Skip to content

Commit b33b41b

Browse files
committed
Bugfix for 1.3.12
1 parent 6cef56e commit b33b41b

10 files changed

+12
-10
lines changed

.github/scripts/secondkey.txt

+1
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
6i6wsYk=9CGeo6D3o=2/I617

.gitignore

+3
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,9 @@ azure/k8s/pod-id.yml
6060
# Challenge 12 ;-)
6161
.github/scripts/yourkey.txt
6262

63+
# Challenge 16
64+
.github/scripts/secondkey.txt
65+
6366
# Node JS
6467
js/node/
6568
js/node_modules/

Dockerfile.web

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
FROM jeroenwillemsen/wrongsecrets:1.3.12-no-vault
1+
FROM jeroenwillemsen/wrongsecrets:1.3.12c-no-vault
22

3-
ARG argBasedVersion="1.3.12"
3+
ARG argBasedVersion="1.3.12c"
44
ARG CANARY_URLS="http://canarytokens.com/terms/about/s7cfbdakys13246ewd8ivuvku/post.jsp,http://canarytokens.com/terms/about/y0all60b627gzp19ahqh7rl6j/post.jsp"
55
ENV APP_VERSION=$argBasedVersion
66
ENV K8S_ENV=Heroku(Docker)

README.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ For the basic docker exercises you currently require:
2525
You can install it by doing:
2626

2727
```bash
28-
docker run -p 8080:8080 jeroenwillemsen/wrongsecrets:1.3.12-no-vault
28+
docker run -p 8080:8080 jeroenwillemsen/wrongsecrets:1.3.12c-no-vault
2929
```
3030

3131
Now you can try to find the secrets by means of solving the challenge offered at:

aws/k8s/secret-challenge-vault-deployment.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ spec:
3737
volumeAttributes:
3838
secretProviderClass: "wrongsecrets-aws-secretsmanager"
3939
containers:
40-
- image: jeroenwillemsen/wrongsecrets:1.3.12-k8s-vault
40+
- image: jeroenwillemsen/wrongsecrets:1.3.12c-k8s-vault
4141
imagePullPolicy: IfNotPresent
4242
ports:
4343
- containerPort: 8080

azure/k8s/secret-challenge-vault-deployment.yml.tpl

+1-1
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ spec:
3535
volumeAttributes:
3636
secretProviderClass: "azure-wrongsecrets-vault"
3737
containers:
38-
- image: jeroenwillemsen/wrongsecrets:1.3.12-k8s-vault
38+
- image: jeroenwillemsen/wrongsecrets:1.3.12c-k8s-vault
3939
imagePullPolicy: IfNotPresent
4040
ports:
4141
- containerPort: 8080

k8s/secret-challenge-deployment.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ spec:
2828
runAsGroup: 2000
2929
fsGroup: 2000
3030
containers:
31-
- image: jeroenwillemsen/wrongsecrets:1.3.12-no-vault
31+
- image: jeroenwillemsen/wrongsecrets:1.3.12c-no-vault
3232
imagePullPolicy: IfNotPresent
3333
ports:
3434
- containerPort: 8080

k8s/secret-challenge-vault-deployment.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ spec:
3030
runAsNonRoot: true
3131
serviceAccountName: vault
3232
containers:
33-
- image: jeroenwillemsen/wrongsecrets:1.3.12-k8s-vault
33+
- image: jeroenwillemsen/wrongsecrets:1.3.12c-k8s-vault
3434
imagePullPolicy: IfNotPresent
3535
ports:
3636
- containerPort: 8080

pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
</parent>
1010
<groupId>org.owasp</groupId>
1111
<artifactId>wrongsecrets</artifactId>
12-
<version>1.3.12-SNAPSHOT</version>
12+
<version>1.3.12c-SNAPSHOT</version>
1313
<name>OWASP WrongSecrets</name>
1414
<description>Examples with how to not use secrets</description>
1515
<url>https://owasp.org/www-project-wrongsecrets/</url>

src/main/resources/application.properties

-2
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,6 @@ spring.cloud.vault.kubernetes.kubernetes-path=kubernetes
4848
spring.cloud.vault.kubernetes.service-account-token-file=/var/run/secrets/kubernetes.io/serviceaccount/token
4949
#---
5050
spring.config.activate.on-profile=local-vault
51-
challengedockermtpath=./
5251
wrongsecretvalue=wrongsecret
5352
spring.config.import=vault://secret/secret-challenge
5453
spring.application.name=secret-challenge
@@ -60,7 +59,6 @@ spring.cloud.vault.authentication=TOKEN
6059
spring.cloud.vault.token=00000000-0000-0000-0000-000000000000
6160
#---
6261
spring.config.activate.on-profile=without-vault
63-
challengedockermtpath=./
6462
wrongsecretvalue=wrongsecret
6563
spring.cloud.vault.enabled=false
6664
asciidoctor.enabled=true

0 commit comments

Comments
 (0)