Offline Lab: A Modern Target (OWASP Juice Shop)

Free Medium Lab Offline lab Avg. time 50 min Solved by 0 2 keys · 35 pts Build Your Lab

DVWA is a classic PHP app; Juice Shop is a modern JavaScript single-page application, so it behaves like the apps you will actually test today. It is an official OWASP project built for training, with a built-in scoreboard of challenges. You run it locally and explore it as you would any unfamiliar target.

Log in or create a free account to submit keys and track your progress.

What you will learn

  • Run a modern single-page application locally
  • Do first-contact recon on an unfamiliar app (robots.txt, the scoreboard, the API traffic)
  • Use browser devtools to watch the API calls a modern app makes
  • Apply the access-control and recon ideas against a target you control

Before you start

These exercises cover what this one builds on.

Offline lab — set up on your own machine

This lab runs locally, not on our servers. Follow the set-up below, attack the target on your own machine, then submit the keys here. Only practise against targets you have set up yourself.

OWASP Juice Shop is a free, official OWASP training application. Run it locally with Docker in one command.

# Run Juice Shop on your own machine (listens on port 3000)
docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shop

# Then open it in your browser:
#   http://127.0.0.1:3000

Prefer Node.js? With Node 20+ installed:

git clone https://github.com/juice-shop/juice-shop.git
cd juice-shop
npm install
npm start      # then open http://127.0.0.1:3000
Warning Keep it bound to 127.0.0.1. Juice Shop is intentionally vulnerable — it is a training target for your machine only, never something to deploy publicly.

Juice Shop has a hidden scoreboard of challenges; finding it is itself the first challenge. Part of this lab is discovering it the way you would on any app.

Get the target

1 A target that behaves like the real thing

Modern web apps are mostly single-page applications: the browser loads a bundle of JavaScript once, and from then on the page talks to the server through background API calls rather than full page loads. Testing them feels different from testing a classic server-rendered app, and the best way to get used to it is to run one you control.

Set up and explore a local target
Set up and explore a local target

Juice Shop is exactly that kind of app, built by OWASP for practice. Set it up with the panel at the top of this page, open http://127.0.0.1:3000, and just use it for a few minutes — browse products, make an account, add things to a basket. You are getting a feel for the app before you probe it, which is what real recon looks like.

2 First-contact recon

Recall the recon exercise: before testing, you map. On a web app that means noticing what it exposes and how it talks to its server.

Recon before you probe
Recon before you probe

Three things to do on your local Juice Shop:

  • Check robots.txt. Visit http://127.0.0.1:3000/robots.txt. This file asks search engines not to index certain paths — which often points you straight at interesting ones. Note what it mentions.
  • Open your browser's developer tools (F12) and watch the Network tab while you click around. You will see the background API calls the single-page app makes — the real surface you would test. Notice the URL patterns (they look like an API: /rest/..., /api/...).
  • Find the scoreboard. Juice Shop hides a challenge scoreboard. Finding it is a recon exercise in itself — the hints above (robots.txt, watching traffic, guessing an obvious path) are how people find it. When you reach it, you will see dozens of built-in challenges graded by difficulty, which you can keep working through long after this lab.

None of this is "attacking" yet — it is learning the shape of the target, which is most of the job.

3 Confirm you did it

The keys check a couple of facts you can only know from running Juice Shop and looking around. Because this is an offline lab on your own machine, the keys are observations about the app, not a captured flag.

Keep the instance — the built-in scoreboard gives you a huge, free, legal set of challenges to grow with, all on a target you fully control.

Tip Leave the Network tab of devtools open as you use any web app. Getting fluent at reading an app's real API traffic is one of the highest-value habits in web testing.

Submit your keys

Keys are not case-sensitive. Each is worth points the first time you get it right.

Key 1What port does OWASP Juice Shop listen on by default (the one in http://127.0.0.1:____)?

+15 pts

Show a hintIt is in the run command and the URL above.

A written solution is included with Pro, or appears here once you solve it.

Key 2Which small text file, requested at the site root, is a classic first-recon check that can hint at hidden paths? (filename including extension)

+20 pts

Show a hintIt tells search-engine crawlers where not to go.

A written solution is included with Pro, or appears here once you solve it.

References

Next exerciseOffline Lab: See & Edit Real Requests (Intercepting Proxy) →