OWASP/wrongsecrets

Have a challenge with a backup bucket containing the secret

Open

#982 opened on Sep 9, 2023

 (15 comments) (0 reactions) (1 assignee)Java (601 forks)github user discovery
New Challengehelp wanted

Repository metrics

Stars
 (1,457 stars)
PR merge metrics
 (Avg merge 4d 1h) (29 merged PRs in 30d)

Description

Context

  • What should the challenge scenario be like? Have a backup s3/storage bucket with a private ed25519 key publicly exposed
  • What should the participant learn from completing the challenge? Secure your backup at all cost
  • For what category would the challenge be? (e.g. Docker, K8s, binary) Docker/cloud depending on how we implement the backup solution

Actions:

  • create separate Terraform folder to have an S3 bucket (in our AWS folder) under the name "backupchallenge"
  • have the key copying logic in a shell script using AWS CLI as part of the backupchallenge folder
  • implement the challenge according to contributing.md and make sure you hide the key in your classfile.

Contributor guide