Skip to content

Latest commit

 

History

History
57 lines (44 loc) · 1.61 KB

File metadata and controls

57 lines (44 loc) · 1.61 KB

Laboratório DevSecOps

  • Laboratório DevSecOps em containers com:
    • Java Goof,
    • Sonar,
    • OWASP ZAP,
    • OWASP Juice Shop,
    • Hawkscan

Requisistos mínimos:

Uso

  • Dentro da pasta clonada executar:
    • docker-compose up

Extensões recomendadas

Java Goof

-This is a collection of Java demo apps that are vulnerable in different ways.

It's divided into modules, each one having its own README:

Sonar

  • http://localhost:9000
  • Usuário e senha inicial: admin
  • Para entrar no shell do container java-goof execute:
    docker-compose exec java-goof bash

OWASP Juice Shop

OWASP ZAP

Hawkscan

  • Passos para rodar:
    • descomentar o service hawkscan.
    • alterar o conteúdo do arquivo stackhawk.yml
    • alterar o valor do environment API_KEY no service hawkscan
  • Referência: