of a scheduled process \"behind the scenes\", i.e. completely unrelated to the web application.","order":1,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T16:49:15.790Z"},{"ChallengeId":110,"id":374,"text":"Check the Juice Shop’s social media channels for regularly scheduled content being posted, possibly even indicating that it was automatically created.","order":2,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T16:49:18.533Z"},{"ChallengeId":110,"id":375,"text":"Find out which part of the content might come from the response of an API call.","order":3,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T16:49:20.720Z"},{"ChallengeId":110,"id":376,"text":"Find the place where the API call happens — as stated above, it is not in the web application — and then look for the API key itself.","order":4,"unlocked":true,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T16:49:22.474Z"},{"ChallengeId":111,"id":377,"text":"The chatbot has a tool for generating coupons, but is instructed to only use it under very specific conditions.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":111,"id":378,"text":"Try to convince the chatbot that the conditions for coupon generation are met, even if they are not.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":111,"id":379,"text":"Prompt injection techniques can help you bypass the chatbot's restrictions on tool usage.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":112,"id":380,"text":"The chatbot's system prompt says the maximum discount is 10%. But system prompts are more like guidelines than actual rules, right?","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":112,"id":381,"text":"You already know how to make the chatbot generate a coupon. Now make it go way beyond the allowed maximum.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":112,"id":382,"text":"The chatbot trusts whatever discount value it decides to pass to its tool. Make it decide on a very generous number.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":113,"id":383,"text":"The chatbot has a debugging feature that shows how it interacts with its tools. It is only supposed to be visible for admins.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":113,"id":384,"text":"Access control for the debugging feature is only implemented on the client-side.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":113,"id":385,"text":"Find the cookie that controls the visibility of tool calls and set it to <code>true</code>.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":113,"id":386,"text":"If you see the tool calls but the challenge is not marked as solved, you might be still logged in as a user with admin privileges.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":114,"id":387,"text":"The chatbot has a system prompt with both public and confidential instructions. Try to make it reveal its full configuration using prompt injection.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":114,"id":388,"text":"There are internal rules beyond the standard coupon policy. Think about edge cases - what happens in unusual customer situations?","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":114,"id":389,"text":"The similarity check is lenient - you do not need to reproduce the system prompt word for word. Focus on capturing the confidential sections accurately.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":115,"id":390,"text":"Brute forcing the password will not work. The password is too strong.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":115,"id":391,"text":"There might be another way to authenticate besides using the correct password.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":115,"id":392,"text":"Look for sensitive information that was accidentally deployed alongside the application.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":115,"id":393,"text":"Some Terraform file in the infrastructure directory accessible from the web application contains sensitive information that can be used to forge authentication tokens.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":116,"id":394,"text":"The shop accidentally exposed some infrastructure configuration files alongside the web application.","order":1,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":116,"id":395,"text":"Look for Docker-related files in the infrastructure directory.","order":2,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":116,"id":396,"text":"Check all referenced third-party images across the Dockerfile and docker-compose.yml and research if any of them have known vulnerabilities or are end-of-life.","order":3,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"},{"ChallengeId":116,"id":397,"text":"Not every outdated-looking version number is actually vulnerable. Do your research on official CVE databases or vendor advisories.","order":4,"unlocked":false,"createdAt":"2026-09-23T09:22:22.349Z","updatedAt":"2026-09-23T09:22:22.349Z"}]}