
New releaseSep 10, 2026
oss-oopssec-store v2.20.0
실제로 출시하는 앱을 위한 보안 교육입니다. 브라우저를 열고 해킹을 시작하세요.
OSS - OopsSec Store
실제로 배포하는 앱을 위한 보안 교육.
웹, API, 인증, 비즈니스 로직, 암호학, 공급망, AI 에이전트 및 MCP 전반에 걸친 36개의 챌린지.
Next.js, React, TypeScript 및 Prisma로 구축된 의도적으로 취약한 이커머스 앱을 공략하세요.
버그를 찾고. 익스플로잇하고. 왜 작동하는지 이해하세요.
/ __ / // / / __ \ ___ ___ ___ / / ___ ____ / / / / ___ ____ ___ / // /\ \ \ \ / // // _ \ / _ (-<\ \ / -)/ __/\ \ / // _ \ / // -) _//// __/ _// ./// _/ _/// _/ ___/// _/ /_/
Start with Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
Start with Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store
Then open http://localhost:3000 and start hacking
<div align="center">
<table>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-0.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-0.png" alt="OopsSec Store storefront" width="100%"></a>
<br><sub><b>Storefront</b> · 공격 대상인 이커머스 앱</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-1.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-1.png" alt="Player dashboard tracking captured flags" width="100%"></a>
<br><sub><b>플레이어 대시보드</b> · 진행 상황, 난이도 및 카테고리 분석</sub>
</td>
</tr>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-2.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-2.png" alt="OSSBot AI customer support assistant" width="100%"></a>
<br><sub><b>OSSBot</b> · 프롬프트 인젝션 대상인 AI 지원 어시스턴트</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-3.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-3.png" alt="Challenge roadmap across 11 chapters" width="100%"></a>
<br><sub><b>로드맵</b> · 프로덕션 코드에 배포되는 버그들</sub>
</td>
</tr>
</table>
<sub>스크린샷을 클릭하면 원본 크기로 볼 수 있습니다.</sub>
</div>
---
## 시작하기
<table>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/1-15803d?style=for-the-badge" alt="Step 1"></td>
<td valign="top">
<b>랩 시작하기</b><br>
<code>npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start</code><br>
<sub>또는 <a href="#docker">Docker로 실행하기</a>. 스토어는 <a href="http://localhost:3000">localhost:3000</a>에서 실행됩니다.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/2-15803d?style=for-the-badge" alt="Step 2"></td>
<td valign="top">
<b>챌린지 #1 도전하기</b><br>
<a href="http://localhost:3000/vulnerabilities/public-env-variable">퍼블릭 환경 변수 유출</a>: Next.js가 클라이언트 번들에 포함시키는 결제 시크릿.<br>
<sub>쉬움 · 15–20분 · 브라우저 개발자 도구만 있으면 됩니다.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/3-15803d?style=for-the-badge" alt="Step 3"></td>
<td valign="top">
<b>막혔나요? 해설을 읽어보세요</b><br>
모든 챌린지에는 취약점부터 익스플로잇, 수정까지 다루는 해설이 있습니다.<br>
<sub>첫 번째: <a href="https://koadt.github.io/oss-oopssec-store/posts/next-public-env-variable-leak/">브라우저에서 시크릿 읽기: Next.js의 NEXT_PUBLIC_ 함정</a>.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/4-15803d?style=for-the-badge" alt="Step 4"></td>
<td valign="top">
<b>플래그 검증하기</b><br>
<code>OSS{...}</code>를 모든 페이지에 떠 있는 플래그 검사 위젯에 붙여넣으세요.<br>
<sub><a href="http://localhost:3000/player-dashboard">플레이어 대시보드</a>에서 남은 항목을 추적합니다.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/5-15803d?style=for-the-badge" alt="Step 5"></td>
<td valign="top">
<b>다음 챌린지 선택하기</b><br>
<a href="https://koadt.github.io/oss-oopssec-store/roadmap">로드맵</a>은 모든 챌린지를 챕터별로 정리합니다: 난이도, 예상 시간, 사전 요구 사항.<br>
<sub>다음 카드를 선택한 후 2단계로 돌아가세요. ↻</sub>
</td>
</tr>
</table>
> [!TIP]
> 모두 클리어했나요? [명예의 전당에 참여하고](#hall-of-fame), 저장소에 스타를 눌러주세요. 그리고 [Show your solve](https://github.com/kOaDT/oss-oopssec-store/discussions/categories/show-your-solve)에 여러분의 공략 경로를 공유하세요.
<sub>오펜시브 보안이 처음이신가요? <a href="https://tryhackme.com/jr/oopssecstorethesummeraudit">TryHackMe 룸</a>에서 첫 플래그들을 안내형 스토리로 체험할 수 있습니다.</sub>
---
## 목차
- [기능](#features)
- [왜 OopsSec Store인가?](#why-oopssec-store)
- [설치](#installation)
- [빠른 시작 (npm)](#quick-start)
- [Docker](#docker)
- [명예의 전당](#hall-of-fame)
- [커뮤니티](#community)
- [프로젝트 구조](#project-structure)
- [테스트](#testing)
- [면책 조항](#disclaimer)
- [기여하기](#contributing)
- [교육자 키트](#-using-oopssec-store-in-a-course-or-ctf)
- [프로젝트 통계](#project-stats)
---
> [!WARNING]
> 이 애플리케이션에는 의도적인 보안 결함이 포함되어 있으며, 프로덕션 환경에 절대 배포해서는 안 됩니다.
## 기능
- 의도적으로 취약한 이커머스 앱 (XSS, CSRF, IDOR, JWT 공격, 경로 탐색, SQL 인젝션 등)
- Next.js (App Router), React, TypeScript, Prisma, SQLite로 구축
- 공격 벡터가 문서화된 REST API
- 11개 챕터에 걸친 36개의 CTF 챌린지, 체계적인 [학습 로드맵](https://koadt.github.io/oss-oopssec-store/roadmap)으로 구성
- 각 챌린지에 대한 취약점 문서 및 커뮤니티 해설
- 안내형 [TryHackMe 룸](https://tryhackme.com/jr/oopssecstorethesummeraudit): _The Summer Audit_, 8개 태스크와 7개 플래그로, 초보자를 위한 스토리형 입문 과정
- 익스플로잇이 여전히 작동하는지 검증하는 자동화 테스트 (실수로 취약점을 수정하는 PR은 CI에서 실패합니다)
## 왜 OopsSec Store인가?
최신 프레임워크는 보안 취약점이 나타나는 위치와 수정 방법을 바꿔놓았습니다. OopsSec Store는 고전적인 취약점 유형을 오늘날 많은 개발자가 사용하는 스택에 담았습니다: Next.js App Router, React, TypeScript, Prisma.
서버 렌더링 컴포넌트, 미들웨어, ORM은 서로 다른 신뢰 경계와 실패 모드를 도입합니다. 여러 챌린지는 이 스택에 대해 공개된 CVE를 재현하기도 합니다.
커리큘럼은 AI 지원 개발과 함께 등장한 공격 표면도 다룹니다: 고객 지원 에이전트에 대한 프롬프트 인젝션, MCP 도구 포이즈닝, 백도어가 심어진 코딩 에이전트 규칙 파일, 그리고 엔드 투 엔드로 시뮬레이션된 npm 타이포스쿼팅 체인.