<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ivan+Buetler</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ivan+Buetler"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Ivan_Buetler"/>
		<updated>2026-04-26T00:15:45Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=234460</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=234460"/>
				<updated>2017-10-17T12:12:23Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: update broken links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=245 OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=302 OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=557 OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/eventregister.html?event=245  OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/eventregister.html?event=302  OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/eventregister.html?event=557  OWASP Hackademic]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.ohloh.net/p/Hacking_Lab Ohloh: Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/ European Challenge]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=234459</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=234459"/>
				<updated>2017-10-17T12:10:54Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: update broken links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=245 OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=302 OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=557 OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.ohloh.net/p/Hacking_Lab Ohloh: Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/ European Challenge]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ivan_Buetler&amp;diff=234458</id>
		<title>User:Ivan Buetler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ivan_Buetler&amp;diff=234458"/>
				<updated>2017-10-17T12:03:05Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: bio update&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Ivan Buetler is a renowned security expert in the field of cyber security. He started his career by co-founding and developing Compass Security AG, a leading ethical hacking and penetration testing company headquartered in Switzerland near Zurich with its subsidiaries in Berne and Berlin. Several of his publications on network and computer security have raised international recognition. Besides his own business, he is a tutor at several Swiss Universities, where he lectures in the field of '''Hacking''', '''Cyber Crime''' and '''Advanced Persistent Threats'''. Ivan is a regular speaker at international security conferences. He is in the board of the Swiss Cyber Storm association and responsible for the European Cyber Security Challenge. He is the founder of Hacking-Lab, a world-wide recognized ethical hacking testing lab. Additionally, he is leading and volunteering the [[OWASP Hacking Lab|OWASP/Hacking-Lab]] project and an acknowledged security expert at the Swiss Academy of Engineering Sciences (SATW).&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ivan_Buetler&amp;diff=234457</id>
		<title>User:Ivan Buetler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ivan_Buetler&amp;diff=234457"/>
				<updated>2017-10-17T12:02:38Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: bio update&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218694</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218694"/>
				<updated>2016-07-07T14:27:51Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP UC? ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
== Information ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
* Travel and lodging has to be organized and covered by the student teams themselves, the conference should feed the students&lt;br /&gt;
&lt;br /&gt;
* Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
* It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Learn more about:&lt;br /&gt;
* [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2017 @ AppSec EU in Belfast (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218693</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218693"/>
				<updated>2016-07-07T14:25:17Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Ohloh */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.ohloh.net/p/Hacking_Lab Ohloh: Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/ European Challenge]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218692</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218692"/>
				<updated>2016-07-07T14:25:05Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Ohloh */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.ohloh.net/p/Hacking_Lab Ohloh:Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/ European Challenge]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218691</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218691"/>
				<updated>2016-07-07T14:24:47Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Ohloh */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.ohloh.net/p/Hacking_Lab Hacking-Lab Ohloh]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/ European Challenge]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218690</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218690"/>
				<updated>2016-07-07T14:24:23Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Ohloh */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.ohloh.net/p/Hacking_Lab Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/ European Challenge]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218689</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218689"/>
				<updated>2016-07-07T14:23:28Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/ European Challenge]&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218686</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218686"/>
				<updated>2016-07-07T14:00:31Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* What is the OWASP University Challenge? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP UC? ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
== Information ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
* Travel and lodging has to be organized and covered by the student teams themselves, the conference should feed the students&lt;br /&gt;
&lt;br /&gt;
* Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
* It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Learn more about:&lt;br /&gt;
* [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2017 @ AppSec EU in Belfast (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218685</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218685"/>
				<updated>2016-07-07T14:00:02Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* What is the OWASP University Challenge? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
== Information ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
* Travel and lodging has to be organized and covered by the student teams themselves, the conference should feed the students&lt;br /&gt;
&lt;br /&gt;
* Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
* It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Learn more about:&lt;br /&gt;
* [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2017 @ AppSec EU in Belfast (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218684</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218684"/>
				<updated>2016-07-07T13:59:32Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* What is the OWASP University Challenge? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
&lt;br /&gt;
== Information ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
* Travel and lodging has to be organized and covered by the student teams themselves, the conference should feed the students&lt;br /&gt;
&lt;br /&gt;
* Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
* It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Learn more about:&lt;br /&gt;
* [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2017 @ AppSec EU in Belfast (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218683</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218683"/>
				<updated>2016-07-07T13:57:17Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Acknowledgements */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
* Travel and lodging has to be organized and covered by the student teams themselves, the conference should feed the students&lt;br /&gt;
&lt;br /&gt;
* Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
* It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Learn more about:&lt;br /&gt;
* [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2017 @ AppSec EU in Belfast (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218682</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218682"/>
				<updated>2016-07-07T13:56:23Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Hacking-Lab */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
* Travel and lodging has to be organized and covered by the student teams themselves, the conference should feed the students&lt;br /&gt;
&lt;br /&gt;
* Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
* It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about:&lt;br /&gt;
* [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Hacking_Lab OWASP Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2017 @ AppSec EU in Belfast (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218681</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218681"/>
				<updated>2016-07-07T13:51:17Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* What is Hacking Lab */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218680</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218680"/>
				<updated>2016-07-07T13:50:00Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* European Cyber Security Challenge 2016 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218679</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218679"/>
				<updated>2016-07-07T13:49:29Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Introduction */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Ecsc-logo.png&amp;diff=218678</id>
		<title>File:Ecsc-logo.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Ecsc-logo.png&amp;diff=218678"/>
				<updated>2016-07-07T13:48:31Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218677</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218677"/>
				<updated>2016-07-07T13:46:22Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* European Challenge */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== European Cyber Security Challenge 2016 ==&lt;br /&gt;
&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.&lt;br /&gt;
 &lt;br /&gt;
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.&lt;br /&gt;
&lt;br /&gt;
=== How to join the ECSC 2016 ===&lt;br /&gt;
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218676</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218676"/>
				<updated>2016-07-07T13:40:08Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* University Challenge */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=European Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218675</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218675"/>
				<updated>2016-07-07T13:37:19Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Quick Download */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Challenge_development_by_OWASP.zip&amp;diff=218674</id>
		<title>File:Challenge development by OWASP.zip</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Challenge_development_by_OWASP.zip&amp;diff=218674"/>
				<updated>2016-07-07T13:35:35Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Zip-icon.png&amp;diff=218673</id>
		<title>File:Zip-icon.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Zip-icon.png&amp;diff=218673"/>
				<updated>2016-07-07T13:32:25Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218670</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218670"/>
				<updated>2016-07-07T13:26:17Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218669</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218669"/>
				<updated>2016-07-07T13:23:39Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218668</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218668"/>
				<updated>2016-07-07T13:23:18Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:ppt-icon.png|Download Power Point|link=HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218667</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218667"/>
				<updated>2016-07-07T13:12:51Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218666</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218666"/>
				<updated>2016-07-07T13:12:29Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:word-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218665</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218665"/>
				<updated>2016-07-07T13:09:17Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218664</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218664"/>
				<updated>2016-07-07T13:08:45Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:pdf-icon.png|Download PDF]] [[File:HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[File:word-icon.png|Download Power Point]] [[File:HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218663</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218663"/>
				<updated>2016-07-07T13:07:25Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218662</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218662"/>
				<updated>2016-07-07T13:07:05Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Presentation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
*[[File:pdf-icon.png|left|Download PDF]] [[File:HL CTF 2016.pdf]]&lt;br /&gt;
&lt;br /&gt;
*[[File:word-icon.png|left|Download Power Point]] [[File:HL CTF 2016.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Ppt-icon.png&amp;diff=218661</id>
		<title>File:Ppt-icon.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Ppt-icon.png&amp;diff=218661"/>
				<updated>2016-07-07T13:05:51Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Pdf-icon.png&amp;diff=218660</id>
		<title>File:Pdf-icon.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Pdf-icon.png&amp;diff=218660"/>
				<updated>2016-07-07T12:59:36Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Word-icon.png&amp;diff=218659</id>
		<title>File:Word-icon.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Word-icon.png&amp;diff=218659"/>
				<updated>2016-07-07T12:59:23Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:HL_CTF_2016.pptx&amp;diff=218658</id>
		<title>File:HL CTF 2016.pptx</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:HL_CTF_2016.pptx&amp;diff=218658"/>
				<updated>2016-07-07T12:56:13Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:HL_CTF_2016.pdf&amp;diff=218657</id>
		<title>File:HL CTF 2016.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:HL_CTF_2016.pdf&amp;diff=218657"/>
				<updated>2016-07-07T12:54:40Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218655</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218655"/>
				<updated>2016-07-07T12:47:26Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Road Map and Getting Involved */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
* Travel and lodging has to be organized and covered by the student teams themselves, the conference should feed the students&lt;br /&gt;
&lt;br /&gt;
* Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
* It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2017 @ AppSec EU in Belfast (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218654</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218654"/>
				<updated>2016-07-07T11:58:04Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218653</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218653"/>
				<updated>2016-07-07T11:56:35Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Introduction */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Attack-Defense System===&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]] &lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218652</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218652"/>
				<updated>2016-07-07T11:55:20Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Introduction */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]&lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. &lt;br /&gt;
&lt;br /&gt;
If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218651</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218651"/>
				<updated>2016-07-07T11:52:45Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Questions */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218650</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218650"/>
				<updated>2016-07-07T11:51:43Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Rating: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
***'''3 Points for vulnerability description'''&lt;br /&gt;
***'''3 Points for proven exploit'''&lt;br /&gt;
***'''4 Points for complete mitigation description'''&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review UC faq: https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218649</id>
		<title>OWASP Hacking Lab</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Hacking_Lab&amp;diff=218649"/>
				<updated>2016-07-07T11:49:13Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* About Hacking-Lab */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Hacking Lab==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.&lt;br /&gt;
&lt;br /&gt;
==Available challenges==&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP TopTen Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP Hackademic Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
* Free registration for [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP WebGoat Hands-On Training]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Hacking Lab ==&lt;br /&gt;
&lt;br /&gt;
OWASP Hacking Lab provides:&lt;br /&gt;
&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=245&amp;amp;uk= OWASP Top 10]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=302&amp;amp;uk= OWASP WebGoat]&lt;br /&gt;
* [https://www.hacking-lab.com/events/registerform.html?eventid=557&amp;amp;uk= OWASP Hackademic]&lt;br /&gt;
* University Challenges&lt;br /&gt;
* Fun Challenges&lt;br /&gt;
* [http://www.hacking-lab-ctf.com/ CTF System]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
[mailto:ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.Martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/Hacking_Lab&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* Link to page/download&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==Solution Grading &amp;amp; Evaluation Guidelines for Teachers==&lt;br /&gt;
*Always be polite&lt;br /&gt;
**Never ever be unpolite. No matter what comment or question you receive!&lt;br /&gt;
**You are OWASP's interface, behave mature and polite.&lt;br /&gt;
*Comment in positive phrasing&lt;br /&gt;
**E.g. if partially scored has been achieved, congratulate them&lt;br /&gt;
**If the solution contains a good write-up, let them know you appreciate!&lt;br /&gt;
**If they thank you for the event, return the favor e.g. thanks for contributing&lt;br /&gt;
*Teaching and mentoring&lt;br /&gt;
**If a previous suggestion is not understand, try to rephrase&lt;br /&gt;
*No abusive language is permitted&lt;br /&gt;
**If you receive any in a solution, don't 'hit back'&lt;br /&gt;
**See what is causing the frustration, see if you can help is, let Ivan or Martin know&lt;br /&gt;
&lt;br /&gt;
==Rating:==&lt;br /&gt;
*Understanding the vulnerability is essential&lt;br /&gt;
**If a solution describes the vulnerability, this does scores points.&lt;br /&gt;
&lt;br /&gt;
*Mitigation scores higher than hacking:&lt;br /&gt;
**We are training security awareness! If mitigation is asked as part of the solution, this scores higher then exploitation&lt;br /&gt;
*Exploiting is essential&lt;br /&gt;
**The exploit has to be proven, but a solution that describes the exploit detailed, this is fine too!&lt;br /&gt;
*Give points when possible&lt;br /&gt;
**If not the complete answer has been supplied, give partial points when possible.&lt;br /&gt;
**Only reject if:&lt;br /&gt;
***there is no solution (e.g. a question asked by the student)&lt;br /&gt;
***the solution is answering the wrong challenge&lt;br /&gt;
***the vulnerability / exploit / mitigation has clearly not been understood&lt;br /&gt;
&lt;br /&gt;
*Rating example:&lt;br /&gt;
**If you have 10 points to give this is how to divide them:&lt;br /&gt;
**;3 Points for vulnerability description&lt;br /&gt;
**;3 Points for proven exploit&lt;br /&gt;
**;4 Points for complete mitigation description&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Hacking-Lab is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* Ivan Buetler&lt;br /&gt;
* Martin Knobloch&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
&lt;br /&gt;
==Volunteer Roles==&lt;br /&gt;
* Challenge developer&lt;br /&gt;
* Challenge tester&lt;br /&gt;
* LiveCD developer&lt;br /&gt;
* Teachers (solution grading)&lt;br /&gt;
* University Challenge Organizer&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of Hack Lab is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
==Become an OWASP challenge participant/student==&lt;br /&gt;
*Register to a free OWASP Hands-On Training (see tab &amp;quot;Available Challenges&amp;quot;)&lt;br /&gt;
*Sign-Up a Hacking-Lab account&lt;br /&gt;
*Prepare your client infrastructure (recommended LiveCD from http://media.hacking-lab.com/)&lt;br /&gt;
*Setup VPN from within your LiveCD&lt;br /&gt;
*Read the challenge description (once registered in the first step)&lt;br /&gt;
*Submit your solution into the HL portal&lt;br /&gt;
*OWASP volunteers will grade your submission&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP teacher==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Make yourself familiar with the OWASP TOP 10, Hackademics and WebGoat challenges&lt;br /&gt;
*Ask for becoming a teacher to the project leaders&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge developer==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your challenge ideas (using the challenge concept template)&lt;br /&gt;
*Create your challenge&lt;br /&gt;
&lt;br /&gt;
==Become an OWASP challenge tester==&lt;br /&gt;
*Solve the challenges as participant/student first&lt;br /&gt;
*Submit your feedback and ideas how to improve the challenges&lt;br /&gt;
&lt;br /&gt;
=University Challenge=&lt;br /&gt;
== Introduction ==&lt;br /&gt;
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. &lt;br /&gt;
&lt;br /&gt;
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]&lt;br /&gt;
&lt;br /&gt;
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
===Previous events:===&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Please review UC faq: https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Hacking_Lab}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218647</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218647"/>
				<updated>2016-07-07T11:47:47Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Expenses: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
* Travel and lodging has to be organized and covered by the student teams themselves, the conference should feed the students&lt;br /&gt;
&lt;br /&gt;
* Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
* It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2015 @ AppSec EU in Amsterdam (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218646</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218646"/>
				<updated>2016-07-07T11:46:12Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Outline: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (challenge server) come from [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
Travel and lodging has to be organized and covered by the student teams themselves&lt;br /&gt;
The Conference should feed the students&lt;br /&gt;
&lt;br /&gt;
Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2015 @ AppSec EU in Amsterdam (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218645</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218645"/>
				<updated>2016-07-07T11:43:50Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* About Hacking-Lab */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with Hacking-Lab&lt;br /&gt;
* Hardware (challenge server) come from Hacking-Lab&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
Travel and lodging has to be organized and covered by the student teams themselves&lt;br /&gt;
The Conference should feed the students&lt;br /&gt;
&lt;br /&gt;
Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about [https://www.hacking-lab.com Hacking-Lab]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2015 @ AppSec EU in Amsterdam (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218644</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218644"/>
				<updated>2016-07-07T11:38:16Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* What is the OWASP University Challenge? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with Hacking-Lab&lt;br /&gt;
* Hardware (challenge server) come from Hacking-Lab&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
Travel and lodging has to be organized and covered by the student teams themselves&lt;br /&gt;
The Conference should feed the students&lt;br /&gt;
&lt;br /&gt;
Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about Hacking-Lab: https://www.hacking-lab.com&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2015 @ AppSec EU in Amsterdam (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218643</id>
		<title>OWASP University Challenge</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_University_Challenge&amp;diff=218643"/>
				<updated>2016-07-07T11:35:54Z</updated>
		
		<summary type="html">&lt;p&gt;Ivan Buetler: /* Attack-Defense System */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP University Challenge ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The University Challenge is a competition among teams comprised of university students that will be held during the training days of the larger OWASP AppSec conferences (AppSec US, AppSec EU, …). &lt;br /&gt;
&lt;br /&gt;
* There is no admission fee for the University Challenge – participation in the conference is possible for free. &lt;br /&gt;
&lt;br /&gt;
* During the University Challenge teams will solve mission style security challenges using the Hacking-Lab framework. &lt;br /&gt;
&lt;br /&gt;
* The OWASP University Challenge could be limited to 8 teams, depending on available space and budget. Teams will consist of 4-8 students, with one team per university. &lt;br /&gt;
&lt;br /&gt;
* All team openings are on a first come first serve basis. If multiple teams are received from the same university the second team will be put on a wait list. &lt;br /&gt;
&lt;br /&gt;
* All team members must be registered. Registration for the University Challenge event is free. &lt;br /&gt;
&lt;br /&gt;
* Food and beverages will be provided during the challenge and all participants will get an OWASP University Challenge t-shirt. Of course, the first three winning teams will get some small prizes (to be announced).&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
The OWASP University Challenge is a one or two day mission style security challenge event during the AppSec conferences training days!&lt;br /&gt;
University / Student teams can compete solving hack challenges and defending insecure applications.&lt;br /&gt;
&lt;br /&gt;
==Attack-Defense System==&lt;br /&gt;
[[File:Attack-Defense.png|left|Hacking-Lab]]The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP University Challenge? ==&lt;br /&gt;
&lt;br /&gt;
OWASP University Challenge  provides:&lt;br /&gt;
&lt;br /&gt;
The AppSec conference should take care of:&lt;br /&gt;
*Venue / rooms during the conference training days&lt;br /&gt;
*Feed the students&lt;br /&gt;
*Local pr / announcements at local Universities&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Link to presentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:Ivan.buetler@owasp.org Ivan Buetler]&lt;br /&gt;
&lt;br /&gt;
[mailto:Mateo.martinez@owasp.org Mateo Martinez]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Student Chapters Program]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=Set Up=&lt;br /&gt;
==Conference Organisation:==&lt;br /&gt;
* Announcement&lt;br /&gt;
* Room / Space for the University Challenge&lt;br /&gt;
** Internet connection&lt;br /&gt;
** Video projector (scoring/ranking)&lt;br /&gt;
** Power and extensions&lt;br /&gt;
* Outreach to the local Universities&lt;br /&gt;
* Sponsor for winner prizes&lt;br /&gt;
* Winner announcement during the main track / (before) end of the conference&lt;br /&gt;
&lt;br /&gt;
==Outline:==&lt;br /&gt;
During the two training days&lt;br /&gt;
* challenges will be organized together with Hacking-Lab&lt;br /&gt;
* Hardware (challenge server) come from Hacking-Lab&lt;br /&gt;
* Hardware (wilreless routers) come form the Education Committee&lt;br /&gt;
&lt;br /&gt;
==Expenses:==&lt;br /&gt;
Travel and lodging has to be organized and covered by the student teams themselves&lt;br /&gt;
The Conference should feed the students&lt;br /&gt;
&lt;br /&gt;
Travel and lodging of the University Challenge project leader (running the challenge) is covered by the conference&lt;br /&gt;
&lt;br /&gt;
It is recommended to give the University Challenge teams free entrance to the conference&lt;br /&gt;
&lt;br /&gt;
==Prices:==&lt;br /&gt;
We could need the conference organization team to help finding sponsors for the prices.&lt;br /&gt;
&lt;br /&gt;
=University Challenge Events=&lt;br /&gt;
==Previous events:==&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]&lt;br /&gt;
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]&lt;br /&gt;
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]&lt;br /&gt;
*AppSec-US 2012 Austin&lt;br /&gt;
*AppSec-US 2011 Minneapolis&lt;br /&gt;
&lt;br /&gt;
==Ticket winning&amp;quot; pre-conference challenges:==&lt;br /&gt;
-&amp;gt; option for conference to offer free tickets via solving Hacking-Lab challenges &lt;br /&gt;
-&amp;gt; qualifying for UC? -&amp;gt; Team qualifying&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
    Q1: When typically has the event run at AppSec, during the training days or during conference proper?&lt;br /&gt;
    A1: The UC is normally hosted during the training days&lt;br /&gt;
&lt;br /&gt;
    Q2: What size of room or seating capacity has typically been used?&lt;br /&gt;
    A2: Depending to the PR and number of teams (teams have a max of 8 members)&lt;br /&gt;
&lt;br /&gt;
    Q3: What prizes are usually awarded?&lt;br /&gt;
    A3: depends, if the conference manages to find sponsors there are prices. At the AppSec-Eu 2013, there where no prices, only the honor of winning&lt;br /&gt;
&lt;br /&gt;
    Q4: Do the teams  have free conference access?&lt;br /&gt;
    A4: No, the teams have to organize travel and lodging themself. all we do is hosting the UC and feed them.&lt;br /&gt;
    There are no entrance / attendance fees charged previously&lt;br /&gt;
    The attendees usually get free access to the conference (because they travel from foreign countries too) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Hacking-Lab==&lt;br /&gt;
The University Challenge is run by the OWASP/Hacking-Lab project. Real knowledge derives from hands-on experience.&lt;br /&gt;
&lt;br /&gt;
===About Hacking-Lab===&lt;br /&gt;
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. &lt;br /&gt;
Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.&lt;br /&gt;
&lt;br /&gt;
Learn more about Hacking-Lab: https://www.hacking-lab.com&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
* University Challenge 2015 @ AppSec EU in Amsterdam (Martin Knobloch)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_University_Challenge}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Ivan Buetler</name></author>	</entry>

	</feed>