Sign inSign up

ozcanpng/secureshift

By ozcanpng

•Updated about 1 year ago

Deliberately vulnerable Go web app for practicing common security exploits.

Image
Networking
Security
Web servers
0

945

ozcanpng/secureshift repository overview

⁠SecureShift

SecureShift is a security training and demonstration project written in Go with a simple SQLite backend and a static web frontend.
It is designed to showcase common web vulnerabilities in a controlled environment, allowing security researchers, students, and developers to practice exploitation and mitigation.

⁠Implemented Vulnerabilities

  • SQL Injection (SQLi)
  • Cross-Site Scripting (XSS)
  • Cross Site Request Forgery (CSRF)
  • DOM-based Vulnerabilities (DOM XSS)
  • OS Command Injection
  • Path Traversal
  • Insecure Deserialization
  • Information Disclosure
  • File Upload Vulnerabilities
  • JWT (JSON Web Token) Bypass
  • Insecure Direct Object Reference (IDOR)
  • Server-Side Request Forgery (SSRF)
  • Server-Side Template Injection (SSTI)
  • XML External Entity (XXE)

⁠Lightweight Stack

  • Backend: Go (Chi Router, SQLite3)
  • Frontend: Static HTML/CSS/JS
  • Database: SQLite (preloaded sample data)

⁠Default Credentials

Use the following credentials to log in:

  • Username: darlene
  • Password: darlene321

⁠Usage

Run the following commands step by step:

# 1) Pull the image (latest tag by default)
docker pull ozcanpng/secureshift

# 2) Run the container (detached, port 3000 exposed, named "secureshift")
docker run -d -p 3000:3000 --name secureshift ozcanpng/secureshift

# 3) Stop the container
docker stop secureshift

# 4) Start the container again
docker start secureshift

Tag summary

Content type

Image

Digest

sha256:e3926dd99…

Size

56.1 MB

Last updated

about 1 year ago

docker pull ozcanpng/secureshift