Skip to content

feat: add challenge 77 for weakly stored sqlite passwords - #2737

Open
bhushan4work wants to merge 1 commit into
OWASP:masterfrom
bhushan4work:fix#2071
Open

bhushan4work wants to merge 1 commit into
OWASP:masterfrom
bhushan4work:fix#2071

Conversation

@bhushan4work

@bhushan4work bhushan4work commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

What kind of changes does this PR include?

  • Fixes or refactors
  • A new challenge
  • Additional documentation
  • Something else

Description

Adds challenge 77 to demonstrate insecure password storage in SQLite databases.

  • Includes a SQLite database with 2,000 synthetic user records containing unsalted MD5 hashes and AES-encrypted passwords.
  • Selects a target user dynamically at runtime and keeps the displayed username, expected answer, and validation consistent.
  • Adds a database download endpoint, challenge explanation, hint, and reason.
  • Includes focused tests covering challenge behavior, database access, and registration.

Relations

Closes #2071

References

Checklist

  • All the contributions made are solely the work of me and my co-authors
  • I used AI to generate parts of the content.
  • I tested the changes in this PR (if applicable)
  • I added unit tests to ensure my change works (when change in Java or on front-end code)
  • I added UI tests to ensure my UI changes work (not needed for this challenge-only change)
  • The PR passes pre-commit hooks and automated tests

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🧪 Testing this PR locally

If you already have the repository

First, make sure the official OWASP WrongSecrets repository is configured
as the wrongsecrets-upstream remote:

git remote get-url wrongsecrets-upstream >/dev/null 2>&1 || \
  git remote add wrongsecrets-upstream https://github.com/OWASP/wrongsecrets.git

Then fetch and check out this PR:

git fetch wrongsecrets-upstream pull/2737/head:pr-2737
git checkout pr-2737

If you already have a wrongsecrets-upstream remote, the first command
leaves it unchanged.

Or, if you want the contributor branch directly

If the contributor repository is already configured as origin:

git fetch origin
git checkout -b test-pr-2737 origin/fix#2071

🧹 Cleaning up after testing

When you are finished testing, you can remove the local PR branch:

git checkout main
git branch -D pr-2737

If you added the wrongsecrets-upstream remote specifically for testing
this PR and no longer need it, remove it with:

git remote remove wrongsecrets-upstream

⚠️ Only remove wrongsecrets-upstream if you added it for this test.
If you already had this remote before testing, keep it.

PR: #2737
Branch: fix#2071
Repository: bhushan4work/wrongsecrets

@commjoen

Copy link
Copy Markdown
Collaborator

Can you make this challenge77 instead please?

@bhushan4work bhushan4work changed the title feat: add challenge 76 for weakly stored sqlite passwords feat: add challenge 77 for weakly stored sqlite passwords Oct 11, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Challenge idea: sqlite file with username/password dumps

2 participants