{"repo":"NeuraLegion/brokencrystals","free":true,"listed":false,"github":"https://github.com/NeuraLegion/brokencrystals","clone":"git clone https://github.com/NeuraLegion/brokencrystals.git","description":"A Broken Application - Very Vulnerable!","language":"TypeScript","stars":203,"topics":["security","cyber-security","secops","devops","typescript","react","nodejs","nestjs","vulnerable","benchmark"],"license":"MIT","category":"security-tools","readme_excerpt":"Description Broken Crystals is a benchmark application that uses modern technologies and implements a set of common security vulnerabilities. The application contains: - React based web client & API: http://localhost:3000 - Node.js server that serves the React client and provides both OpenAPI and GraphQL endpoints. The full API documentation is available via swagger or GraphQL: - Swagger UI - http://localhost:3000/swagger - Swagger JSON file - http://localhost:3000/swagger-json - GraphiQL UI - http://localhost:3000/graphiql Note The GraphQL API does not yet support all the endpoints the REST API does. Building and Running the Application Build and start local development environment with Postgres DB, MailCatcher and the app: To rebuild the app and restart the containers: Running tests by SecTester In the path ./test you can find tests to run with Jest. First, you have to get a Bright API key, navigate to your .env file, and paste your Bright API key as the value of the BRIGHT TOKEN variable: Then, you can modify a URL to your instance of the application by setting the SEC TESTER TARGET environment variable in your .env file: Finally, you can start tests with SecTester against these endpoints as follows: Full configuration & usage examples can be found in our demo project; Vulnerabilities Overview - Broken JWT Authentication - The application includes multiple endpoints that generate and validate several types of JWT tokens. The main login API, used by the UI, is utilizing one","default_branch":null,"files":null,"tree":[],"storefront":"/r/NeuraLegion","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/NeuraLegion/brokencrystals/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}