OWASP/wrongsecrets

Have a challenge with a backup bucket containing the secret

Ouverte

#982 ouverte le 9 sept. 2023

 (15 commentaires) (0 réaction) (1 personne assignée)Java (601 forks)github user discovery
New Challengehelp wanted

Métriques du dépôt

Stars
 (1 457 étoiles)
Métriques de merge PR
 (Merge moyen 4j 1h) (29 PRs mergées en 30 j)

Description

Context

  • What should the challenge scenario be like? Have a backup s3/storage bucket with a private ed25519 key publicly exposed
  • What should the participant learn from completing the challenge? Secure your backup at all cost
  • For what category would the challenge be? (e.g. Docker, K8s, binary) Docker/cloud depending on how we implement the backup solution

Actions:

  • create separate Terraform folder to have an S3 bucket (in our AWS folder) under the name "backupchallenge"
  • have the key copying logic in a shell script using AWS CLI as part of the backupchallenge folder
  • implement the challenge according to contributing.md and make sure you hide the key in your classfile.

Guide contributeur