Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
oss-oopssec-store — Security training for the apps you actually ship. Open your browser and start hacking. | Kitploit
उपकरण/GitHubGitHub/koadt/oss-oopssec-store
Vulnerability AnalysisWeb Application ExploitationWeb SecurityCTFPenetration TestingSupply Chain SecurityLearning & EducationLearning Paths & CoursesAI SecurityLabs & Practice
GitHubkoadt/oss-oopssec-store
3445405 दिन पहलेKitploit द्वारा समीक्षित

oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

रिपॉजिटरी देखेंवेबसाइट

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

OSS - OopsSec Store

Security training for the apps you actually ship.

36 challenges across web, API, authentication, business logic, cryptography, supply chain, AI agents and MCP.

Break a deliberately vulnerable e-commerce app built on Next.js, React, TypeScript and Prisma.
Find the bugs. Exploit them. Understand why they work.

Docker Hub · npm · Roadmap · Walkthroughs · Contributing · Good first issues

OWASP VWAD TryHackMe room Intentionally Vulnerable
GitHub license PRs Welcome Good first issues
GitHub stars GitHub forks


   ____  ____ ____     ____                  ____            ____  _
  / __ \/ __// __/    / __ \ ___   ___  ___ / __/ ___  ____ / __/ / /_ ___   ____ ___
 / /_/ /\ \ _\ \     / /_/ // _ \ / _ \(_-<_\ \  / -_)/ __/_\ \  / __// _ \ / __// -_)
 \____/___//___/     \____/ \___// .__/___/___/  \__/ \__//___/  \__/ \___//_/   \__/
                                /_/

# Start with Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start

# Start with Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store

# Then open http://localhost:3000 and start hacking
OopsSec Store storefront
Storefront · the e-commerce app you are attacking
Player dashboard tracking captured flags
Player dashboard · progress, difficulty and category breakdown
OSSBot AI customer support assistant
OSSBot · the AI support assistant you prompt-inject
Challenge roadmap across 11 chapters
Roadmap · the bugs that ship in production code

Click any screenshot to view it full size.


Getting started

Step 1 Start the lab
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
Or run it with Docker. The store comes up on localhost:3000.
Step 2 Go after challenge #1
Public env variable leak: a payment secret that Next.js bakes into the client bundle.
Easy · 15–20 min · nothing but your browser devtools.
Step 3 Stuck? Read the walkthrough
Every challenge has one, from vulnerability to exploit to fix.
The first: Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js.
Step 4 Validate the flag
Paste OSS{...} into the flag checker, the floating widget on every page.
Your player dashboard tracks what is left.
Step 5 Pick the next one
The roadmap orders every challenge across chapters: difficulty, time estimate, prerequisites.
Take the next card, then back to step 2. ↻

[!TIP] All captured? Join the Hall of Fame, star the repo, and post your route in Show your solve.

New to offensive security? The TryHackMe room wraps the first flags in a guided narrative.


Table of contents

  • Features
  • Why OopsSec Store?
  • Installation
    • Quick start (npm)
    • Docker
    • Updating an existing install
  • Hall of fame
  • Community
  • Project structure
  • Testing
  • Disclaimer
  • Contributing
  • Educator Kit
  • Project stats

[!WARNING] This application contains intentional security flaws and must never be deployed in a production environment.

Features

टूल डाउनलोड करें