Torna agli aggiornamenti
New releaseAug 12, 2026

oss-oopssec-store v2.18.0

Formazione sulla sicurezza per le app che effettivamente distribuisci. Apri il tuo browser e inizia a hackerare.

Condividi

OSS - OopsSec Store

Formazione sulla sicurezza per le app che distribuisci davvero.

36 sfide tra web, API, autenticazione, logica di business, crittografia, supply chain, agenti AI e MCP.

Metti alla prova un'app di e-commerce deliberatamente vulnerabile costruita su Next.js, React, TypeScript e Prisma.
Trova i bug. Sfruttali. Comprendi perché funzionano.

Docker Hub · npm · Roadmap · Walkthroughs · Contributing · Good first issues

OWASP VWAD TryHackMe room Intentionally Vulnerable
GitHub license PRs Welcome Good first issues
GitHub stars GitHub forks

```bash

/ __ / // / / __ \ ___ ___ ___ / / ___ ____ / / / / ___ ____ ___ / // /\ \ \ \ / // // _ \ / _ (-<\ \ / -)/ __/\ \ / // _ \ / // -) _//// __/ _// ./// _/ _/// _/ ___/// _/ /_/

Start with Node.js

npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start

Start with Docker

docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store

Then open http://localhost:3000 and start hacking

<div align="center">

<table>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-0.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-0.png" alt="OopsSec Store storefront" width="100%"></a>
<br><sub><b>Storefront</b> · l'app e-commerce che stai attaccando</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-1.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-1.png" alt="Player dashboard tracking captured flags" width="100%"></a>
<br><sub><b>Player dashboard</b> · progressi, difficoltà e ripartizione per categoria</sub>
</td>
</tr>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-2.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-2.png" alt="OSSBot AI customer support assistant" width="100%"></a>
<br><sub><b>OSSBot</b> · l'assistente AI di supporto su cui fai prompt injection</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-3.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-3.png" alt="Challenge roadmap across 11 chapters" width="100%"></a>
<br><sub><b>Roadmap</b> · i bug che finiscono nel codice di produzione</sub>
</td>
</tr>
</table>

<sub>Clicca su qualsiasi screenshot per visualizzarlo a dimensione intera.</sub>

</div>

---

## Per iniziare

<table>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/1-15803d?style=for-the-badge" alt="Step 1"></td>
<td valign="top">
<b>Avvia il lab</b><br>
<code>npx create-oss-store my-ctf-lab &amp;&amp; cd my-ctf-lab &amp;&amp; npm start</code><br>
<sub>Oppure <a href="#docker">eseguilo con Docker</a>. Lo store si avvia su <a href="http://localhost:3000">localhost:3000</a>.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/2-15803d?style=for-the-badge" alt="Step 2"></td>
<td valign="top">
<b>Passa alla challenge #1</b><br>
<a href="http://localhost:3000/vulnerabilities/public-env-variable">Public env variable leak</a>: un segreto di pagamento che Next.js incorpora nel bundle client.<br>
<sub>Facile · 15–20 min · ti bastano i devtools del browser.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/3-15803d?style=for-the-badge" alt="Step 3"></td>
<td valign="top">
<b>Bloccato? Leggi il walkthrough</b><br>
Ogni challenge ne ha uno, dalla vulnerabilità all'exploit fino alla correzione.<br>
<sub>Il primo: <a href="https://koadt.github.io/oss-oopssec-store/posts/next-public-env-variable-leak/">Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js</a>.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/4-15803d?style=for-the-badge" alt="Step 4"></td>
<td valign="top">
<b>Valida la flag</b><br>
Incolla <code>OSS{...}</code> nel flag checker, il widget flottante presente su ogni pagina.<br>
<sub>La tua <a href="http://localhost:3000/player-dashboard">player dashboard</a> tiene traccia di ciò che resta.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/5-15803d?style=for-the-badge" alt="Step 5"></td>
<td valign="top">
<b>Scegli la prossima</b><br>
La <a href="https://koadt.github.io/oss-oopssec-store/roadmap">roadmap</a> ordina ogni challenge in capitoli: difficoltà, stima del tempo, prerequisiti.<br>
<sub>Prendi la prossima card, poi torna al passo 2. ↻</sub>
</td>
</tr>
</table>

> [!TIP]
> Le hai catturate tutte? [Entra nella Hall of Fame](#hall-of-fame), metti una star al repo e pubblica il tuo percorso in [Show your solve](https://github.com/kOaDT/oss-oopssec-store/discussions/categories/show-your-solve).

<sub>Nuovo alla sicurezza offensiva? La <a href="https://tryhackme.com/jr/oopssecstorethesummeraudit">stanza TryHackMe</a> racchiude le prime flag in una narrazione guidata.</sub>

---

## Indice

- [Features](#features)
- [Perché OopsSec Store?](#why-oopssec-store)
- [Installazione](#installation)
  - [Avvio rapido (npm)](#quick-start)
  - [Docker](#docker)
- [Hall of fame](#hall-of-fame)
- [Community](#community)
- [Struttura del progetto](#project-structure)
- [Testing](#testing)
- [Disclaimer](#disclaimer)
- [Contribuire](#contributing)
- [Educator Kit](#-using-oopssec-store-in-a-course-or-ctf)
- [Statistiche del progetto](#project-stats)

---

> [!WARNING]
> Questa applicazione contiene vulnerabilità di sicurezza intenzionali e non deve mai essere distribuita in un ambiente di produzione.

## Features

Categorie