कोशिश गोल्ड - मुक्त

Juicy

Linux Magazine

|

#296/July 2025: Pen Testing

The OWASP Juice Shop has over 100 tasks that will get you up to speed on pen testing. This article guides you through your first steps.

- By Tim Schürmann

You can quickly test whether your web server is an open door for attackers by breaking into your own system. All you need to do is ... well, what actually? Isn't there this Metasploit tool that you can simply fire against the server? But before you point massive unknown weapons at your own server, you might want to take some time to familiarize yourself with the available tools and their purposes. And the best way to get started is to break into a test system.

The Open Worldwide Application Security Project (OWASP) makes its Juice Shop [1] available for starting pen testers. In addition to offering tasty fruit juices, the Juice Shop also deliberately contains a number of vulnerabilities, providing newcomers with an ideal target for hands-on pen testing practice. You can quickly set up the Juice Shop in a Docker container.

Open for Business

Because the Juice Shop has security vulnerabilities, you will not want to launch it on your own system. Instead, install your favorite distribution on a virtual machine (VM) or on an old laptop. Other services running in the background on your system will not interfere with the analysis. In principle, any distribution can serve as the underpinnings, but it should have the following tools in its repositories: Docker, Nmap, Dirb, and Base64. You can play it safe with Debian or go for the Kali Linux [2] pen testing distribution.

As soon as your distribution is running on the VM or on an old computer, use the package manager to integrate the tools I just mentioned. On Kali Linux, all you need to do is type

imageAll other tools are already in place. The two commands from Listing 1 will download the container with the Juice Shop and launch it.

Linux Magazine से और कहानियाँ

Linux Magazine

Exercise Place

The GRUB 2 boot manager might seem intimidating at first glance. All the more reason to spin up a virtual playground so you can practice.

time to read

10 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Terminal Mosaic

What's better than one command line? Many command lines that never die. Take the terminal to new places with Zellij.

time to read

9 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

MakerSpace

Build a Long-Range Sensor Network with ChirpStack Sensor Symphony

time to read

14 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

How Flatpak, AppImage, and Snap are changing software distribution Ship It!

Modern-day package systems solve some problems posed by classic formats like DEB and RPM. We look at Flatpak, AppImage, and Snap and describe how they differ.

time to read

12 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

Dashboard Delight

Simplify the chaos of self-hosted services with Homepage, a customizable dashboard with widgets that put service statistics at your fingertips.

time to read

9 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

MADDOG'S DOGHOUSE

Free software, and the FOSS community, can help technology students get the education they desire in Brazil and elsewhere.

time to read

3 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

Rethinking the Terminal

The Warp AI agent takes the guesswork out of working at the command line. We show you how to build a simple website with one prompt.

time to read

4 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Just in Time

Just is a command runner that lets you define project-specific tasks in a declarative justfile.

time to read

7 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

The Watcher

This versatile security app checks for vulnerabilities, watches logs, and acts as a single interface for other tools.

time to read

7 mins

#298/September 2025: Indie Game Studio

Linux Magazine

Linux Magazine

NO INTERNETREQUIRED

This new utility lets you update a system that is notconnected to the Internet.

time to read

4 mins

#298/September 2025: Indie Game Studio

Listen

Translate

Share

-
+

Change font size