Skip to content

Feature/lab5#8

Open
Uiyrte wants to merge 4 commits intomainfrom
feature/lab5
Open

Feature/lab5#8
Uiyrte wants to merge 4 commits intomainfrom
feature/lab5

Conversation

@Uiyrte
Copy link
Owner

@Uiyrte Uiyrte commented Oct 10, 2025

Goal

Completion of Laboratory 5: Performing static (SAST) and dynamic (DAST) security analysis of the OWASP Juice Shop application. The goal is to identify vulnerabilities and provide recommendations for protection.

Changes

  • Added the labs/submission5.md file with the analysis results
  • Directories with the results of the tools are created:
    • semgrep/ - SAST scanning results
    • zap/ - OWASP ZAP reports
    • nuclei/ - template scanning results
    • nikto/ - server security reports
    • sqlmap/ - SQL injection testing
    • analysis/ - summary reports and correlation

Testing

  • SAST (Semgrep): source code analysis, identified injections, XSS, and workarounds
  • DAST:
    • ZAP — leaks of backups and configurations
    • Nuclei — lack of security headers
    • Nikto — outdated software and open files
    • SQLmap — confirmed SQL injection

Artifacts & Screenshots

  • labs/submission5.md — final report
  • labs/lab5/ — results of all tools

Checklist

  • Clear title
  • Docs updated if needed
  • No secrets/large temp files
  • Task 1 done — SAST Analysis with Semgrep
  • Task 2 done — DAST Analysis (ZAP + Nuclei + Nikto + SQLmap)
  • Task 3 done — SAST/DAST Correlation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant