Damn Vulnerable NodeJS Application (DVNA) is a simple NodeJS application to demonstrate OWASP Top 10 Vulnerabilities and guide on fixing and avoiding these vulnerabilities. The fixes branch will contain fixes for the vulnerabilities. Fixes for vunerabilities OWASP Top 10 2017 vulnerabilities at fixes-2017 branch.
The application is powered by commonly used libraries such as express, passport, sequelize, etc.
Developer Security Guide book
The application comes with a developer friendly comprehensive guidebook which can be used to learn, avoid and fix the vulnerabilities. The guide available at https://appsecco.com/books/dvna-developers-security-guide/ covers the following
- Instructions for setting up DVNA
- Instructions on exploiting the vulnerabilities
- Vulnerable code snippets and instructions on fixing vulnerabilities
- Recommendations for avoid such vulnerabilities
- References for learning more
Quick start
Try DVNA using a single command with Docker. This setup uses an SQLite database instead of MySQL.
docker run --name dvna -p 9090:9090 -d appsecco/dvna:sqlite
Getting Started
DVNA can be deployed in three ways
- For Developers, using docker-compose with auto-reload on code updates
- For Security Testers, using the Official image from Docker Hub
- For Advanced Users, using a fully manual setup
Development Setup
Clone this repository
git clone https://github.com/appsecco/dvna; cd dvna
vars.env
with the desired database configurationMYSQL_USER=dvna
MYSQL_DATABASE=dvna
MYSQL_PASSWORD=passw0rd
MYSQL_RANDOM_ROOT_PASSWORD=yes
Start the application and database using docker-composedocker-compose up
The application will automatically reload on code changes, so feel free to patch and play around with the application.
Using Official Docker Image
Create a file named
vars.env
with the following configurationMYSQL_USER=dvna
MYSQL_DATABASE=dvna
MYSQL_PASSWORD=passw0rd
MYSQL_RANDOM_ROOT_PASSWORD=yes
MYSQL_HOST=mysql-db
MYSQL_PORT=3306
Start a MySQL containerdocker run --name dvna-mysql --env-file vars.env -d mysql:5.7
docker run --name dvna-app --env-file vars.env --link dvna-mysql:mysql-db -p 9090:9090 appsecco/dvna
Manual Setup
Clone the repository
git clone https://github.com/appsecco/dvna; cd dvna
export MYSQL_USER=dvna
export MYSQL_DATABASE=dvna
export MYSQL_PASSWORD=passw0rd
export MYSQL_HOST=127.0.0.1
export MYSQL_PORT=3306
npm install
npm start
TODO
- Link commits to fixes in documentation
- Add new vulnerabilities from OWASP Top 10 2017
- Improve application features, documentation
Thanks
Abhisek Datta - abhisek for application architecture and front-end code