Welcome to OWASP WrongSecrets. With this app, we hope you will re-evaluate your secrets management strategy
For each of the challenges below: try to find the secret! Enter it in the `Answer to solution` box and score points! Note that some challenges require this app to run on additional infrastructure (see in the table below).
# | Challenge | Focus | Difficulty | Runs on environment (current: OKTETO _K8S) |
---|---|---|---|---|
0 | Challenge 0 | Intro |
|
Docker |
1 | Challenge 1 | Git |
|
Docker |
2 | Challenge 2 | Git |
|
Docker |
3 | Challenge 3 | Docker |
|
Docker |
4 | Challenge 4 | Docker |
|
Docker |
5 | Challenge 5 | Configmaps |
|
K8S |
6 | Challenge 6 | Secrets |
|
K8S |
7 | Challenge 7 | Vault |
|
K8S with Vault |
8 | Challenge 8 | Logging |
|
Docker |
9 | Challenge 9 | Terraform |
|
AWS, GCP, Azure |
10 | Challenge 10 | CSI-Driver |
|
AWS, GCP, Azure |
11 | Challenge 11 | IAM privilege escalation |
|
AWS, GCP, Azure |
12 | Challenge 12 | Docker |
|
Docker |
13 | Challenge 13 | CI/CD |
|
Docker |
14 | Challenge 14 | Password Manager |
|
Docker |
15 | Challenge 15 | Git |
|
Docker |
16 | Challenge 16 | Front-end |
|
Docker |
17 | Challenge 17 | Docker |
|
Docker |
18 | Challenge 18 | Cryptography |
|
Docker |
19 | Challenge 19 | Binary |
|
Docker |
20 | Challenge 20 | Binary |
|
Docker |
21 | Challenge 21 | Binary |
|
Docker |
22 | Challenge 22 | Binary |
|
Docker |
23 | Challenge 23 | Front-end |
|
Docker |
24 | Challenge 24 | Cryptography |
|
Docker |
25 | Challenge 25 | Web3 |
|
Docker |
26 | Challenge 26 | Web3 |
|
Docker |
27 | Challenge 27 | Web3 |
|
Docker |
28 | Challenge 28 | Documentation |
|
Docker |
Hasty? Here is the Vault secret;-)