Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
owasp-ctf-in-a-box — Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies | Kitploit
工具/GitHubGitHub/owasp/owasp-ctf-in-a-box
Container SecurityVulnerability AnalysisSecurity VirtualizationWeb SecurityCTFPenetration TestingDevSecOpsLearning & EducationLabs & Practice
GitHubowasp/owasp-ctf-in-a-box

owasp-ctf-in-a-box

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

1581268天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库网站
内容在请求的语言中不可用。显示英文版本。

OWASP

OWASP CTF in a Box

A self-hosted control plane for security-learning events — one box, one free GitHub org.
Run it for a university, a high school, an OWASP chapter, a meetup.

ci docs code license MIT docs license CC BY-SA 4.0 OWASP incubator project

Walkthrough of the contestant leaderboard: sweeping the score-over-time graph to read every team's points at that instant, then expanding the leading team to its members, its per-module totals, its per-target breakdown and the list of flags it has open

Working on the kit (humans and agents)

Read AGENTS.md before you write code. It is the operating manual: the exact commands CI runs, the failure modes this repo has already hit, and the review invariants in docs/reviewing.md. CLAUDE.md is a pointer to the same file.

A change is ready when CI is green and every actionable CodeRabbit thread on the latest commit is resolved (or declined on the record). Commits follow Conventional Commits and carry no AI attribution.

Small, well-specified work is tagged good first issue. New modules start as an issue, not a PR — see CONTRIBUTING.md.

What this is

A control plane, not a single game. The box gives an event its shared spine — a GitHub org, team registration, a live leaderboard, an organizer admin panel, and the scoring pipeline that feeds it. Modules plug challenge content into that spine, and any subset can run alone or together: patch-to-score Secure Development, a Quiz bank, a Jeopardy board, and externally hosted AI challenges. The module contract is the boundary between spine and content, so the box is built to host further modules — forensics, API-security, cloud — as they land.

Why it exists. The Secure Development module teaches defence rather than attack, and it is a genuinely good way to teach secure coding. Until now, running one meant standing up Vercel, Upstash, Lambda and DynamoDB, holding the cloud bill, and having access to a private scoring image. That is a reasonable ask for a conference with a budget. It is an unreasonable ask for a university security course, a high-school club, an OWASP chapter night, or a weekend workshop.

This kit removes it. Everything runs from Docker Compose on one machine you already have — a laptop, a spare desktop, a small VPS — plus one free GitHub org for the forks. The rubrics for all six targets ship inside the box, so there is no private image to request and no scoring code to write. Nothing is billed, nothing phones home, and when the event ends you archive the repos and stop the stack.

Who it's for: anyone who wants to run this event and does not want to become a cloud operator to do it — course instructors, club organizers, OWASP chapter leads, workshop facilitators, security teams running an internal training day.

Status

Deployed and exercised end to end; not yet run for a real cohort. The full scoring path ships in-kit — the scorer's bearer-authed POST /score, the self-contained scoring workflow for the forks, the poll transport — and scripts/smoke.sh drives that whole pipeline against mocks. Beyond that, the kit runs continuously on a hosted box from the same Compose file this repo ships, GET /health reports the exact revision serving it, and an end-to-end pass over that live instance is where a batch of real defects were found and fixed — the sort a mocked suite cannot see.

What has not happened is a real event: a cohort of contestants opening real PRs against real forks, at once, for hours. That is the gap between "the pipeline works" and "the pipeline works at 40 people". Two caveats are open rather than buried: the Security Shepherd result matcher has a stated residual limit (an unusually-phrased refusal can still read as a solve — it can under-credit a correct patch, never award a free point), and the load profile of a full cohort is untested. Detail and current state: Status and upstream dependencies.

What it is not

  • Not a general CTF platform. CTFd is mature, battle-tested, and has a large plugin ecosystem — if you want a conventional jeopardy or attack-defense event with maximum flexibility, use CTFd. This kit's Jeopardy module is deliberately smaller than CTFd.
  • Not a hosted practice gym. picoCTF gives you curriculum and challenges with zero operations — if you don't need to run your own event with your own content and roster, it's the better answer.
  • Not an attack trainer. The flagship module grades patches, not exploits. Contestants fix vulnerabilities and a pipeline proves the fix.

What it does that those don't: patch-to-score defence training graded through GitHub pull requests, a module contract for mixing game types on one leaderboard, and a control plane you own end to end — one box, one free org, no cloud bill, no telemetry.

This is an OWASP Foundation project — an incubator-level tool project; its home page is owasp.org/projects/ctf-in-a-box. Four of the six vulnerable targets are OWASP projects (Juice Shop, WebGoat, Security Shepherd, VulnerableApp); DVWA and VAmPI are community projects. OWASP does not endorse or recommend any product or service, including the targets this kit hosts — they are training material, chosen for what they teach.

Quickstart

See it running in two minutes — no GitHub org, no OAuth app, nothing to configure. You need Docker with Compose v2 and openssl:

git clone https://github.com/OWASP/owasp-ctf-in-a-box
cd owasp-ctf-in-a-box
./scripts/dev-stack up
下载工具