OWASP/wrongsecrets
Have a challenge with a backup bucket containing the secret
Open
#982 opened on Sep 9, 2023
New Challengehelp wanted
Repository metrics
- Stars
- (1,457 stars)
- PR merge metrics
- (Avg merge 4d 1h) (29 merged PRs in 30d)
Description
Context
- What should the challenge scenario be like? Have a backup s3/storage bucket with a private ed25519 key publicly exposed
- What should the participant learn from completing the challenge? Secure your backup at all cost
- For what category would the challenge be? (e.g. Docker, K8s, binary) Docker/cloud depending on how we implement the backup solution
Actions:
- create separate Terraform folder to have an S3 bucket (in our AWS folder) under the name "backupchallenge"
- have the key copying logic in a shell script using AWS CLI as part of the backupchallenge folder
- implement the challenge according to contributing.md and make sure you hide the key in your classfile.