This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
OWASP Snakes and Ladders
- Main
- Web Applications Edition
- Mobile Apps Edition
- FAQs
- Acknowledgements
- Road Map and Getting Involved
OWASP Snakes and LaddersSnakes and Ladders is an educational project. It uses gamification to promote awareness of application security controls and risks, and in particular knowledge of other OWASP documents and tools. EditionsWeb Applications In the board game for web applications, the virtuous behaviours (ladders) are secure coding practices (from OWASP Proactive Controls project 2014) and the vices (snakes) are application security risks (from OWASP Top Ten Project 2013). Mobile Apps The identical board game for mobile apps uses mobile controls (from the Mobile Security Project Top Ten Controls 2013) as the virtuous behaviours and mobile risks (from the Top Ten Mobile Risks 2014 from the same project) as the vices. Application Intrusion Detection Coming soon. BackgroundThis board game was created to use as an ice-breaker in application security training, but it potentially has wider appeal simply as a promotional hand-out, and maybe also more usefully as learning materials for younger coders. To cover all of that, we use the phrase "OWASP Snakes and Ladders is meant to be used by software programmers, big and small". The game is quite lightweight, and does not have the same rigour or depth as the card game Cornucopia, but it is meant to be just some fun with some learning attached. Print-ready PDFs have been published - these are poster sized A2 (international ISO 216 paper size 420×594mm, approximately 16.5×23.4in, with 3mm bleed and printers' marks). But the original files are in Adobe Illustrator, so these are also available for anyone to use and improve upon. We recommend playing using a real die and counters (markers), but you can cut out and make these from the paper sheet itself if you have scissor and glue skills. We hope it may be of use in any upcoming office party, celebration, festival, seasonal event, application security awareness or training exercise. Or just to help spread the word about controls and risks at work, at college or at school. If you are training anyone about the OWASP Top Ten, OWASP Proactive Controls or the OWASP Mobile projects, please consider giving each attendee a printed copy of the game as a take away. LicensingOWASP Cornucopia is free to use. It is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. © OWASP Foundation Other Security GamificationIf you are interested in using gaming for security, also see OWASP Cornucopia, Elevation of Privilege: The Threat Modeling Game, Security Cards from the University of Washington, the commercial card game Control-Alt-Hack (presentation for latter), and web application security training tools incorporating gamification such as OWASP Hackademic Challenges Project, OWASP Security Shepherd and ITSEC Games. Additionally, Adam Shostack maintains a list of tabletop security games and related resources at security games. |
What is This?Snakes and Ladders is a popular board game, with ancient provenance imported into Great Britain from Asia in the 19th century. The original game showed the effects of good and evil, or virtues and vices. This OWASP game is a poster-sized print-your-own paper sheet with the game board on it. Just get some players together with a die and counters. The virtues are application security controls, and the vices are risks. How to Play
Project LeaderColin Watson Related Projects |
Quick Download
News and Events
Follow two mock games running on Twitter: Classifications |
OWASP Snakes and Ladders - Web Applications
This was the first edition created. The objective is to raise awareness of the security controls that every web application should have, but link that with the much more widely known Top Ten Risks. The virtuous behaviours (ladders) are secure coding practices (from OWASP Proactive Controls project 2014) and the vices (snakes) are application security risks (from OWASP Top Ten Project 2013).
Current Release
DE: Deutsch | EN: English | ES: Español |
Schlangen und Leitern Web Anwendungen |
Snakes and Ladders Web Applications |
Serpientes y Escaleras Aplicaciones Web |
|
|
|
FR: Français | JA: 日本語 | ZH: 中文 |
Serpents et Échelles Application Web |
蛇とはしご ウェブアプリケーション |
蛇梯棋 WEB应用程序 |
(Source Adobe Illustrator file)
Release History
- [25 Nov 2014] 1.0.2 - Additional contributors added, FR, JA and ZH versions released
- [05 Nov 2014] 1.0.1 - Correction to paths in source Illustrator file; PDFs regenerated
- [31 Oct 2014] 1.0 - First release
Colour Scheme 'Classic'
This edition uses simple primary colours, like many versions that can be seen in pictures of Snakes and Ladders games. The colours used in 'Classic' are:
- Green
- Yellow
- White
- Red
- Blue
The start square (1) is yellow and the final square (100) is red.
OWASP Snakes and Ladders - Mobile Apps
The edition for Mobile Apps was created after working out the idea and design for the web application version of the board game. It seemed easy to replicate the idea since the OWASP Mobile Project lists both security controls and risks. The virtuous behaviours (ladders) are mobile controls (from the Mobile Security Project Top Ten Controls 2013) and the vices (snakes) are mobile risks (from the Top Ten Mobile Risks 2014).
Current Release
EN: English | JA: 日本語 |
Snakes and Ladders Mobile Apps |
Snakes and Ladders 蛇とはしご モバイルアプリ版 |
(Source Adobe Illustrator file)
Release History
- [02 Dec 2014] 1.0.2 - Additional contributor added, JA version released
- [05 Nov 2014] 1.0.1 - Correction to paths in source Illustrator file; EN PDF regenerated
- [31 Oct 2014] 1.0 - First release
Colour Scheme 'Farringdon'
Other people's versions of Snakes and Ladders use a wide variety of designs and colour schemes. Thus to make a complete contrast to the edition for web applications, the colours used are the designatory colours of the underground and mainline train services that run through Colin Watson's local station at Farringdon in Clerkenwell, London EC1. The colours in 'Farringdon' are:
- Purple (future Crossrail)
- Yellow (Circle)
- White (Thameslink)
- Maroon (Metropolitan)
- Pink (Hammersmith & City)
You can see these colours on tube maps and station signage. The start square (1) is yellow and the final square (100) is maroon.
How was the game created?
TBC
How can I participate in your project?
All you have to do is make the Project Leader aware of your available time to contribute to the project. It is also important to let the Leader know how you would like to contribute and pitch in to help the project meet its goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. Please see the road map and getting involved section
If I am not a programmer can I participate in your project?
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for users, translators and people to promote the project.
Volunteers
Snakes and Ladders is developed, maintained, updated and promoted by a worldwide team of volunteers. The contributors to date have been:
- Manuel Lopez Arredondo
- Fabio Cerullo
- Tobias Gondrom
- Martin Haslinger
- Yongliang He
- Cédric Messeguer
- Takanori Nakanowatari
- Riotaro Okada
- Ferdinand Vroom
- Ivy Zhang
- Colin Watson
Others
- The project leaders and contributors to the referenced controls and risks:
- OWASP staff for helping to set up the project and support its ongoing activities.
As of November 2014, the priorities are:
- Promote use of Snakes and Ladders [In progress]
- Create a project presentation
- Translate into other languages
- Develop other boards
Involvement in the development and promotion of Snakes and Ladders is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help are listed below.
Localization
Are you fluent in another language? Can you help translate Snakes and Ladders into that language?
Use and Promote the Board Game
Please help raise awareness of Snakes and Ladders:
- Use the game with your colleagues, friends, families, students and children
- Create video about how to play the game
- Develop a multi-user mobile app or web application to play the game
Feedback
Please use the project mailing list for feedback:
- How did you use it?
- What is people's reaction?
- What do like?
- What don't you like?
- What doesn't make sense?
- How could the guidance be improved?
- What other boards would you like to see?
Create a Board
Do you have an idea for your own application security Snakes and Ladders board? Please contribute your ideas via the mailing list.