This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Hacking Lab"
From OWASP
Ivan Buetler (talk | contribs) (update broken links) |
|||
(37 intermediate revisions by the same user not shown) | |||
Line 4: | Line 4: | ||
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- | {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- | ||
− | | | + | | style="border-right: 1px dotted gray;padding-right:25px;" valign="top" | |
==OWASP Hacking Lab== | ==OWASP Hacking Lab== | ||
− | OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings. | + | OWASP Hacking Lab is providing free remote security (web) challenges and riddles (OWASP TOP 10, OWASP WebGoat, OWASP Hackademics). It differs from other damn vulnerable applications and sites with it's unique teacher application. Every challenge is asking for the vulnerability, exploit and mitigation. Send in your solution and other OWASP volunteers will grade your submission. A system where you can interact with human beings. |
− | == | + | ===About Hacking-Lab=== |
+ | [[File:Hacking-Lab.png|left|Hacking-Lab]]Hacking-Lab is an online ethical hacking, computer network and security challenge platform, dedicated to finding and educating cyber security talents. Furthermore, Hacking-Lab is providing the CTF and mission style challenges for the OWASP University Challenges and for the European Cyber Security Challenge. The Hacking-Lab also provides free OWASP TOP 10 online security labs. Hacking-Labs’ goal is to raise awareness towards increased education and ethics in information security through a series of cyber competitions that encompass forensics, cryptography, reverse-engineering, ethical hacking and defense. | ||
− | + | Learn more about [https://www.hacking-lab.com Hacking-Lab] | |
+ | ==Introduction== | ||
+ | Currently, there is one challenge, the OWASP TopTen with currently 8700 registered users and +3500 solutions send in and verified by the OWASP teachers! The goal is to provide an open and transparent process about the challenges, the teachers and continuously working on extending the available challenges. | ||
− | == | + | ==Available challenges== |
− | |||
− | + | * Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=245 OWASP TopTen Hands-On Training] | |
− | + | * Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=302 OWASP Hackademic Hands-On Training] | |
− | + | * Free registration for [https://www.hacking-lab.com/events/eventregister.html?event=557 OWASP WebGoat Hands-On Training] | |
− | |||
− | |||
− | |||
− | |||
==Licensing== | ==Licensing== | ||
OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. | OWASP Hacking Lab is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. | ||
− | + | | style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" valign="top" | | |
− | | | ||
== What is Hacking Lab == | == What is Hacking Lab == | ||
Line 39: | Line 36: | ||
OWASP Hacking Lab provides: | OWASP Hacking Lab provides: | ||
− | * | + | * [https://www.hacking-lab.com/events/eventregister.html?event=245 OWASP Top 10] |
− | * | + | * [https://www.hacking-lab.com/events/eventregister.html?event=302 OWASP WebGoat] |
− | * | + | * [https://www.hacking-lab.com/events/eventregister.html?event=557 OWASP Hackademic] |
− | * University | + | * [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge] |
− | * | + | * [http://www.hacking-lab-ctf.com/ CTF System] |
− | |||
== Presentation == | == Presentation == | ||
− | + | [[File:pdf-icon.png|Download PDF]] [[Media:HL CTF 2016.pdf|HL CTF 2016.pdf]] | |
− | |||
− | |||
+ | [[File:ppt-icon.png|Download Power Point]] [[Media:HL CTF 2016.pptx|HL CTF 2016.pptx]] | ||
== Project Leaders == | == Project Leaders == | ||
Line 66: | Line 61: | ||
== Ohloh == | == Ohloh == | ||
− | *https://www.ohloh.net/p/Hacking_Lab | + | * [https://www.ohloh.net/p/Hacking_Lab Ohloh: Hacking-Lab] |
− | | | + | | style="padding-left:25px;width:200px;" valign="top" | |
== Quick Download == | == Quick Download == | ||
− | + | [[File:zip-icon.png|Download ZIP]] [[Media:Challenge_development_by_OWASP.zip|Challenge Concept Template]] | |
− | |||
− | |||
== News and Events == | == News and Events == | ||
− | |||
− | |||
+ | * [https://www.owasp.org/index.php/OWASP_University_Challenge University Challenge] | ||
+ | * [http://www.europeancybersecuritychallenge.eu/ European Challenge] | ||
== In Print == | == In Print == | ||
Line 89: | Line 82: | ||
{| width="200" cellpadding="2" | {| width="200" cellpadding="2" | ||
|- | |- | ||
− | | | + | | rowspan="2" width="50%" valign="top" align="center" | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]] |
− | | | + | | width="50%" valign="top" align="center" | [[File:Owasp-builders-small.png|link=]] |
|- | |- | ||
− | | | + | | width="50%" valign="top" align="center" | [[File:Owasp-defenders-small.png|link=]] |
|- | |- | ||
− | | colspan="2" align="center" | + | | colspan="2" align="center" | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] |
|- | |- | ||
− | | colspan="2" align="center" | + | | colspan="2" align="center" | [[File:Project_Type_Files_DOC.jpg|link=]] |
|} | |} | ||
Line 134: | Line 127: | ||
*Rating example: | *Rating example: | ||
**If you have 10 points to give this is how to divide them: | **If you have 10 points to give this is how to divide them: | ||
− | ** | + | ***'''3 Points for vulnerability description''' |
− | ** | + | ***'''3 Points for proven exploit''' |
− | ** | + | ***'''4 Points for complete mitigation description''' |
= Acknowledgements = | = Acknowledgements = | ||
Line 185: | Line 178: | ||
The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. | The OWASP Hacking-Lab project is the framework used for the OWASP AppSec University Challenges. | ||
− | This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: https://www.owasp.org/index.php/OWASP_University_Challenge | + | This is an on-site university team versus university team competition run during the training days of an AppSec conference. See more here: [https://www.owasp.org/index.php/OWASP_University_Challenge OWASP University Challenge] |
− | * | + | |
− | * OWASP AppSec EU | + | |
− | * | + | ===Attack-Defense System=== |
+ | [[File:Attack-Defense.png|left|Hacking-Lab]] | ||
+ | The challenges are even more dynamic and realistic now. Instead of just solving different security challenges, teams carry out a virtual online battle against each other in an attack-defense based competition, also known as CTF system. If you are interested to learn more about the CTF system, you will find here more information: [http://www.hacking-lab-ctf.com CTF System] | ||
+ | |||
+ | |||
+ | ===Previous events:=== | ||
+ | *[https://www.hacking-lab.com/references/AppSec_EU_2016_Rome/ AppSec EU 2016 Rome] | ||
+ | *[https://www.hacking-lab.com/references/AppSec_EU_2015_Amsterdam/ AppSec EU 2015 Amsterdam] | ||
+ | *[https://www.hacking-lab.com/references/AppSec_EU_2014_Cambridge/ AppSec EU 2014 Cambridge] | ||
+ | *[https://www.hacking-lab.com/references/AppSec-EU-2013-University-Challenges.pdf AppSec-EU 2013 Hamburg] | ||
+ | *[https://www.hacking-lab.com/references/OWASP-AppSec-Athen-2012/ AppSec-EU 2012 Athens] | ||
+ | *AppSec-US 2012 Austin | ||
+ | *AppSec-US 2011 Minneapolis | ||
+ | |||
+ | ===Questions=== | ||
+ | Please review [https://www.owasp.org/index.php/OWASP_University_Challenge#tab=FAQs University Challenge FAQ] | ||
+ | |||
+ | |||
+ | |||
+ | =European Challenge= | ||
+ | == European Cyber Security Challenge 2016 == | ||
+ | |||
+ | === Introduction === | ||
+ | [[File:Ecsc-logo.png|left|European Cyber Security Challenge]]Today, most countries lack sufficient IT security professionals to protect their IT infrastructure. To help mitigate this problem, many of them set up national cyber security competitions for finding young cyber talents and for encouraging them to pursue a career in cyber security. | ||
+ | |||
+ | The European Cyber Security Challenge (ECSC) leverages these competitions in that it adds a pan-European layer to them: The top cyber talents from each country meet to network and collaborate and finally compete against each other to determine which country has the best cyber talents. To find out which country's team is the best, contestants have to solve security related tasks from domains such as web security, mobile security, crypto puzzles, reverse engineering and forensics and collect points for solving them. | ||
+ | |||
+ | |||
− | + | === How to join the ECSC 2016 === | |
+ | * [http://www.europeancybersecuritychallenge.eu/2016/join/ How to join the ECSC 2016] | ||
=Project About= | =Project About= | ||
{{:Projects/OWASP_Hacking_Lab}} | {{:Projects/OWASP_Hacking_Lab}} | ||
− | __NOTOC__ <headertabs /> | + | __NOTOC__ <headertabs></headertabs> |
− | [[Category:OWASP Project]] [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]] [[Category:OWASP_Document]] | + | [[Category:OWASP Project]] |
+ | [[Category:OWASP_Builders]] | ||
+ | [[Category:OWASP_Defenders]] | ||
+ | [[Category:OWASP_Document]] |
Latest revision as of 12:12, 17 October 2017