OWASP/wrongsecrets

Have a challenge with a backup bucket containing the secret

Aperta

#982 aperta il 9 set 2023

 (15 commenti) (0 reazioni) (1 assegnatario)Java (601 fork)github user discovery
New Challengehelp wanted

Metriche repository

Star
 (1457 stelle)
Metriche merge PR
 (Merge medio 4g 1h) (29 PR mergiate in 30 g)

Descrizione

Context

  • What should the challenge scenario be like? Have a backup s3/storage bucket with a private ed25519 key publicly exposed
  • What should the participant learn from completing the challenge? Secure your backup at all cost
  • For what category would the challenge be? (e.g. Docker, K8s, binary) Docker/cloud depending on how we implement the backup solution

Actions:

  • create separate Terraform folder to have an S3 bucket (in our AWS folder) under the name "backupchallenge"
  • have the key copying logic in a shell script using AWS CLI as part of the backupchallenge folder
  • implement the challenge according to contributing.md and make sure you hide the key in your classfile.

Guida contributor