Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
oss-oopssec-store — Security training for the apps you actually ship. Open your browser and start hacking. | Kitploit
Tools/GitHubGitHub/koadt/oss-oopssec-store
Vulnerability AnalysisWeb Application ExploitationWeb SecurityCTFPenetration TestingSupply Chain SecurityLearning & EducationLearning Paths & CoursesAI SecurityLabs & Practice
GitHubkoadt/oss-oopssec-store
344539vor 5 TagenVon Kitploit geprüft

oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

Repository anzeigenWebseite

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Inhalt in der angeforderten Sprache nicht verfügbar. Englische Version wird angezeigt.

OSS - OopsSec Store

Security training for the apps you actually ship.

36 challenges across web, API, authentication, business logic, cryptography, supply chain, AI agents and MCP.

Break a deliberately vulnerable e-commerce app built on Next.js, React, TypeScript and Prisma.
Find the bugs. Exploit them. Understand why they work.

Docker Hub · npm · Roadmap · Walkthroughs · Contributing · Good first issues

OWASP VWAD TryHackMe room Intentionally Vulnerable
GitHub license PRs Welcome Good first issues
GitHub stars GitHub forks


   ____  ____ ____     ____                  ____            ____  _
  / __ \/ __// __/    / __ \ ___   ___  ___ / __/ ___  ____ / __/ / /_ ___   ____ ___
 / /_/ /\ \ _\ \     / /_/ // _ \ / _ \(_-<_\ \  / -_)/ __/_\ \  / __// _ \ / __// -_)
 \____/___//___/     \____/ \___// .__/___/___/  \__/ \__//___/  \__/ \___//_/   \__/
                                /_/

# Start with Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start

# Start with Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store

# Then open http://localhost:3000 and start hacking
OopsSec Store storefront
Storefront · the e-commerce app you are attacking
Player dashboard tracking captured flags
Player dashboard · progress, difficulty and category breakdown
OSSBot AI customer support assistant
OSSBot · the AI support assistant you prompt-inject
Challenge roadmap across 11 chapters
Roadmap · the bugs that ship in production code

Click any screenshot to view it full size.


Getting started

Step 1 Start the lab
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
Or run it with Docker. The store comes up on localhost:3000.
Step 2 Go after challenge #1
Public env variable leak: a payment secret that Next.js bakes into the client bundle.
Easy · 15–20 min · nothing but your browser devtools.
Step 3 Stuck? Read the walkthrough
Every challenge has one, from vulnerability to exploit to fix.
The first: Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js.
Step 4 Validate the flag
Paste OSS{...} into the flag checker, the floating widget on every page.
Your player dashboard tracks what is left.
Step 5 Pick the next one
The roadmap orders every challenge across chapters: difficulty, time estimate, prerequisites.
Take the next card, then back to step 2. ↻

[!TIP] All captured? Join the Hall of Fame, star the repo, and post your route in Show your solve.

New to offensive security? The TryHackMe room wraps the first flags in a guided narrative.


Table of contents

  • Features
  • Why OopsSec Store?
  • Installation
    • Quick start (npm)
    • Docker
    • Updating an existing install
  • Hall of fame
  • Community
  • Project structure
  • Testing
  • Disclaimer
  • Contributing
  • Educator Kit
  • Project stats

[!WARNING] This application contains intentional security flaws and must never be deployed in a production environment.

Features

Tool herunterladen