Skip to content
Ben de Haan edited this page Nov 30, 2021 · 8 revisions

What is WrongSecrets?

OWASP WrongSecrets is a deliberately insecure application focused on secret management.

In this app, we have packed various ways showing you how to not store your secrets. The challenge is to find all the different secrets in multiple environments by means of various tools and techniques.

Our aim is to provide you with some knowledge so that you can improve your own secret management. For a detailed challenge guide with some additional information, keep tabs on this wiki space!

Good luck!

The WrongSecrets Team

Solution guides

Every challenge guide contains:

  • More details on the (mis)configuration
  • Step-by-step instructions on finding the secret
  • A take away message to prevent making these mistakes in real life

Guides:

Additional Support

Need support? Contact us via OWASP Slack (sign up here), file a PR, file an issue, or use discussions. Please note that this is an OWASP volunteer-based project, so it might take a little while before we respond.

Helping the project

Clone this wiki locally