Skip to content
duckdrinkerPublic
forked from xygeni/xygeni-goat

About

For Karate tests

Resources

Stars

0 stars

Watchers

0 watching

Forks

 
 

Latest commit

 

History

16 Commits

Folders and files

Repository files navigation

xygeni-goat - Vulnerable repository against supply chain attacks

Maintained by xygeni.io

A deliberately vulnerable repository against software supply chain attacks, by Xygeni.

Introduction

xygeni-goat

Xygeni-goat helps to understand DevOps teams the best practices to follow and which issues should be avoided, for having a good security posture, lowering the risk against software supply chain attacks. Looking at the elements reported as security flaws, you may learn about misconfigurations to avoid. IaC templates that contains insecure configurations, hardcoded secrets, unsafe tool configurations, troublesome dependencies and more are covered.

This repository is based on existing "Goat" projects, like OWASP WebGoat.

Shear the (nefarious) goat !

WARNING: This repository is for educational purposes only. Do NOT attempt to use the techniques and items shown for unauthorized hacking. Do NOT deploy assets from this repository this in any environment.

DISCLAIMER: Xygeni-goat comes with no warranties. By using xygeni-goat, you take full responsibility for any outcomes. Xygeni would not be liable of any misuse of the information and assets contained in this repository.

Getting Started

Clone the repo, or download

git clone https://github.com/xygeni/xygeni-goat.git

or

gh repo clone xygeni/xygeni-goat

Install the Xygeni scanner

Download the scanner zipfile from https://get.xygeni.io/latest/scanner/xygeni_scanner.zip and unzip it, e.g. in your $HOME directory (it will create a xygeni_scanner directory).

You may check it against the SHA-256 checksum.

You need a personal or organizational Xygeni API token. Set the XYGENI_TOKEN environment variable with the token (export XYGENI_TOKEN=…​ in Linux/macOS, or set XYGENI_TOKEN …​ plus setx XYGENI_TOKEN …​ in Windows).

Tip
You may also set an alias to the xygeni script.

For full details, read Quick start with Xygeni CLI.

Run the scanner on xygeni-goat

Run the scan command over the contents in the xygeni-goat/source directory, or any subdirectory beneath for a partial analysis.

Under Linux / macOS:

cd xygeni-goat/source
"$HOME/xygeni_scanner/xygeni" scan

Under Windows (Powershell):

cd xygeni-goat/source
"$HOME\xygeni_scanner\xygeni.ps1" scan

Open the referenced link to see the findings in the Xygeni dashboard !

To use other scan commands, follow the instructions in the Xygeni CLI Overview.

Contributing

You may add your own vulnerable items to help others learn about additional security issues, and raise awareness on new potential attacks. We recommend you to keep the existing directory structure for better categorizing those security issues. Pull Requests are welcomed !

In addition, if you want to add a new "capture the flag" (CTF) check, you are welcome!

Development

  1. Clone the repository:

    git clone https://github.com/xygeni/xygeni-goat.git

    or

    gh repo clone xygeni/xygeni-goat

    Alternatively, you may fork the repo.

  2. Create your topic branch

  3. Develop your changes

    We recommend to follow the existing directory structure for categorizing the security issue.

  4. Test your changes

    If you developed a new check, test with [TBD].

    If you created a new vulnerable element, test it with Xygeni scanner, as shown in the Getting Started section.

  5. Push commits to your topic branch.

  6. Create a pull request, using gh pr create command or the GitHub desktop / web UI.

    After review, your PR will be merged.

Add a new Capture The Flag challenge

[TBD]

Each CTF challenge has a separate directory in the ctf directory. Follow the steps below to add a CTF challenge:

  1. Write challenge description.

  2. Choose category and difficulty level.

  3. Write hints for help.

  4. Add a flag. Ensure that it is not accesible when solving other CTF challenges.

  5. Write tests.

  6. Write the solution.

  7. Create a README.md in your CTF directory.

Support

[TBD]

About

For Karate tests

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages