This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Hacking Lab"

From OWASP
Jump to: navigation, search
(update broken links)
 
(37 intermediate revisions by the same user not shown)
Line 4: Line 4:
  
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
| valign="top"  style="border-right: 1px dotted gray;padding-right:25px;" |
+
| style="border-right: 1px dotted gray;padding-right:25px;" valign="top" |
  
 
==OWASP Hacking Lab==
 
==OWASP Hacking Lab==
  
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.  
+
OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.
  
==Introduction==
+
===About Hacking-Lab===
 +
[[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.
  
Currently, there is one challenge, the OWASP TopTen with currently 1164 registered users and +500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.
+
Learn more about [https://www.hacking-lab.com Hacking-Lab]
  
 +
==Introduction==
  
 +
Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.
  
==Description==
+
==Available challenges==
'''Available challenges'''
 
  
'''''OWASP TopTen Hands-On Training'''''
+
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=245 OWASP TopTen Hands-On Training]
  
;Free registration: https://www.hacking-lab.com/events/registerform.html?eventid=245&uk=
+
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=302 OWASP Hackademic Hands-On Training]
  
'''''OWASP Hackademic Hands-On Training'''''
+
* Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=557 OWASP WebGoat Hands-On Training]
;Free registration: https://www.hacking-lab.com/events/registerform.html?eventid=302&uk=
 
 
 
'''''OWASP WebGoat Hands-On Training'''''
 
;Free registration: https://www.hacking-lab.com/events/registerform.html?eventid=557&uk=
 
  
 
==Licensing==
 
==Licensing==
 
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
 
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
  
 
+
| style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" valign="top" |
| valign="top"  style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
 
  
 
== What is Hacking Lab ==
 
== What is Hacking Lab ==
Line 39: Line 36:
 
OWASP Hacking Lab provides:
 
OWASP Hacking Lab provides:
  
* OWASP Top 10 [https://www.hacking-lab.com/events/registerform.html?eventid=245&uk=]
+
* [https://www.hacking-lab.com/events/eventregister.html?event=245 OWASP Top 10]
* OWASP WebGoat [https://www.hacking-lab.com/events/registerform.html?eventid=302&uk=]
+
* [https://www.hacking-lab.com/events/eventregister.html?event=302 OWASP WebGoat]
* OWASP Hackademic [https://www.hacking-lab.com/events/registerform.html?eventid=557&uk=]
+
* [https://www.hacking-lab.com/events/eventregister.html?event=557 OWASP Hackademic]
* University Challenges
+
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]
* Fun Challenges
+
* [http://www.hacking-lab-ctf.com/ CTF System]
 
 
  
 
== Presentation ==
 
== Presentation ==
  
Link to presentation
+
[[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]]
 
 
 
 
  
 +
[[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]]
  
 
== Project Leaders ==
 
== Project Leaders ==
Line 66: Line 61:
 
== Ohloh ==
 
== Ohloh ==
  
*https://www.ohloh.net/p/Hacking_Lab
+
* [https://www.ohloh.net/p/Hacking_Lab Ohloh: Hacking-Lab]
  
| valign="top"  style="padding-left:25px;width:200px;" |  
+
| style="padding-left:25px;width:200px;" valign="top" |
  
 
== Quick Download ==
 
== Quick Download ==
  
* Link to page/download
+
[[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]]
 
 
 
 
  
 
== News and Events ==
 
== News and Events ==
* [20 Nov 2013] News 2
 
* [30 Sep 2013] News 1
 
  
 +
* [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge]
 +
* [http://www.europeancybersecuritychallenge.eu/ European Challenge]
  
 
== In Print ==
 
== In Print ==
Line 89: Line 82:
 
   {| width="200" cellpadding="2"
 
   {| width="200" cellpadding="2"
 
   |-
 
   |-
   | align="center" valign="top" width="50%" rowspan="2"| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]
+
   | rowspan="2" width="50%" valign="top" align="center" | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]
   | align="center" valign="top" width="50%"| [[File:Owasp-builders-small.png|link=]]   
+
   | width="50%" valign="top" align="center" | [[File:Owasp-builders-small.png|link=]]   
 
   |-
 
   |-
   | align="center" valign="top" width="50%"| [[File:Owasp-defenders-small.png|link=]]
+
   | width="50%" valign="top" align="center" | [[File:Owasp-defenders-small.png|link=]]
 
   |-
 
   |-
   | colspan="2" align="center" | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]
+
   | colspan="2" align="center" | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]
 
   |-
 
   |-
   | colspan="2" align="center" | [[File:Project_Type_Files_DOC.jpg|link=]]
+
   | colspan="2" align="center" | [[File:Project_Type_Files_DOC.jpg|link=]]
 
   |}
 
   |}
  
Line 134: Line 127:
 
*Rating example:
 
*Rating example:
 
**If you have 10 points to give this is how to divide them:
 
**If you have 10 points to give this is how to divide them:
**;3 Points for vulnerability description
+
***'''3 Points for vulnerability description'''
**;3 Points for proven exploit
+
***'''3 Points for proven exploit'''
**;4 Points for complete mitigation description
+
***'''4 Points for complete mitigation description'''
  
 
= Acknowledgements =
 
= Acknowledgements =
Line 185: Line 178:
 
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges.  
 
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges.  
  
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: https://www.owasp.org/index.php/OWASP_University_Challenge
+
This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge]
* OWASP AppSec US 2011 (http://2011.appsecusa.org/edu_ctf.html)
+
 
* OWASP AppSec EU Greece, Athens
+
 
* OWASP AppSec EU Germany, Hamburg (https://www.owasp.org/index.php/AppSecEU2013/Uni-Challenge)
+
===Attack-Defense System===
 +
[[File:Attack-Defense.png|left|Hacking-Lab]]
 +
The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System]
 +
 
 +
 
 +
===Previous events:===
 +
*[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome]
 +
*[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam]
 +
*[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge]
 +
*[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg]
 +
*[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens]
 +
*AppSec-US 2012 Austin
 +
*AppSec-US 2011 Minneapolis
 +
 
 +
===Questions===
 +
Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ]
 +
 
 +
 
 +
 
 +
=European Challenge=
 +
== European Cyber Security Challenge 2016 ==
 +
 
 +
=== Introduction ===
 +
[[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security.
 +
 +
The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them.
 +
 
 +
 
  
Please review UC faq: https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs
+
=== How to join the ECSC 2016 ===
 +
* [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016]
  
 
=Project About=
 
=Project About=
 
{{:Projects/OWASP_Hacking_Lab}}   
 
{{:Projects/OWASP_Hacking_Lab}}   
  
__NOTOC__ <headertabs />  
+
__NOTOC__ <headertabs></headertabs>  
  
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]
+
[[Category:OWASP Project]]   
 +
[[Category:OWASP_Builders]]  
 +
[[Category:OWASP_Defenders]]   
 +
[[Category:OWASP_Document]]

Latest revision as of 12:12, 17 October 2017

OWASP Project Header.jpg

OWASP Hacking Lab

OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings.

About Hacking-Lab

Hacking-Lab
Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense.

Learn more about Hacking-Lab

Introduction

Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges.

Available challenges

Licensing

OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

What is Hacking Lab

OWASP Hacking Lab provides:

Presentation

Download PDF HL CTF 2016.pdf

Download Power Point HL CTF 2016.pptx

Project Leaders

Ivan Buetler

Mateo Martinez

Related Projects


Ohloh

Quick Download

Download ZIP Challenge Concept Template

News and Events

In Print

This project can be purchased as a print on demand book from Lulu.com


Classifications

Owasp-incubator-trans-85.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg