OWASP / wrongsecrets

Vulnerable app with examples showing how to not use secrets
https://owasp.org/www-project-wrongsecrets/
GNU Affero General Public License v3.0
1.24k stars 366 forks source link

Add hardcoded encryption key on top of a secret. #297

Open commjoen opened 2 years ago

commjoen commented 2 years ago

Have a challenge about "bad encryption practices" where we hardocde the key and the secret in java.

Steps to take:

kshitijk4poor commented 1 year ago

I would like to work on this one. could you please assign it to me?

commjoen commented 1 year ago

Welcome to the team sir! It is assigned to you now.

commjoen commented 1 year ago

Hi @kshitijk4poor , do you have any update on this?

kshitijk4poor commented 1 year ago

Hey @commjoen , yeah I'm on it

divyanshuagarwal-23 commented 1 year ago

Hello @kshitijk4poor, I am new here can I please work with you so that I can get familiar with the code base and hence can contribute in the future

CaduRoriz commented 1 year ago

/assign

nick2432 commented 11 months ago

Can I contribute to this issue? I'm new here, but I have experience contributing to many other organizations. Is there a Discord channel or any other channel where I can discuss and get assistance?

commjoen commented 11 months ago

Dear all, the issue is still assigned to kshitijk4poor. once it is completed or he unassigns or it gets unassigned automatically, we will assign it to someone else. For any potential contributor, please read our readme, code of conduct and contribution guidelines. See https://github.com/OWASP/wrongsecrets/blob/master/README.md#support for how to get in touch via Slack to chat about the project.

commjoen commented 9 months ago

Hi @kshitijk4poor how are you doing :) ? Do you have any update on the issue?

commjoen commented 6 months ago

The issue is opened for new assignees due to inactivity. Want to contribute? have a go at it :)

jangalasriramd7 commented 4 months ago

Hi @commjoen ,

I would like to work on this one. Could you please assign it to me?