πŸ€– Challenge 57 - LLM Security Demo (PR #2400)
This is a live preview of Challenge 57 featuring an interactive AI assistant with embedded secrets. Try asking it questions to find the hidden secret!
>
Welcome to OWASP WrongSecrets

Learn about secrets management by finding real secrets hidden in code, configuration files, and cloud infrastructure.


Pro Tip: Each challenge below has a different difficulty level and may require different environments. Start with the easier ones and work your way up! πŸš€

Difficulty: ⭐ (Easy) ⭐⭐ (Medium) ⭐⭐⭐ (Hard) ⭐⭐⭐⭐ (Expert) ⭐⭐⭐⭐⭐ (Master) | Environment: Where the challenge can be solved
#  Challenge      Focus    Difficulty        Solved
0   Find the hard-coded password DEVOPS ⭐ Docker
1   Find the unencrypted password in Git GIT ⭐⭐ Docker
2   Find the hard-coded password in front-end FRONTEND ⭐⭐⭐ Docker
3   Take a look at this file DEVOPS ⭐⭐⭐⭐ Docker
4   Find the AWS S3 bucket password AWS ⭐⭐⭐⭐⭐ AWS
5   Find the Azure Key Vault secret AZURE ⭐ Azure
6   Connect the dots with Docker DOCKER ⭐⭐ Docker
7   Find the secret in the container DOCKER ⭐⭐⭐ Docker
8   Retrieve cloud instance metadata AWS ⭐⭐⭐⭐ AWS
9   Use AWS Parameter Store AWS ⭐⭐⭐⭐⭐ AWS

Total score: 42

Hasty? Here is the Vault secret;-)

Like what you see? Please
Star us on Github
Note: The above button only takes you to the repository. Please ensure to star the repository once you are there!
OWASP WrongSecrets - Challenge 57 Preview OWASP Project Leaders: Top Contributors: Contributors: Testers: Special mentions for helping out:
Wondering what a secret is? A secret is often a confidential piece of information that is required to unlock certain functionalities or information. It can exists in many shapes or forms, for instance:
  • 2FA keys
  • Activation/Callback links
  • API keys
  • Credentials
  • Passwords
  • Private keys (decryption, signing, TLS, SSH, GPG)
  • Secret keys (symmetric encryption, HMAC)
  • Session cookies
  • Tokens (Session, Refresh, Authentication, Activation, etc.)
Want to see if your tool of choice detects all the secrets available in this project?
Check the instructions in the README .
Developing our solution in 3 clouds costs money. Want to help us to cover our cloud bills? Donate.