Skip to content

Cybersecurity portfolio project: OWASP Juice Shop pentest with Critical/High findings, risk ratings, and a consulting-style PDF report.

Notifications You must be signed in to change notification settings

Errorx365/owasp_juice_shop_pentest

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

5 Commits
Β 
Β 
Β 
Β 

Repository files navigation

OWASP Juice Shop – Penetration Testing Report (with Risk Ratings)

owasp_juice_shop_pentest.pdf

πŸ“Œ Project Overview

This repository showcases a penetration testing project conducted on OWASP Juice Shop, a deliberately vulnerable web application.
The project demonstrates end-to-end penetration testing methodology β€” from reconnaissance to exploitation β€” and presents findings in a consulting-style report with risk ratings and remediation steps.


🎯 Objectives

  • Apply a structured penetration testing approach.
  • Identify and exploit common web application vulnerabilities.
  • Provide risk ratings (Critical, High) for each issue.
  • Deliver a professional pentest report for recruiters and hiring managers.

πŸ› οΈ Tools & Techniques Used

  • Reconnaissance: Nmap, Gobuster, Subdomain Enumeration
  • Exploitation: Burp Suite, Manual Testing
  • Documentation: Screenshots, PoC Payloads, PDF Report
  • Vulnerabilities Tested: SQL Injection, IDOR, XSS, Broken Authentication

πŸ”‘ Key Findings

  • SQL Injection – Login Bypass [Critical]
  • Broken Authentication [Critical]
  • Insecure Direct Object Reference (IDOR) [High]
  • Cross-Site Scripting (XSS) [High]

πŸ“Š Risk Rating Summary

Vulnerability Severity Impact
SQL Injection – Login Bypass πŸ”΄ Critical Full authentication bypass, admin access
Broken Authentication πŸ”΄ Critical Unauthorized access with weak credentials
Insecure Direct Object Reference (IDOR) 🟠 High Unauthorized access to other users' data
Cross-Site Scripting (XSS) 🟠 High Session hijacking, account takeover

⚠️ Disclaimer

This assessment was conducted in a controlled lab environment using OWASP Juice Shop, a vulnerable application designed for training.
The work is for educational and portfolio purposes only.


πŸ‘¨β€πŸ’» Author

Koustav Parui
Cybersecurity Enthusiast | Penetration Testing | Vulnerability Assessment

About

Cybersecurity portfolio project: OWASP Juice Shop pentest with Critical/High findings, risk ratings, and a consulting-style PDF report.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published