{
  "2": "2",
  "3": "3",
  "Apple Juice (1000ml)": "Apple Juice (1000ml)",
  "The all-time classic.": "The all-time classic.",
  "Apple Pomace": "Apple Pomace",
  "Finest pressings of apples. Allergy disclaimer: Might contain traces of worms. Can be <a href=\"/#recycle\">sent back to us</a> for recycling.": "Finest pressings of apples. Allergy disclaimer: Might contain traces of worms. Can be <a href=\"/#recycle\">sent back to us</a> for recycling.",
  "Banana Juice (1000ml)": "Banana Juice (1000ml)",
  "Monkeys love it the most.": "Monkeys love it the most.",
  "Basil Smoothie": "Basil Smoothie",
  "A unique blend of fresh basil and ginger for a healthy kick.": "A unique blend of fresh basil and ginger for a healthy kick.",
  "Berry Juice (1000ml)": "Berry Juice (1000ml)",
  "A delicious blend of fresh forest berries.": "A delicious blend of fresh forest berries.",
  "Best Juice Shop Salesman Artwork": "Best Juice Shop Salesman Artwork",
  "Unique digital painting depicting Stan, our most qualified and almost profitable salesman. He made a succesful carreer in selling used ships, coffins, krypts, crosses, real estate, life insurance, restaurant supplies, voodoo enhanced asbestos and courtroom souvenirs before <em>finally</em> adding his expertise to the Juice Shop marketing team.": "Unique digital painting depicting Stan, our most qualified and almost profitable salesman. He made a succesful carreer in selling used ships, coffins, krypts, crosses, real estate, life insurance, restaurant supplies, voodoo enhanced asbestos and courtroom souvenirs before <em>finally</em> adding his expertise to the Juice Shop marketing team.",
  "Bragă (500ml)": "Bragă (500ml)",
  "Traditional Balkan drink made from fermented millet. Lightly sweet-sour, refreshing, and naturally energizing.": "Traditional Balkan drink made from fermented millet. Lightly sweet-sour, refreshing, and naturally energizing.",
  "Carrot Juice (1000ml)": "Carrot Juice (1000ml)",
  "As the old German saying goes: \"Carrots are good for the eyes. Or has anyone ever seen a rabbit with glasses?\"": "As the old German saying goes: \"Carrots are good for the eyes. Or has anyone ever seen a rabbit with glasses?\"",
  "Dragonfruit Juice (500ml)": "Dragonfruit Juice (500ml)",
  "Exotic and vibrant juice made from dragonfruit.": "Exotic and vibrant juice made from dragonfruit.",
  "Eggfruit Juice (500ml)": "Eggfruit Juice (500ml)",
  "Now with even more exotic flavour.": "Now with even more exotic flavour.",
  "Elderflower Cordial (500ml)": "Elderflower Cordial (500ml)",
  "Floral and fragrant soft drink made from elderflowers. Traditionally enjoyed chilled.": "Floral and fragrant soft drink made from elderflowers. Traditionally enjoyed chilled.",
  "Fruit Press": "Fruit Press",
  "Fruits go in. Juice comes out. Pomace you can send back to us for recycling purposes.": "Fruits go in. Juice comes out. Pomace you can send back to us for recycling purposes.",
  "Grape Juice (1000ml)": "Grape Juice (1000ml)",
  "Deep purple and full of antioxidants from selected grapes.": "Deep purple and full of antioxidants from selected grapes.",
  "Green Smoothie": "Green Smoothie",
  "Looks poisonous but is actually very good for your health! Made from green cabbage, spinach, kiwi and grass.": "Looks poisonous but is actually very good for your health! Made from green cabbage, spinach, kiwi and grass.",
  "Juice Shop \"Permafrost\" 2020 Edition": "Juice Shop \"Permafrost\" 2020 Edition",
  "Exact version of <a href=\"https://github.com/juice-shop/juice-shop/releases/tag/v9.3.1-PERMAFROST\">OWASP Juice Shop that was archived on 02/02/2020</a> by the GitHub Archive Program and ultimately went into the <a href=\"https://github.blog/2020-07-16-github-archive-program-the-journey-of-the-worlds-open-source-code-to-the-arctic\">Arctic Code Vault</a> on July 8. 2020 where it will be safely stored for at least 1000 years.": "Exact version of <a href=\"https://github.com/juice-shop/juice-shop/releases/tag/v9.3.1-PERMAFROST\">OWASP Juice Shop that was archived on 02/02/2020</a> by the GitHub Archive Program and ultimately went into the <a href=\"https://github.blog/2020-07-16-github-archive-program-the-journey-of-the-worlds-open-source-code-to-the-arctic\">Arctic Code Vault</a> on July 8. 2020 where it will be safely stored for at least 1000 years.",
  "Lemon Juice (500ml)": "Lemon Juice (500ml)",
  "Sour but full of vitamins.": "Sour but full of vitamins.",
  "Melon Bike (Comeback-Product 2018 Edition)": "Melon Bike (Comeback-Product 2018 Edition)",
  "The wheels of this bicycle are made from real water melons. You might not want to ride it up/down the curb too hard.": "The wheels of this bicycle are made from real water melons. You might not want to ride it up/down the curb too hard.",
  "Melon Juice (1000ml)": "Melon Juice (1000ml)",
  "Refreshing and sweet juice made from ripe melons.": "Refreshing and sweet juice made from ripe melons.",
  "OWASP Juice Shop \"King of the Hill\" Facemask": "OWASP Juice Shop \"King of the Hill\" Facemask",
  "Facemask with compartment for filter from 50% cotton and 50% polyester.": "Facemask with compartment for filter from 50% cotton and 50% polyester.",
  "OWASP Juice Shop CTF Girlie-Shirt": "OWASP Juice Shop CTF Girlie-Shirt",
  "For serious Capture-the-Flag heroines only!": "For serious Capture-the-Flag heroines only!",
  "OWASP Juice Shop Card (non-foil)": "OWASP Juice Shop Card (non-foil)",
  "Mythic rare <small><em>(obviously...)</em></small> card \"OWASP Juice Shop\" with three distinctly useful abilities. Alpha printing, mint condition. A true collectors piece to own!": "Mythic rare <small><em>(obviously...)</em></small> card \"OWASP Juice Shop\" with three distinctly useful abilities. Alpha printing, mint condition. A true collectors piece to own!",
  "OWASP Juice Shop Coaster (10pcs)": "OWASP Juice Shop Coaster (10pcs)",
  "Our 95mm circle coasters are printed in full color and made from thick, premium coaster board.": "Our 95mm circle coasters are printed in full color and made from thick, premium coaster board.",
  "OWASP Juice Shop Holographic Sticker": "OWASP Juice Shop Holographic Sticker",
  "Die-cut holographic sticker. Stand out from those 08/15-sticker-covered laptops with this shiny beacon of 80's coolness!": "Die-cut holographic sticker. Stand out from those 08/15-sticker-covered laptops with this shiny beacon of 80's coolness!",
  "OWASP Juice Shop Hoodie": "OWASP Juice Shop Hoodie",
  "Mr. Robot-style apparel. But in black. And with logo.": "Mr. Robot-style apparel. But in black. And with logo.",
  "OWASP Juice Shop Iron-Ons (16pcs)": "OWASP Juice Shop Iron-Ons (16pcs)",
  "Upgrade your clothes with washer safe <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">iron-ons</a> of the OWASP Juice Shop or CTF Extension logo!": "Upgrade your clothes with washer safe <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">iron-ons</a> of the OWASP Juice Shop or CTF Extension logo!",
  "OWASP Juice Shop LEGO™ Tower": "OWASP Juice Shop LEGO™ Tower",
  "Want to host a Juice Shop CTF in style? Build <a href=\"https://github.com/OWASP/owasp-swag/blob/master/projects/juice-shop/lego/OWASP%20JuiceShop%20Pi-server%201.2.pdf\" target=\"_blank\">your own LEGO™ tower</a> which holds four Raspberry Pi 4 models with PoE HAT modules <a href=\"https://github.com/juice-shop/multi-juicer/blob/main/guides/raspberry-pi/raspberry-pi.md\" target=\"_blank\">running a MultiJuicer Kubernetes cluster</a>! Wire to a switch and connect to your network to have an out-of-the-box ready CTF up in no time!": "Want to host a Juice Shop CTF in style? Build <a href=\"https://github.com/OWASP/owasp-swag/blob/master/projects/juice-shop/lego/OWASP%20JuiceShop%20Pi-server%201.2.pdf\" target=\"_blank\">your own LEGO™ tower</a> which holds four Raspberry Pi 4 models with PoE HAT modules <a href=\"https://github.com/juice-shop/multi-juicer/blob/main/guides/raspberry-pi/raspberry-pi.md\" target=\"_blank\">running a MultiJuicer Kubernetes cluster</a>! Wire to a switch and connect to your network to have an out-of-the-box ready CTF up in no time!",
  "OWASP Juice Shop Logo (3D-printed)": "OWASP Juice Shop Logo (3D-printed)",
  "This rare item was designed and handcrafted in Sweden. This is why it is so incredibly expensive despite its complete lack of purpose.": "This rare item was designed and handcrafted in Sweden. This is why it is so incredibly expensive despite its complete lack of purpose.",
  "OWASP Juice Shop Magnets (16pcs)": "OWASP Juice Shop Magnets (16pcs)",
  "Your fridge will be even cooler with these OWASP Juice Shop or CTF Extension logo <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">magnets</a>!": "Your fridge will be even cooler with these OWASP Juice Shop or CTF Extension logo <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">magnets</a>!",
  "OWASP Juice Shop Mug": "OWASP Juice Shop Mug",
  "Black mug with regular logo on one side and CTF logo on the other! Your colleagues will envy you!": "Black mug with regular logo on one side and CTF logo on the other! Your colleagues will envy you!",
  "OWASP Juice Shop Sticker Page": "OWASP Juice Shop Sticker Page",
  "Massive decoration opportunities with these OWASP Juice Shop or CTF Extension <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">sticker pages</a>! Each page has 16 stickers on it.": "Massive decoration opportunities with these OWASP Juice Shop or CTF Extension <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">sticker pages</a>! Each page has 16 stickers on it.",
  "OWASP Juice Shop Sticker Single": "OWASP Juice Shop Sticker Single",
  "Super high-quality vinyl <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">sticker single</a> with the OWASP Juice Shop or CTF Extension logo! The ultimate laptop decal!": "Super high-quality vinyl <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">sticker single</a> with the OWASP Juice Shop or CTF Extension logo! The ultimate laptop decal!",
  "OWASP Juice Shop T-Shirt": "OWASP Juice Shop T-Shirt",
  "Real fans wear it 24/7!": "Real fans wear it 24/7!",
  "OWASP Juice Shop Temporary Tattoos (16pcs)": "OWASP Juice Shop Temporary Tattoos (16pcs)",
  "Get one of these <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">temporary tattoos</a> to proudly wear the OWASP Juice Shop or CTF Extension logo on your skin! If you tweet a photo of yourself with the tattoo, you get a couple of our stickers for free! Please mention <a href=\"https://twitter.com/owasp_juiceshop\" target=\"_blank\"><code>@owasp_juiceshop</code></a> in your tweet!": "Get one of these <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">temporary tattoos</a> to proudly wear the OWASP Juice Shop or CTF Extension logo on your skin! If you tweet a photo of yourself with the tattoo, you get a couple of our stickers for free! Please mention <a href=\"https://twitter.com/owasp_juiceshop\" target=\"_blank\"><code>@owasp_juiceshop</code></a> in your tweet!",
  "OWASP Juice Shop-CTF Velcro Patch": "OWASP Juice Shop-CTF Velcro Patch",
  "4x3.5\" embroidered patch with velcro backside. The ultimate decal for every tactical bag or backpack!": "4x3.5\" embroidered patch with velcro backside. The ultimate decal for every tactical bag or backpack!",
  "OWASP SSL Advanced Forensic Tool (O-Saft)": "OWASP SSL Advanced Forensic Tool (O-Saft)",
  "O-Saft is an easy to use tool to show information about SSL certificate and tests the SSL connection according given list of ciphers and various SSL configurations. <a href=\"https://www.owasp.org/index.php/O-Saft\" target=\"_blank\">More...</a>": "O-Saft is an easy to use tool to show information about SSL certificate and tests the SSL connection according given list of ciphers and various SSL configurations. <a href=\"https://www.owasp.org/index.php/O-Saft\" target=\"_blank\">More...</a>",
  "OWASP Snakes and Ladders - Mobile Apps": "OWASP Snakes and Ladders - Mobile Apps",
  "This amazing mobile app security awareness board game is <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1970691216\">available for Tabletop Simulator on Steam Workshop</a> now!": "This amazing mobile app security awareness board game is <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1970691216\">available for Tabletop Simulator on Steam Workshop</a> now!",
  "OWASP Snakes and Ladders - Web Applications": "OWASP Snakes and Ladders - Web Applications",
  "This amazing web application security awareness board game is <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1969196030\">available for Tabletop Simulator on Steam Workshop</a> now!": "This amazing web application security awareness board game is <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1969196030\">available for Tabletop Simulator on Steam Workshop</a> now!",
  "Orange Juice (1000ml)": "Orange Juice (1000ml)",
  "Made from oranges hand-picked by Uncle Dittmeyer.": "Made from oranges hand-picked by Uncle Dittmeyer.",
  "Pineapple Juice (1000ml)": "Pineapple Juice (1000ml)",
  "Tropical refreshment from the finest sun-ripened pineapples.": "Tropical refreshment from the finest sun-ripened pineapples.",
  "Pomegranate Drink (500ml)": "Pomegranate Drink (500ml)",
  "A sweet and tart refreshment inspired by classic grenadine flavors.": "A sweet and tart refreshment inspired by classic grenadine flavors.",
  "Pwning OWASP Juice Shop": "Pwning OWASP Juice Shop",
  "<em>The official Companion Guide</em> by Björn Kimminich available <a href=\"https://leanpub.com/juice-shop\">for free on LeanPub</a> and also <a href=\"https://pwning.owasp-juice.shop\">readable online</a>!": "<em>The official Companion Guide</em> by Björn Kimminich available <a href=\"https://leanpub.com/juice-shop\">for free on LeanPub</a> and also <a href=\"https://pwning.owasp-juice.shop\">readable online</a>!",
  "Quince Juice (1000ml)": "Quince Juice (1000ml)",
  "Juice of the <em>Cydonia oblonga</em> fruit. Not exactly sweet but rich in Vitamin C.": "Juice of the <em>Cydonia oblonga</em> fruit. Not exactly sweet but rich in Vitamin C.",
  "Raspberry Juice (1000ml)": "Raspberry Juice (1000ml)",
  "Made from blended Raspberry Pi, water and sugar.": "Made from blended Raspberry Pi, water and sugar.",
  "Sea Buckthorn Juice (500ml)": "Sea Buckthorn Juice (500ml)",
  "Tangy and slightly sour juice, extremely rich in Vitamin C and antioxidants.": "Tangy and slightly sour juice, extremely rich in Vitamin C and antioxidants.",
  "Strawberry Juice (500ml)": "Strawberry Juice (500ml)",
  "Sweet & tasty!": "Sweet & tasty!",
  "Woodruff Syrup \"Forest Master X-Treme\"": "Woodruff Syrup \"Forest Master X-Treme\"",
  "Harvested and manufactured in the Black Forest, Germany. Can cause hyperactive behavior in children. Can cause permanent green tongue when consumed undiluted.": "Harvested and manufactured in the Black Forest, Germany. Can cause hyperactive behavior in children. Can cause permanent green tongue when consumed undiluted.",
  "Find the carefully hidden 'Score Board' page.": "Najděte pečlivě skrytou stránku \"Výsledková tabulka\".",
  "Order Confirmation": "Order Confirmation",
  "Customer": "Customer",
  "Order": "Order",
  "ea.": "ea.",
  "Delivery Price": "Delivery Price",
  "Total Price": "Total Price",
  "Date": "Date",
  "Bonus Points Earned": "Bonus Points Earned",
  "The bonus points from this order will be added 1:1 to your wallet ¤-fund for future purchases!": "The bonus points from this order will be added 1:1 to your wallet ¤-fund for future purchases!",
  "Thank you for your order!": "Thank you for your order!",
  "Obtain the password (hash) of the currently logged-in user directly from a REST API endpoint.": "Obtain the password (hash) of the currently logged-in user directly from a REST API endpoint.",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> without using the frontend application at all.": "Proveďte <i>přetrvávající</i> XSS útok s <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bez použití frontendové části webu.",
  "Gain access to any access log file of the server.": "Získejte přístup k jakémukoliv souboru protokolu přístupu na serveru (log).",
  "Register as a user with administrator privileges.": "Registrujte se jako uživatel s oprávněním správce.",
  "Access the administration section of the store.": "Získejte přístup do administrativní sekce eshopu.",
  "Overwrite the <a href=\"/ftp/legal.md\">Legal Information</a> file.": "Přepište soubor <a href=\"/ftp/legal.md\">Právní informace</a>.",
  "Reset the password of Bjoern's OWASP account via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "Obnovení hesla k Bjoernově účtu OWASP prostřednictvím mechanismu <a href=\"/#/forgot-password\">Zapomenuté heslo</a> s <i>původní odpovědí</i> na jeho bezpečnostní otázku.",
  "Learn about the Token Sale before its official announcement.": "Zjistěte informaci o prodeji Tokenu před oficiálním oznámením.",
  "Take over the wallet containing our official Soul Bound Token (NFT).": "Take over the wallet containing our official Soul Bound Token (NFT).",
  "Mint the Honey Pot NFT by gathering BEEs from the bee haven.": "Mint the Honey Pot NFT by gathering BEEs from the bee haven.",
  "Withdraw more ETH from the new wallet than you deposited.": "Withdraw more ETH from the new wallet than you deposited.",
  "Find an accidentally deployed code sandbox for writing smart contracts on the fly.": "Find an accidentally deployed code sandbox for writing smart contracts on the fly.",
  "Perform a Remote Code Execution that would keep a less hardened application busy <em>forever</em>.": "Perform a Remote Code Execution that would keep a less hardened application busy <em>forever</em>.",
  "Submit 10 or more customer feedbacks within 20 seconds.": "Submit 10 or more customer feedbacks within 20 seconds.",
  "Change Bender's password into <i>slurmCl4ssic</i> without using SQL Injection or Forgot Password.": "Změňte Bender heslo na <i>slurmCl4ssic</i> bez použití SQL Injekce nebo zapomenutého hesla.",
  "Order the Christmas special offer of 2014.": "Objednejte si Speciální Vánoční nabídku roku 2014.",
  "Bypass the Content Security Policy and perform an XSS attack with <code>&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> on a legacy page within the application.": "Bypass the Content Security Policy and perform an XSS attack with <code>&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> on a legacy page within the application.",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bypassing a <i>client-side</i> security mechanism.": "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bypassing a <i>client-side</i> security mechanism.",
  "Access a confidential document.": "Access a confidential document.",
  "Perform a <i>DOM</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>.": "Proveďte útok <i>DOM</i> XSS pomocí <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>.",
  "Exfiltrate the entire DB schema definition via SQL Injection.": "Exfiltrujte celou definici schématu DB pomocí SQL Injekce.",
  "Use a deprecated B2B interface that was not properly shut down.": "Použijte zastaralé rozhraní B2B, které nebylo řádně vypnuto.",
  "Find the hidden <a href=\"https://en.wikipedia.org/wiki/Easter_egg_(media)\" target=\"_blank\">easter egg</a>.": "Find the hidden <a href=\"https://en.wikipedia.org/wiki/Easter_egg_(media)\" target=\"_blank\">easter egg</a>.",
  "Perform an unwanted information disclosure by accessing data cross-domain.": "Perform an unwanted information disclosure by accessing data cross-domain.",
  "Register a user with an empty email and password.": "Register a user with an empty email and password.",
  "Log in with the (non-existing) accountant <i>acc0unt4nt@juice-sh.op</i> without ever registering that user.": "Log in with the (non-existing) accountant <i>acc0unt4nt@juice-sh.op</i> without ever registering that user.",
  "Provoke an error that is neither very gracefully nor consistently handled.": "Provoke an error that is neither very gracefully nor consistently handled.",
  "Successfully redeem an expired campaign coupon code.": "Successfully redeem an expired campaign coupon code.",
  "Retrieve the language file that never made it into production.": "Retrieve the language file that never made it into production.",
  "Get rid of all 5-star customer feedback.": "Zbavte se všech pětihvězdičkových zpětných vazeb zákazníků.",
  "Forge a coupon code that gives you a discount of at least 80%.": "Forge a coupon code that gives you a discount of at least 80%.",
  "Post some feedback in another user's name.": "Post some feedback in another user's name.",
  "Post a product review as another user or edit any user's existing review.": "Post a product review as another user or edit any user's existing review.",
  "Forge an almost properly RSA-signed JWT token that impersonates the (non-existing) user <i>rsa_lord@juice-sh.op</i>.": "Forge an almost properly RSA-signed JWT token that impersonates the (non-existing) user <i>rsa_lord@juice-sh.op</i>.",
  " <em>(This challenge is <strong>potentially harmful</strong> on Windows!)</em>": " <em>(This challenge is <strong>potentially harmful</strong> on Windows!)</em>",
  "Access a developer's forgotten backup file.": "Access a developer's forgotten backup file.",
  "Access a salesman's forgotten backup file.": "Access a salesman's forgotten backup file.",
  "<a href=\"/#/contact\">Inform the shop</a> about a <i>typosquatting</i> imposter that dug itself deep into the frontend. (Mention the exact name of the culprit)": "<a href=\"/#/contact\">Inform the shop</a> about a <i>typosquatting</i> imposter that dug itself deep into the frontend. (Mention the exact name of the culprit)",
  "Log in with Chris' erased user account.": "Log in with Chris' erased user account.",
  "Steal someone else's personal data without using Injection.": "Steal someone else's personal data without using Injection.",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> through an HTTP header.": "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> through an HTTP header.",
  "Solve challenge #999. Unfortunately, this challenge does not exist.": "Solve challenge #999. Unfortunately, this challenge does not exist.",
  "Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to. (Creating a new account with the same password does not qualify as a solution.)": "Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to. (Creating a new account with the same password does not qualify as a solution.)",
  "Identify an unsafe product that was removed from the shop and <a href=\"/#/contact\">inform the shop</a> which ingredients are dangerous.": "Identify an unsafe product that was removed from the shop and <a href=\"/#/contact\">inform the shop</a> which ingredients are dangerous.",
  "<a href=\"/#/contact\">Inform the shop</a> about a <i>typosquatting</i> trick it has been a victim of at least in <code>v6.2.0-SNAPSHOT</code>. (Mention the exact name of the culprit)": "<a href=\"/#/contact\">Inform the shop</a> about a <i>typosquatting</i> trick it has been a victim of at least in <code>v6.2.0-SNAPSHOT</code>. (Mention the exact name of the culprit)",
  "Log in with the administrator's user account.": "Log in with the administrator's user account.",
  "Log in with Amy's original user credentials. (This could take 93.83 billion trillion trillion centuries to brute force, but luckily she did not read the \"One Important Final Note\")": "Log in with Amy's original user credentials. (This could take 93.83 billion trillion trillion centuries to brute force, but luckily she did not read the \"One Important Final Note\")",
  "Log in with Bender's user account.": "Přihlaste se pomocí Benderova uživatelského účtu.",
  "Log in with Bjoern's Gmail account <i>without</i> previously changing his password, applying SQL Injection, or hacking his Google account.": "Log in with Bjoern's Gmail account <i>without</i> previously changing his password, applying SQL Injection, or hacking his Google account.",
  "Log in with Jim's user account.": "Přihlaste se pomocí Jimova uživatelského účtu.",
  "Log in with MC SafeSearch's original user credentials without applying SQL Injection or any other bypass.": "Log in with MC SafeSearch's original user credentials without applying SQL Injection or any other bypass.",
  "Log in with the support team's original user credentials without applying SQL Injection or any other bypass.": "Log in with the support team's original user credentials without applying SQL Injection or any other bypass.",
  "Put an additional product into another user's shopping basket.": "Put an additional product into another user's shopping basket.",
  "Access a misplaced <a href=\"https://github.com/Neo23x0/sigma\">SIEM signature</a> file.": "Access a misplaced <a href=\"https://github.com/Neo23x0/sigma\">SIEM signature</a> file.",
  "Like any review at least three times as the same user.": "Like any review at least three times as the same user.",
  "Apply some advanced cryptanalysis to find <i>the real</i> easter egg.": "Apply some advanced cryptanalysis to find <i>the real</i> easter egg.",
  "Let the server sleep for some time. (It has done more than enough hard work for you)": "Let the server sleep for some time. (It has done more than enough hard work for you)",
  "All your orders are belong to us! Even the ones which don't.": "All your orders are belong to us! Even the ones which don't.",
  "Update multiple product reviews at the same time.": "Update multiple product reviews at the same time.",
  "Let us redirect you to one of our crypto currency addresses which are not promoted any longer.": "Let us redirect you to one of our crypto currency addresses which are not promoted any longer.",
  "Log in with the administrator's user credentials without previously changing them or applying SQL Injection.": "Log in with the administrator's user credentials without previously changing them or applying SQL Injection.",
  "Place an order that makes you rich.": "Place an order that makes you rich.",
  "💎💎💎💎💎<!--IvLuRfBJYlmStf9XfL6ckJFngyd9LfV1JaaN/KRTPQPidTuJ7FR+D/nkWJUF+0xUF07CeCeqYfxq+OJVVa0gNbqgYkUNvn//UbE7e95C+6e+7GtdpqJ8mqm4WcPvUGIUxmGLTTAC2+G9UuFCD1DUjg==--> <a href=\"https://blockchain.info/address/1AbKfgvw9psQ41NbLi8kufDQTezwG8DRZm\" target=\"_blank\">₿ Unlock Premium Challenge</a> to access exclusive content.": "💎💎💎💎💎<!--IvLuRfBJYlmStf9XfL6ckJFngyd9LfV1JaaN/KRTPQPidTuJ7FR+D/nkWJUF+0xUF07CeCeqYfxq+OJVVa0gNbqgYkUNvn//UbE7e95C+6e+7GtdpqJ8mqm4WcPvUGIUxmGLTTAC2+G9UuFCD1DUjg==--> <a href=\"https://blockchain.info/address/1AbKfgvw9psQ41NbLi8kufDQTezwG8DRZm\" target=\"_blank\">₿ Unlock Premium Challenge</a> to access exclusive content.",
  "Read our privacy policy.": "Read our privacy policy.",
  "Prove that you actually read our privacy policy.": "Prove that you actually read our privacy policy.",
  "Change the <code>href</code> of the link within the <a href=\"/#/search?q=OWASP SSL Advanced Forensic Tool (O-Saft)\">OWASP SSL Advanced Forensic Tool (O-Saft)</a> product description into <i>https://owasp.slack.com</i>.": "Change the <code>href</code> of the link within the <a href=\"/#/search?q=OWASP SSL Advanced Forensic Tool (O-Saft)\">OWASP SSL Advanced Forensic Tool (O-Saft)</a> product description into <i>https://owasp.slack.com</i>.",
  "Perform a <i>reflected</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>.": "Perform a <i>reflected</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>.",
  "Follow the DRY principle while registering a user.": "Follow the DRY principle while registering a user.",
  "Reset Bender's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "Reset Bender's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.",
  "Reset the password of Bjoern's internal account via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "Reset the password of Bjoern's internal account via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.",
  "Reset Jim's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "Reset Jim's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.",
  "Reset Morty's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>his obfuscated answer</i> to his security question.": "Reset Morty's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>his obfuscated answer</i> to his security question.",
  "Deprive the shop of earnings by downloading the blueprint for one of its products.": "Deprive the shop of earnings by downloading the blueprint for one of its products.",
  "Request a hidden resource on server through server.": "Request a hidden resource on server through server.",
  "Infect the server with juicy malware by abusing arbitrary command execution.": "Infect the server with juicy malware by abusing arbitrary command execution.",
  "Behave like any \"white-hat\" should before getting into the action.": "Behave like any \"white-hat\" should before getting into the action.",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bypassing a <i>server-side</i> security mechanism.": "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bypassing a <i>server-side</i> security mechanism.",
  "<a href=\"/#/contact\">Rat out</a> a notorious character hiding in plain sight in the shop. (Mention the exact name of the character)": "<a href=\"/#/contact\">Rat out</a> a notorious character hiding in plain sight in the shop. (Mention the exact name of the character)",
  "Perform a Remote Code Execution that occupies the server for a while without using infinite loops.": "Perform a Remote Code Execution that occupies the server for a while without using infinite loops.",
  "<a href=\"/#/contact\">Inform the development team</a> about a danger to some of <em>their</em> credentials. (Send them the URL of the <em>original report</em> or an assigned CVE or another identifier of this vulnerability)": "<a href=\"/#/contact\">Inform the development team</a> about a danger to some of <em>their</em> credentials. (Send them the URL of the <em>original report</em> or an assigned CVE or another identifier of this vulnerability)",
  "Solve the 2FA challenge for user \"wurstbrot\". (Disabling, bypassing or overwriting his 2FA settings does not count as a solution)": "Solve the 2FA challenge for user \"wurstbrot\". (Disabling, bypassing or overwriting his 2FA settings does not count as a solution)",
  "Forge an essentially unsigned JWT token that impersonates the (non-existing) user <i>jwtn3d@juice-sh.op</i>.": "Forge an essentially unsigned JWT token that impersonates the (non-existing) user <i>jwtn3d@juice-sh.op</i>.",
  "Upload a file larger than 100 kB.": "Upload a file larger than 100 kB.",
  "Upload a file that has no .pdf or .zip extension.": "Upload a file that has no .pdf or .zip extension.",
  "Retrieve a list of all user credentials via SQL Injection.": "Retrieve a list of all user credentials via SQL Injection.",
  "Embed an XSS payload <code>&lt;/script&gt;&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> into our promo video.": "Embed an XSS payload <code>&lt;/script&gt;&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> into our promo video.",
  "View another user's shopping basket.": "View another user's shopping basket.",
  "<a href=\"/#/contact\">Inform the shop</a> about a vulnerable library it is using. (Mention the exact library name and version in your comment)": "<a href=\"/#/contact\">Inform the shop</a> about a vulnerable library it is using. (Mention the exact library name and version in your comment)",
  "<a href=\"/#/contact\">Inform the shop</a> about an algorithm or library it should definitely not use the way it does.": "<a href=\"/#/contact\">Inform the shop</a> about an algorithm or library it should definitely not use the way it does.",
  "Enforce a redirect to a page you are not supposed to redirect to.": "Enforce a redirect to a page you are not supposed to redirect to.",
  "Retrieve the content of <code>C:\\Windows\\system.ini</code> or <code>/etc/passwd</code> from the server.": "Retrieve the content of <code>C:\\Windows\\system.ini</code> or <code>/etc/passwd</code> from the server.",
  "Give the server something to chew on for quite a while.": "Give the server something to chew on for quite a while.",
  "Drop some explosive data into a vulnerable file-handling endpoint.": "Drop some explosive data into a vulnerable file-handling endpoint.",
  "Give a devastating zero-star feedback to the store.": "Give a devastating zero-star feedback to the store.",
  "Retrieve the photo of Bjoern's cat in \"melee combat-mode\".": "Retrieve the photo of Bjoern's cat in \"melee combat-mode\".",
  "Stick <a href=\"https://cataas.com/cat\" target=\"_blank\">cute cross-domain kittens</a> all over our delivery boxes.": "Stick <a href=\"https://cataas.com/cat\" target=\"_blank\">cute cross-domain kittens</a> all over our delivery boxes.",
  "Find the endpoint that serves usage data to be scraped by a <a href=\"https://github.com/prometheus/prometheus\">popular monitoring system</a>.": "Find the endpoint that serves usage data to be scraped by a <a href=\"https://github.com/prometheus/prometheus\">popular monitoring system</a>.",
  "Obtain a Deluxe Membership without paying for it.": "Obtain a Deluxe Membership without paying for it.",
  "Change the name of a user by performing Cross-Site Request Forgery from <a href=\"http://htmledit.squarefree.com\">another origin</a>.": "Change the name of a user by performing Cross-Site Request Forgery from <a href=\"http://htmledit.squarefree.com\">another origin</a>.",
  "Use the bonus payload <code>&lt;iframe width=&quot;100%&quot; height=&quot;166&quot; scrolling=&quot;no&quot; frameborder=&quot;no&quot; allow=&quot;autoplay&quot; src=&quot;https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/771984076&amp;color=%23ff5500&amp;auto_play=true&amp;hide_related=false&amp;show_comments=true&amp;show_user=true&amp;show_reposts=false&amp;show_teaser=true&quot;&gt;&lt;/iframe&gt;</code> in the <i>DOM XSS</i> challenge.": "Use the bonus payload <code>&lt;iframe width=&quot;100%&quot; height=&quot;166&quot; scrolling=&quot;no&quot; frameborder=&quot;no&quot; allow=&quot;autoplay&quot; src=&quot;https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/771984076&amp;color=%23ff5500&amp;auto_play=true&amp;hide_related=false&amp;show_comments=true&amp;show_user=true&amp;show_reposts=false&amp;show_teaser=true&quot;&gt;&lt;/iframe&gt;</code> in the <i>DOM XSS</i> challenge.",
  "Reset Uvogin's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "Reset Uvogin's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.",
  "Determine the answer to John's security question by looking at an upload of him to the Photo Wall and use it to reset his password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism.": "Determine the answer to John's security question by looking at an upload of him to the Photo Wall and use it to reset his password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism.",
  "Determine the answer to Emma's security question by looking at an upload of her to the Photo Wall and use it to reset her password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism.": "Determine the answer to Emma's security question by looking at an upload of her to the Photo Wall and use it to reset her password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism.",
  "Bypass a security control with a <a href=\"https://hakipedia.com/index.php/Poison_Null_Byte\">Poison Null Byte</a> to access a file not meant for your eyes.": "Bypass a security control with a <a href=\"https://hakipedia.com/index.php/Poison_Null_Byte\">Poison Null Byte</a> to access a file not meant for your eyes.",
  "Gain read access to an arbitrary local file on the web server.": "Gain read access to an arbitrary local file on the web server.",
  "Close multiple \"Challenge solved\"-notifications in one go.": "Close multiple \"Challenge solved\"-notifications in one go.",
  "The Juice Shop is susceptible to a known vulnerability in a library, for which an advisory has already been issued, marking the Juice Shop as <i>known affected</i>. A fix is still pending. <a href=\"/#/contact\">Inform the shop</a> about a suitable checksum as proof that you did your due diligence.": "The Juice Shop is susceptible to a known vulnerability in a library, for which an advisory has already been issued, marking the Juice Shop as <i>known affected</i>. A fix is still pending. <a href=\"/#/contact\">Inform the shop</a> about a suitable checksum as proof that you did your due diligence.",
  "A developer was careless with hardcoding unused, but still valid credentials for a testing account on the client-side.": "A developer was careless with hardcoding unused, but still valid credentials for a testing account on the client-side.",
  "<a href=\"/#/contact\">Inform the shop</a> about a leaked API key. (Mention the exact key in your comment)": "<a href=\"/#/contact\">Inform the shop</a> about a leaked API key. (Mention the exact key in your comment)",
  "Trick the chatbot into generating a coupon code for you despite its coupon policy saying otherwise.": "Trick the chatbot into generating a coupon code for you despite its coupon policy saying otherwise.",
  "Convince the chatbot to give you a coupon of 50% or more. Because apparently a 10% max policy is just a suggestion when you ask nicely enough.": "Convince the chatbot to give you a coupon of 50% or more. Because apparently a 10% max policy is just a suggestion when you ask nicely enough.",
  "Reveal some behind-the-scenes information on the chatbot as a non-admin user.": "Reveal some behind-the-scenes information on the chatbot as a non-admin user.",
  "We are out of stock! Sorry for the inconvenience.": "We are out of stock! Sorry for the inconvenience.",
  "You can order only up to {{quantity}} items of this product.": "You can order only up to {{quantity}} items of this product.",
  "Wrong answer to CAPTCHA. Please try again.": "Wrong answer to CAPTCHA. Please try again.",
  "Invalid email or password.": "Invalid email or password.",
  "Current password is not correct.": "Current password is not correct.",
  "Password cannot be empty.": "Password cannot be empty.",
  "New and repeated password do not match.": "New and repeated password do not match.",
  "Wrong answer to security question.": "Wrong answer to security question.",
  "Christmas Super-Surprise-Box (2014 Edition)": "Christmas Super-Surprise-Box (2014 Edition)",
  "Contains a random selection of 10 bottles (each 500ml) of our tastiest juices and an extra fan shirt for an unbeatable price! (Seasonal special offer! Limited availability!)": "Contains a random selection of 10 bottles (each 500ml) of our tastiest juices and an extra fan shirt for an unbeatable price! (Seasonal special offer! Limited availability!)",
  "Rippertuer Special Juice": "Rippertuer Special Juice",
  "Contains a magical collection of the rarest fruits gathered from all around the world, like Cherymoya Annona cherimola, Jabuticaba Myrciaria cauliflora, Bael Aegle marmelos... and others, at an unbelievable price! <br/><span style=\"color:red;\">This item has been made unavailable because of lack of safety standards.</span> (This product is unsafe! We plan to remove it from the stock!)": "Contains a magical collection of the rarest fruits gathered from all around the world, like Cherymoya Annona cherimola, Jabuticaba Myrciaria cauliflora, Bael Aegle marmelos... and others, at an unbelievable price! <br/><span style=\"color:red;\">This item has been made unavailable because of lack of safety standards.</span> (This product is unsafe! We plan to remove it from the stock!)",
  "OWASP Juice Shop Sticker (2015/2016 design)": "OWASP Juice Shop Sticker (2015/2016 design)",
  "Die-cut sticker with the official 2015/2016 logo. By now this is a rare collectors item. <em>Out of stock!</em>": "Die-cut sticker with the official 2015/2016 logo. By now this is a rare collectors item. <em>Out of stock!</em>",
  "Juice Shop Artwork": "Juice Shop Artwork",
  "Unique masterpiece painted with different kinds of juice on 90g/m² lined paper.": "Unique masterpiece painted with different kinds of juice on 90g/m² lined paper.",
  "Global OWASP WASPY Award 2017 Nomination": "Global OWASP WASPY Award 2017 Nomination",
  "Your chance to nominate up to three quiet pillars of the OWASP community ends 2017-06-30! <a href=\"https://www.owasp.org/index.php/WASPY_Awards_2017\">Nominate now!</a>": "Your chance to nominate up to three quiet pillars of the OWASP community ends 2017-06-30! <a href=\"https://www.owasp.org/index.php/WASPY_Awards_2017\">Nominate now!</a>",
  "OWASP Juice Shop Sweden Tour 2017 Sticker Sheet (Special Edition)": "OWASP Juice Shop Sweden Tour 2017 Sticker Sheet (Special Edition)",
  "10 sheets of Sweden-themed stickers with 15 stickers on each.": "10 sheets of Sweden-themed stickers with 15 stickers on each.",
  "Juice Shop Adversary Trading Card (Common)": "Juice Shop Adversary Trading Card (Common)",
  "Common rarity \"Juice Shop\" card for the <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> CCG.": "Common rarity \"Juice Shop\" card for the <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> CCG.",
  "Juice Shop Adversary Trading Card (Super Rare)": "Juice Shop Adversary Trading Card (Super Rare)",
  "Super rare \"Juice Shop\" card with holographic foil-coating for the <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> CCG.": "Super rare \"Juice Shop\" card with holographic foil-coating for the <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> CCG.",
  "20th Anniversary Celebration Ticket": "20th Anniversary Celebration Ticket",
  "Get your <a href=\"https://20thanniversary.owasp.org/\" target=\"_blank\">free 🎫 for OWASP 20th Anniversary Celebration</a> online conference! Hear from world renowned keynotes and special speakers, network with your peers and interact with our event sponsors. With an anticipated 10k+ attendees from around the world, you will not want to miss this live on-line event!": "Get your <a href=\"https://20thanniversary.owasp.org/\" target=\"_blank\">free 🎫 for OWASP 20th Anniversary Celebration</a> online conference! Hear from world renowned keynotes and special speakers, network with your peers and interact with our event sponsors. With an anticipated 10k+ attendees from around the world, you will not want to miss this live on-line event!",
  "DSOMM & Juice Shop User Day Ticket": "DSOMM & Juice Shop User Day Ticket",
  "You are going to the OWASP Global AppSec San Francisco 2024? <a href=\"https://www.eventbrite.com/e/owasp-global-appsec-san-francisco-2024-tickets-723699172707\" target=\"_blank\">Get a ticket<sup>*</sup></a> for this amazing side event as well! Check the juice-packed agenda <a href=\"https://owasp.org/www-project-juice-shop/#div-userday2024\" target=\"_blank\">here</a> for all the details!<br><br><small><small><sup>*</sup>=scroll down to <strong>Elevate: DSOMM and Juice Shop User Day (Sept. 25)</strong> after clicking <em>Get Tickets</em> on Eventbrite. Ticket price set to only covers fees for room, AV, and catering throughout the day.</small></small>": "You are going to the OWASP Global AppSec San Francisco 2024? <a href=\"https://www.eventbrite.com/e/owasp-global-appsec-san-francisco-2024-tickets-723699172707\" target=\"_blank\">Get a ticket<sup>*</sup></a> for this amazing side event as well! Check the juice-packed agenda <a href=\"https://owasp.org/www-project-juice-shop/#div-userday2024\" target=\"_blank\">here</a> for all the details!<br><br><small><small><sup>*</sup>=scroll down to <strong>Elevate: DSOMM and Juice Shop User Day (Sept. 25)</strong> after clicking <em>Get Tickets</em> on Eventbrite. Ticket price set to only covers fees for room, AV, and catering throughout the day.</small></small>",
  "Your eldest siblings middle name?": "Your eldest siblings middle name?",
  "Mother's maiden name?": "Mother's maiden name?",
  "Mother's birth date? (MM/DD/YY)": "Mother's birth date? (MM/DD/YY)",
  "Father's birth date? (MM/DD/YY)": "Father's birth date? (MM/DD/YY)",
  "Maternal grandmother's first name?": "Maternal grandmother's first name?",
  "Paternal grandmother's first name?": "Paternal grandmother's first name?",
  "Name of your favorite pet?": "Name of your favorite pet?",
  "Last name of dentist when you were a teenager? (Do not include 'Dr.')": "Last name of dentist when you were a teenager? (Do not include 'Dr.')",
  "Your ZIP/postal code when you were a teenager?": "Your ZIP/postal code when you were a teenager?",
  "Company you first work for as an adult?": "Company you first work for as an adult?",
  "Your favorite book?": "Your favorite book?",
  "Your favorite movie?": "Your favorite movie?",
  "Number of one of your customer or ID cards?": "Number of one of your customer or ID cards?",
  "What's your favorite place to go hiking?": "What's your favorite place to go hiking?",
  "Do you remember the security question that Jim used for his account?": "Do you remember the security question that Jim used for his account?",
  "While not necessarily as trivial to research via a user's LinkedIn profile, the question is still easy to research or brute force when answered truthfully.": "While not necessarily as trivial to research via a user's LinkedIn profile, the question is still easy to research or brute force when answered truthfully.",
  "When answered truthfully, all security questions are susceptible to online research (on Facebook, LinkedIn etc.) and often even brute force. If at all, they should not be used as the only factor for a security-relevant function.": "When answered truthfully, all security questions are susceptible to online research (on Facebook, LinkedIn etc.) and often even brute force. If at all, they should not be used as the only factor for a security-relevant function.",
  "You need to understand what happens \"behind the scenes\", so make sure to use your DevTools or a proxy to inspect network traffic.": "You need to understand what happens \"behind the scenes\", so make sure to use your DevTools or a proxy to inspect network traffic.",
  "Look for an API endpoint that already returns some user information.": "Look for an API endpoint that already returns some user information.",
  "An overly generic solution for data retrieval can backfire if not properly safeguarded.": "An overly generic solution for data retrieval can backfire if not properly safeguarded.",
  "You need to work with the server-side API directly. Try different HTTP verbs on different entities exposed through the API.": "Musíte pracovat s API přímo na serveru. Vyzkoušejte jiná HTTP slova, která jsou zobrazena pomocí API.",
  "A matrix of known data entities and their supported HTTP verbs through the API can help you here.": "A matrix of known data entities and their supported HTTP verbs through the API can help you here.",
  "Careless developers might have exposed API methods that the client does not even need.": "Careless developers might have exposed API methods that the client does not even need.",
  "Who would want a server access log to be accessible through a web application?": "Kdo by chtěl, aby protokol přístupu na server (log) byl přístupný prostřednictvím webové aplikace?",
  "Normally, server log files are written to disk on server side and are not accessible from the outside.": "Normally, server log files are written to disk on server side and are not accessible from the outside.",
  "One particular file found in the folder you might already have found during the \"Access a confidential document\" challenge might give you an idea who is interested in such a public exposure.": "One particular file found in the folder you might already have found during the \"Access a confidential document\" challenge might give you an idea who is interested in such a public exposure.",
  "Drilling down one level into the file system might not be sufficient.": "Drilling down one level into the file system might not be sufficient.",
  "You have to assign the unassignable.": "Musíte přiřadit nepřiřazené položky.",
  "Register as an ordinary user to learn what API endpoints are involved in this use case.": "Register as an ordinary user to learn what API endpoints are involved in this use case.",
  "Think of the simplest possible implementations of a distinction between regular users and administrators.": "Think of the simplest possible implementations of a distinction between regular users and administrators.",
  "It is just slightly harder to find than the score board link.": "Je o něco těžší najít než odkaz na stránku s výsledkovou tabulkou.",
  "Knowing it exists, you can simply guess what URL the admin section might have.": "Knowing it exists, you can simply guess what URL the admin section might have.",
  "Alternatively, you can try to find a reference or clue within the parts of the application that are not usually visible in the browser.": "Alternatively, you can try to find a reference or clue within the parts of the application that are not usually visible in the browser.",
  "It is probably just slightly harder to find and gain access to than the score board link.": "It is probably just slightly harder to find and gain access to than the score board link.",
  "There is some access control in place, but there are at least three ways to bypass it.": "There is some access control in place, but there are at least three ways to bypass it.",
  "Look out for a tweet praising new functionality of the web shop. Then find a third party vulnerability associated with it.": "Podívejte se na tweet chválící nové funkce eshopu. Pak najděte třetí stranu, která je s ním spojena.",
  "Find all places in the application where file uploads are possible.": "Find all places in the application where file uploads are possible.",
  "For at least one of these, the Juice Shop is depending on a library that suffers from an arbitrary file overwrite vulnerability.": "For at least one of these, the Juice Shop is depending on a library that suffers from an arbitrary file overwrite vulnerability.",
  "You can find a hint toward the underlying vulnerability in the @owasp_juiceshop Twitter timeline.": "You can find a hint toward the underlying vulnerability in the @owasp_juiceshop Twitter timeline.",
  "Hints to the answer to Bjoern’s question can be found by looking him up on the Internet.": "Hints to the answer to Bjoern’s question can be found by looking him up on the Internet.",
  "More precisely, Bjoern might have accidentally (?) doxxed himself by mentioning his security answer on at least one occasion where a camera was running.": "More precisely, Bjoern might have accidentally (?) doxxed himself by mentioning his security answer on at least one occasion where a camera was running.",
  "Brute forcing the answer might be very well possible with a sufficiently extensive list of common pet names.": "Brute forcing the answer might be very well possible with a sufficiently extensive list of common pet names.",
  "The developers truly believe in \"Security through Obscurity\" over actual access restrictions.": "Vývojáři skutečně věří v \"Bezpečnost prostřednictvím obejití\" nad konkrétními omezeními přístupu.",
  "Guessing or brute forcing the URL of the token sale page is very unlikely to succeed.": "Guessing or brute forcing the URL of the token sale page is very unlikely to succeed.",
  "You should closely investigate the place where all paths within the application are defined.": "You should closely investigate the place where all paths within the application are defined.",
  "Beating the employed obfuscation mechanism manually will take some time. Maybe there is an easier way to undo it?": "Beating the employed obfuscation mechanism manually will take some time. Maybe there is an easier way to undo it?",
  "Find the seed phrase posted accidentally.": "Find the seed phrase posted accidentally.",
  "Discover NFT wonders among the captivating visual memories.": "Discover NFT wonders among the captivating visual memories.",
  "Try to exploit the contract of the wallet.": "Try to exploit the contract of the wallet.",
  "It is just as easy as finding the Score Board.": "It is just as easy as finding the Score Board.",
  "The feature you need to exploit for this challenge is not directly advertised anywhere.": "Vlastnost, kterou potřebujete využít pro tuto výzvu, není zobrazena nikde přímo.",
  "As the Juice Shop is written in pure Javascript, there is one data format that is most probably used for serialization.": "As the Juice Shop is written in pure Javascript, there is one data format that is most probably used for serialization.",
  "You should try to make the server busy for all eternity.": "You should try to make the server busy for all eternity.",
  "The challenge will be solved if you manage to trigger the protection of the application against a very specific DoS attack vector.": "The challenge will be solved if you manage to trigger the protection of the application against a very specific DoS attack vector.",
  "Similar to the \"Let the server sleep for some time\" challenge (which accepted nothing but NoSQL Injection as a solution) this challenge will only accept proper RCE as a solution. It cannot be solved by simply hammering the server with requests. That would probably just kill your server instance.": "Similar to the \"Let the server sleep for some time\" challenge (which accepted nothing but NoSQL Injection as a solution) this challenge will only accept proper RCE as a solution. It cannot be solved by simply hammering the server with requests. That would probably just kill your server instance.",
  "After finding a CAPTCHA bypass, write a script that automates feedback submission. Or open many browser tabs and be really quick.": "After finding a CAPTCHA bypass, write a script that automates feedback submission. Or open many browser tabs and be really quick.",
  "You could prepare 10 browser tabs, solving every CAPTCHA and filling out the each feedback form. Then you’d need to very quickly switch through the tabs and submit the forms in under 20 seconds total.": "You could prepare 10 browser tabs, solving every CAPTCHA and filling out the each feedback form. Then you’d need to very quickly switch through the tabs and submit the forms in under 20 seconds total.",
  "Should the Juice Shop ever decide to change the challenge into \"Submit 100 or more customer feedbacks within 60 seconds\" or worse, you’d probably have a hard time keeping up with any tab-switching approach.": "Should the Juice Shop ever decide to change the challenge into \"Submit 100 or more customer feedbacks within 60 seconds\" or worse, you’d probably have a hard time keeping up with any tab-switching approach.",
  "Investigate closely how the CAPTCHA mechanism works and try to find either a bypass or some automated way of solving it dynamically.": "Investigate closely how the CAPTCHA mechanism works and try to find either a bypass or some automated way of solving it dynamically.",
  "Wrap this into a script (in whatever programming language you prefer) that repeats this 10 times.": "Wrap this into a script (in whatever programming language you prefer) that repeats this 10 times.",
  "In previous releases this challenge was wrongly accused of being based on CSRF.": "In previous releases this challenge was wrongly accused of being based on CSRF.",
  "It might also have been put into the Improper Input Validation category.": "It might also have been put into the Improper Input Validation category.",
  "Bender’s current password is so strong that brute force, rainbow table or guessing attacks will probably not work.": "Bender’s current password is so strong that brute force, rainbow table or guessing attacks will probably not work.",
  "Find out how the application handles unavailable products and try to find a loophole.": "Find out how the application handles unavailable products and try to find a loophole.",
  "Find out how the application hides deleted products from its customers.": "Find out how the application hides deleted products from its customers.",
  "Try to craft an attack string that makes deleted products visible again.": "Try to craft an attack string that makes deleted products visible again.",
  "You need to get the deleted product into your shopping cart and trigger the Checkout.": "You need to get the deleted product into your shopping cart and trigger the Checkout.",
  "Neither of the above can be achieved through the application frontend and it might even require (half-)Blind SQL Injection.": "Neither of the above can be achieved through the application frontend and it might even require (half-)Blind SQL Injection.",
  "What is even \"better\" than a legacy page with a homegrown RegEx sanitizer? Having CSP injection issues on the exact same page as well!": "What is even \"better\" than a legacy page with a homegrown RegEx sanitizer? Having CSP injection issues on the exact same page as well!",
  "Find a screen in the application that looks subtly odd and dated compared with all other screens.": "Find a screen in the application that looks subtly odd and dated compared with all other screens.",
  "Before trying any XSS attacks, you should understand how the page is setting its Content Security Policy.": "Before trying any XSS attacks, you should understand how the page is setting its Content Security Policy.",
  "For the subsequent XSS, make good use of the flaws in the homegrown sanitization based on a RegEx!": "For the subsequent XSS, make good use of the flaws in the homegrown sanitization based on a RegEx!",
  "There are only some input fields in the Juice Shop forms that validate their input.": "There are only some input fields in the Juice Shop forms that validate their input.",
  "Even less of these fields are persisted in a way where their content is shown on another screen.": "Even less of these fields are persisted in a way where their content is shown on another screen.",
  "Bypassing client-side security can typically be done by either disabling it on the client (i.e. in the browser by manipulating the DOM tree) or by ignoring it completely and interacting with the backend instead.": "Bypassing client-side security can typically be done by either disabling it on the client (i.e. in the browser by manipulating the DOM tree) or by ignoring it completely and interacting with the backend instead.",
  "Analyze and tamper with links in the application that deliver a file directly.": "Analyze and tamper with links in the application that deliver a file directly.",
  "The file you are looking for is not protected in any way. Once you found it you can also access it.": "The file you are looking for is not protected in any way. Once you found it you can also access it.",
  "Look for an input field where its content appears in the HTML when its form is submitted.": "Look for an input field where its content appears in the HTML when its form is submitted.",
  "This challenge is almost indistinguishable from \"Perform a reflected XSS attack\" if you do not look \"under the hood\" to find out what the application actually does with the user input.": "This challenge is almost indistinguishable from \"Perform a reflected XSS attack\" if you do not look \"under the hood\" to find out what the application actually does with the user input.",
  "Find out where this information could come from. Then craft an attack string against an endpoint that offers an unnecessary way to filter data.": "Find out where this information could come from. Then craft an attack string against an endpoint that offers an unnecessary way to filter data.",
  "Find out which database system is in use and where it would usually store its schema definitions.": "Find out which database system is in use and where it would usually store its schema definitions.",
  "Craft a UNION SELECT attack string to join the relevant data from any such identified system table into the original result.": "Craft a UNION SELECT attack string to join the relevant data from any such identified system table into the original result.",
  "You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next.": "You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next.",
  "As with \"Order the Christmas special offer of 2014\" this cannot be achieved through the application frontend.": "As with \"Order the Christmas special offer of 2014\" this cannot be achieved through the application frontend.",
  "The developers who disabled the interface think they could go invisible by just closing their eyes.": "The developers who disabled the interface think they could go invisible by just closing their eyes.",
  "The old B2B interface was replaced with a more modern version recently.": "The old B2B interface was replaced with a more modern version recently.",
  "When deprecating the old interface, not all of its parts were cleanly removed from the code base.": "When deprecating the old interface, not all of its parts were cleanly removed from the code base.",
  "Simply using the deprecated interface suffices to solve this challenge. No attack or exploit is necessary.": "Simply using the deprecated interface suffices to solve this challenge. No attack or exploit is necessary.",
  "If you solved one of the four file access challenges, you already know where to find the easter egg.": "If you solved one of the four file access challenges, you already know where to find the easter egg.",
  "Simply reuse the trick that already worked for the files above.": "Simply reuse the trick that already worked for the files above.",
  "Try to find and attack an endpoint that responds with user information. SQL Injection is not the solution here.": "Try to find and attack an endpoint that responds with user information. SQL Injection is not the solution here.",
  "What ways are there to access data from a web application cross-domain?": "What ways are there to access data from a web application cross-domain?",
  "This challenge uses an old way which is no longer recommended.": "This challenge uses an old way which is no longer recommended.",
  "Consider intercepting and playing with the request payload.": "Consider intercepting and playing with the request payload.",
  "Try to create the needed user \"out of thin air\".": "Try to create the needed user \"out of thin air\".",
  "The user literally needs to be ephemeral as in \"lasting for only a short time\".": "The user literally needs to be ephemeral as in \"lasting for only a short time\".",
  "Registering normally with the user’s email address will then obviously not solve this challenge. The Juice Shop will not even let you register as acc0unt4nt@juice-sh.op, as this would make the challenge unsolvable for you.": "Registering normally with the user’s email address will then obviously not solve this challenge. The Juice Shop will not even let you register as acc0unt4nt@juice-sh.op, as this would make the challenge unsolvable for you.",
  "Getting the user into the database some other way will also fail to solve this challenge. In case you somehow managed to do so, you need to restart the Juice Shop application in order to wipe the database and make the challenge solvable again.": "Getting the user into the database some other way will also fail to solve this challenge. In case you somehow managed to do so, you need to restart the Juice Shop application in order to wipe the database and make the challenge solvable again.",
  "The fact that this challenge is in the Injection category should already give away the intended approach.": "The fact that this challenge is in the Injection category should already give away the intended approach.",
  "Try to submit bad input to forms. Alternatively tamper with URL paths or parameters.": "Try to submit bad input to forms. Alternatively tamper with URL paths or parameters.",
  "This challenge actually triggers from various possible error conditions.": "This challenge actually triggers from various possible error conditions.",
  "You can try to submit bad input to forms to provoke an improper error handling.": "You can try to submit bad input to forms to provoke an improper error handling.",
  "Tampering with URL paths or parameters might also trigger an unforeseen error.": "Tampering with URL paths or parameters might also trigger an unforeseen error.",
  "Try to identify past special event or holiday campaigns of the shop first.": "Try to identify past special event or holiday campaigns of the shop first.",
  "Look for clues about the past campaign or holiday event somewhere in the application.": "Look for clues about the past campaign or holiday event somewhere in the application.",
  "Solving this challenge does not require actual time traveling.": "Solving this challenge does not require actual time traveling.",
  "First you should find out how the languages are technically changed in the user interface.": "First you should find out how the languages are technically changed in the user interface.",
  "Guessing will most definitely not work in this challenge.": "Guessing will most definitely not work in this challenge.",
  "Brute force is not the only option for this challenge, but a perfectly viable one.": "Brute force is not the only option for this challenge, but a perfectly viable one.",
  "Investigate online what languages are actually available.": "Investigate online what languages are actually available.",
  "Once you found admin section of the application, this challenge is almost trivial.": "Once you found admin section of the application, this challenge is almost trivial.",
  "Nothing happens when you try to delete feedback entries? Check the JavaScript console for errors!": "Nothing happens when you try to delete feedback entries? Check the JavaScript console for errors!",
  "Try either a) a knowledgeable brute force attack or b) reverse engineering or c) some research in the cloud.": "Try either a) a knowledgeable brute force attack or b) reverse engineering or c) some research in the cloud.",
  "One viable solution would be to reverse-engineer how coupon codes are generated and craft your own 80% coupon by using the same (or at least similar) implementation.": "One viable solution would be to reverse-engineer how coupon codes are generated and craft your own 80% coupon by using the same (or at least similar) implementation.",
  "Another possible solution might be harvesting as many previous coupon as possible and look for patterns that might give you a leverage for a brute force attack.": "Another possible solution might be harvesting as many previous coupon as possible and look for patterns that might give you a leverage for a brute force attack.",
  "If all else fails, you could still try to blindly brute force the coupon code field before checkout.": "If all else fails, you could still try to blindly brute force the coupon code field before checkout.",
  "You can solve this by tampering with the user interface or by intercepting the communication with the RESTful backend.": "You can solve this by tampering with the user interface or by intercepting the communication with the RESTful backend.",
  "To find the client-side leverage point, closely analyze the HTML form used for feedback submission.": "To find the client-side leverage point, closely analyze the HTML form used for feedback submission.",
  "The backend-side leverage point is similar to some of the XSS challenges found in OWASP Juice Shop.": "The backend-side leverage point is similar to some of the XSS challenges found in OWASP Juice Shop.",
  "Observe the flow of product review posting and editing and see if you can exploit it.": "Observe the flow of product review posting and editing and see if you can exploit it.",
  "This challenge can be solved by using developers tool of your browser or with tools like postman.": "This challenge can be solved by using developers tool of your browser or with tools like postman.",
  "Analyze the form used for review submission and try to find a leverage point.": "Analyze the form used for review submission and try to find a leverage point.",
  "This challenge is pretty similar to \"Post some feedback in another user’s name\" challenge.": "This challenge is pretty similar to \"Post some feedback in another user’s name\" challenge.",
  "This challenge is explicitly not about acquiring the RSA private key used for JWT signing.": "This challenge is explicitly not about acquiring the RSA private key used for JWT signing.",
  "The three generic hints from Forge an essentially unsigned JWT token also help with this challenge.": "The three generic hints from Forge an essentially unsigned JWT token also help with this challenge.",
  "Instead of enforcing no encryption to be applied, try to apply a more sophisticated exploit against the JWT libraries used in the Juice Shop.": "Instead of enforcing no encryption to be applied, try to apply a more sophisticated exploit against the JWT libraries used in the Juice Shop.",
  "Getting your hands on the public RSA key the application employs for its JWTs is mandatory for this challenge.": "Getting your hands on the public RSA key the application employs for its JWTs is mandatory for this challenge.",
  "Finding the corresponding private key should actually be impossible, but that obviously doesn’t make this challenge unsolvable.": "Finding the corresponding private key should actually be impossible, but that obviously doesn’t make this challenge unsolvable.",
  "Make sure your JWT is URL safe!": "Make sure your JWT is URL safe!",
  "You need to trick a security mechanism into thinking that the file you want has a valid file type.": "You need to trick a security mechanism into thinking that the file you want has a valid file type.",
  "The file is not directly accessible because a security mechanism prevents access to it.": "The file is not directly accessible because a security mechanism prevents access to it.",
  "You need to trick the security mechanism into thinking that the file has a valid file type.": "You need to trick the security mechanism into thinking that the file has a valid file type.",
  "For this challenge there is only one approach to pull this trick.": "For this challenge there is only one approach to pull this trick.",
  "This challenge has nothing to do with mistyping web domains. There is no conveniently misplaced file helping you with this one either. Or is there?": "This challenge has nothing to do with mistyping web domains. There is no conveniently misplaced file helping you with this one either. Or is there?",
  "This challenge has nothing to do with URLs or domains.": "This challenge has nothing to do with URLs or domains.",
  "Other than for its legacy companion, combing through the package.json.bak does not help for this challenge.": "Other than for its legacy companion, combing through the package.json.bak does not help for this challenge.",
  "Turns out that something is technically and legally wrong with the implementation of the \"right to be forgotten\" for users.": "Turns out that something is technically and legally wrong with the implementation of the \"right to be forgotten\" for users.",
  "Trying out the Request Data Erasure functionality might be interesting, but cannot help you solve this challenge in real time.": "Trying out the Request Data Erasure functionality might be interesting, but cannot help you solve this challenge in real time.",
  "If you have solved the challenge Retrieve a list of all user credentials via SQL Injection you might have already retrieved some information about how the Juice Shop \"deletes\" users upon their request.": "If you have solved the challenge Retrieve a list of all user credentials via SQL Injection you might have already retrieved some information about how the Juice Shop \"deletes\" users upon their request.",
  "What the Juice Shop does here is totally incompliant with GDPR. Luckily a 4% fine on a gross income of 0$ is still 0$.": "What the Juice Shop does here is totally incompliant with GDPR. Luckily a 4% fine on a gross income of 0$ is still 0$.",
  "Trick the regular Data Export to give you more than actually belongs to you.": "Trick the regular Data Export to give you more than actually belongs to you.",
  "You should not try to steal data from a \"vanilla\" user who never even ordered something at the shop.": "You should not try to steal data from a \"vanilla\" user who never even ordered something at the shop.",
  "As everything about this data export functionality happens on the server-side, it won’t be possible to just tamper with some HTTP requests to solve this challenge.": "As everything about this data export functionality happens on the server-side, it won’t be possible to just tamper with some HTTP requests to solve this challenge.",
  "Inspecting various server responses which contain user-specific data might give you a clue about the mistake the developers made.": "Inspecting various server responses which contain user-specific data might give you a clue about the mistake the developers made.",
  "Finding a piece of displayed information that could originate from an HTTP header is part of this challenge.": "Finding a piece of displayed information that could originate from an HTTP header is part of this challenge.",
  "You might have to look into less common or even proprietary HTTP headers to find the leverage point.": "You might have to look into less common or even proprietary HTTP headers to find the leverage point.",
  "Adding insult to injury, the HTTP header you need will never be sent by the application on its own.": "Adding insult to injury, the HTTP header you need will never be sent by the application on its own.",
  "You need to trick the hacking progress persistence feature into thinking you solved challenge #999.": "You need to trick the hacking progress persistence feature into thinking you solved challenge #999.",
  "Find out how saving and restoring progress is done behind the scenes.": "Find out how saving and restoring progress is done behind the scenes.",
  "Deduce from all available information (e.g. the package.json.bak) how the application encrypts and decrypts your hacking progress.": "Deduce from all available information (e.g. the package.json.bak) how the application encrypts and decrypts your hacking progress.",
  "Other than the user’s passwords, the hacking progress involves an additional secret during its encryption.": "Other than the user’s passwords, the hacking progress involves an additional secret during its encryption.",
  "What would be a really stupid mistake a developer might make when choosing such a secret?": "What would be a really stupid mistake a developer might make when choosing such a secret?",
  "As the challenge name implies, your task is to find some leaked access logs which happen to have a fairly common format.": "As the challenge name implies, your task is to find some leaked access logs which happen to have a fairly common format.",
  "A very popular help platform for developers might contain breadcrumbs towards solving this challenge.": "A very popular help platform for developers might contain breadcrumbs towards solving this challenge.",
  "The actual log file was copied & paste onto a platform often used to share data quickly with externals or even just internal peers.": "The actual log file was copied & paste onto a platform often used to share data quickly with externals or even just internal peers.",
  "Once you found and harvested the important piece of information from the log, you could employ a technique called Password Spraying to solve this challenge.": "Once you found and harvested the important piece of information from the log, you could employ a technique called Password Spraying to solve this challenge.",
  "Your own SQLi and someone else's Ctrl-V will be your accomplices in this challenge!": "Your own SQLi and someone else's Ctrl-V will be your accomplices in this challenge!",
  "You must first identify the \"unsafe product\" which ist not available any more in the shop.": "You must first identify the \"unsafe product\" which ist not available any more in the shop.",
  "Solving the \"Order the Christmas special offer of 2014\" challenge might give it to you as by-catch.": "Solving the \"Order the Christmas special offer of 2014\" challenge might give it to you as by-catch.",
  "The actual data you need to solve this challenge was leaked on the same platform that was involved in the \"Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to\" challenge.": "The actual data you need to solve this challenge was leaked on the same platform that was involved in the \"Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to\" challenge.",
  "Google is a particularly good accomplice in this challenge.": "Google is a particularly good accomplice in this challenge.",
  "This challenge has nothing to do with mistyping web domains. Investigate the forgotten developer's backup file instead.": "This challenge has nothing to do with mistyping web domains. Investigate the forgotten developer's backup file instead.",
  "Investigating the forgotten developer’s backup file might bring some insight.": "Investigating the forgotten developer’s backup file might bring some insight.",
  "\"Malicious packages in npm\" is a worthwhile read on Ivan Akulov’s blog.": "\"Malicious packages in npm\" is a worthwhile read on Ivan Akulov’s blog.",
  "The challenge description probably gave away what form you should attack.": "The challenge description probably gave away what form you should attack.",
  "If you happen to know the email address of the admin already, you can launch a targeted attack.": "If you happen to know the email address of the admin already, you can launch a targeted attack.",
  "You might be lucky with a dedicated attack pattern even if you have no clue about the admin email address.": "You might be lucky with a dedicated attack pattern even if you have no clue about the admin email address.",
  "If you harvested the admin’s password hash, you can of course try to attack that instead of using SQL Injection.": "If you harvested the admin’s password hash, you can of course try to attack that instead of using SQL Injection.",
  "Alternatively you can solve this challenge as a combo with the Log in with the administrator’s user credentials without previously changing them or applying SQL Injection challenge.": "Alternatively you can solve this challenge as a combo with the Log in with the administrator’s user credentials without previously changing them or applying SQL Injection challenge.",
  "This challenge will make you go after a needle in a haystack.": "This challenge will make you go after a needle in a haystack.",
  "As with so many other characters from Futurama this challenge is of course about logging in as Amy from that show.": "As with so many other characters from Futurama this challenge is of course about logging in as Amy from that show.",
  "Did you know that Amy is married to an alien named Kif?": "Did you know that Amy is married to an alien named Kif?",
  "The challenge description contains a few sentences which give away some information how Amy decided to strengthen her password.": "The challenge description contains a few sentences which give away some information how Amy decided to strengthen her password.",
  "Obviously, Amy - being a little dimwitted - did not put nearly enough effort and creativity into the password selection process.": "Obviously, Amy - being a little dimwitted - did not put nearly enough effort and creativity into the password selection process.",
  "You need to know (or smart-guess) Bender’s email address so you can launch a targeted attack.": "You need to know (or smart-guess) Bender’s email address so you can launch a targeted attack.",
  "Bender's password hash might not help you very much.": "Bender's password hash might not help you very much.",
  "In case you try some other approach than SQL Injection, you will notice that Bender’s password hash is not very useful.": "In case you try some other approach than SQL Injection, you will notice that Bender’s password hash is not very useful.",
  "The security flaw behind this challenge is 100% OWASP Juice Shop's fault and 0% Google's.": "The security flaw behind this challenge is 100% OWASP Juice Shop's fault and 0% Google's.",
  "One way to light up this challenge in green on the score board, is to be Bjoern Kimminich. In that case, just log in with your Google account to automatically solve this challenge! Congratulations!": "One way to light up this challenge in green on the score board, is to be Bjoern Kimminich. In that case, just log in with your Google account to automatically solve this challenge! Congratulations!",
  "Most likely you are not Bjoern Kimminich, so instead you might want to take detailed look into how the OAuth login with Google is implemented.": "Most likely you are not Bjoern Kimminich, so instead you might want to take detailed look into how the OAuth login with Google is implemented.",
  "It could bring you some insight to register with your own Google account and analyze closely what happens behind the scenes.": "It could bring you some insight to register with your own Google account and analyze closely what happens behind the scenes.",
  "You need to know (or smart-guess) Jim’s email address so you can launch a targeted attack.": "You need to know (or smart-guess) Jim’s email address so you can launch a targeted attack.",
  "If you harvested Jim’s password hash, you can try to attack that instead of using SQL Injection.": "If you harvested Jim’s password hash, you can try to attack that instead of using SQL Injection.",
  "MC SafeSearch is a rapper who produced the song \"Protect Ya' Passwordz\" which explains password & sensitive data protection very nicely.": "MC SafeSearch is a rapper who produced the song \"Protect Ya' Passwordz\" which explains password & sensitive data protection very nicely.",
  "After watching the music video of this song, you should agree that even ⭐⭐ is a slightly exaggerated difficulty rating for this challenge.": "After watching the music video of this song, you should agree that even ⭐⭐ is a slightly exaggerated difficulty rating for this challenge.",
  "The underlying flaw of this challenge is a lot more human error than technical weakness.": "The underlying flaw of this challenge is a lot more human error than technical weakness.",
  "The support team is located in a low-cost country and the team structure fluctuates a lot due to people leaving for jobs with even just slightly better wages.": "The support team is located in a low-cost country and the team structure fluctuates a lot due to people leaving for jobs with even just slightly better wages.",
  "To prevent abuse the password for the support team account itself is actually very strong.": "To prevent abuse the password for the support team account itself is actually very strong.",
  "To allow easy access during an incident, the support team utilizes a 3rd party tool which every support engineer can access to get the current account password from.": "To allow easy access during an incident, the support team utilizes a 3rd party tool which every support engineer can access to get the current account password from.",
  "While it is also possible to use SQL Injection to log in as the support team, this will not solve the challenge.": "While it is also possible to use SQL Injection to log in as the support team, this will not solve the challenge.",
  "Have an eye on the HTTP traffic while placing products in the shopping basket.": "Have an eye on the HTTP traffic while placing products in the shopping basket.",
  "Adding more instances of the same product to someone else’s basket does not qualify as a solution. The same goes for stealing from someone else’s basket.": "Adding more instances of the same product to someone else’s basket does not qualify as a solution. The same goes for stealing from someone else’s basket.",
  "This challenge requires a bit more sophisticated tampering than others of the same ilk.": "This challenge requires a bit more sophisticated tampering than others of the same ilk.",
  "If you solved one of the other four file access challenges, you already know where the SIEM signature file is located.": "If you solved one of the other four file access challenges, you already know where the SIEM signature file is located.",
  "Punctuality is the politeness of kings.": "Přesnost je výsada králů.",
  "Every user is (almost) immediately associated with the review they \"liked\" to prevent abuse of that functionality.": "Every user is (almost) immediately associated with the review they \"liked\" to prevent abuse of that functionality.",
  "Did you really think clicking the \"like\" button three times in a row really fast would be enough to solve a ⭐⭐⭐⭐⭐⭐ challenge?": "Did you really think clicking the \"like\" button three times in a row really fast would be enough to solve a ⭐⭐⭐⭐⭐⭐ challenge?",
  "The underlying flaw of this challenge is a Race Condition.": "The underlying flaw of this challenge is a Race Condition.",
  "You might have to peel through several layers of tough-as-nails encryption for this challenge.": "You might have to peel through several layers of tough-as-nails encryption for this challenge.",
  "Make sure you solve Find the hidden easter egg first.": "Make sure you solve Find the hidden easter egg first.",
  "This challenge is essentially a stripped-down Denial of Service (DoS) attack.": "This challenge is essentially a stripped-down Denial of Service (DoS) attack.",
  "As stated in the Architecture overview, OWASP Juice Shop uses a MongoDB derivate as its NoSQL database.": "As stated in the Architecture overview, OWASP Juice Shop uses a MongoDB derivate as its NoSQL database.",
  "The categorization into the NoSQL Injection category totally gives away the expected attack vector for this challenge. Trying any others will not solve the challenge, even if they might yield the same result.": "The categorization into the NoSQL Injection category totally gives away the expected attack vector for this challenge. Trying any others will not solve the challenge, even if they might yield the same result.",
  "In particular, flooding the application with requests will not solve this challenge. That would probably just kill your server instance.": "In particular, flooding the application with requests will not solve this challenge. That would probably just kill your server instance.",
  "Take a close look on how the $where query operator works in MongoDB.": "Take a close look on how the $where query operator works in MongoDB.",
  "This challenge requires a classic Injection attack.": "This challenge requires a classic Injection attack.",
  "Find an API endpoint with the intent of delivering a single order to the user and work with that.": "Find an API endpoint with the intent of delivering a single order to the user and work with that.",
  "Reading up on how MongoDB queries work is really helpful here.": "Reading up on how MongoDB queries work is really helpful here.",
  "Take a close look on how the equivalent of UPDATE-statements in MongoDB work.": "Take a close look on how the equivalent of UPDATE-statements in MongoDB work.",
  "This challenge requires another classic Injection attack.": "This challenge requires another classic Injection attack.",
  "It is also worth looking into how Query Operators work in MongoDB.": "It is also worth looking into how Query Operators work in MongoDB.",
  "When removing references to those addresses from the code the developers have been a bit sloppy.": "When removing references to those addresses from the code the developers have been a bit sloppy.",
  "More particular, they have been sloppy in a way that even the Angular Compiler was not able to clean up after them automatically.": "More particular, they have been sloppy in a way that even the Angular Compiler was not able to clean up after them automatically.",
  "It is of course not sufficient to just visit any of the crypto currency links directly to solve the challenge.": "It is of course not sufficient to just visit any of the crypto currency links directly to solve the challenge.",
  "This challenge can be solved with three different approaches.": "This challenge can be solved with three different approaches.",
  "Guessing might work just fine.": "Guessing might work just fine.",
  "If you harvested the admin’s password hash, you can try to attack that.": "If you harvested the admin’s password hash, you can try to attack that.",
  "In case you use some hacker tool, you can also go for a brute force attack using a generic password list.": "In case you use some hacker tool, you can also go for a brute force attack using a generic password list.",
  "You literally need to make the shop owe you any amount of money.": "You literally need to make the shop owe you any amount of money.",
  "Investigate the shopping basket closely to understand how it prevents you from creating orders that would fulfil the challenge.": "Investigate the shopping basket closely to understand how it prevents you from creating orders that would fulfil the challenge.",
  "You do not have to pay anything to unlock this challenge! Nonetheless, donations are very much appreciated.": "You do not have to pay anything to unlock this challenge! Nonetheless, donations are very much appreciated.",
  "There is no inappropriate, self-written or misconfigured cryptographic library to be exploited here.": "There is no inappropriate, self-written or misconfigured cryptographic library to be exploited here.",
  "How much protection does a sturdy top-quality door lock add to your house if you put the key under the door mat? Or hide the key in the nearby plant pot? Or tape the key to the underside of the mailbox?": "How much protection does a sturdy top-quality door lock add to your house if you put the key under the door mat? Or hide the key in the nearby plant pot? Or tape the key to the underside of the mailbox?",
  "Once more: You do not have to pay anything to unlock this challenge!": "Once more: You do not have to pay anything to unlock this challenge!",
  "We won't even ask you to confirm that you did. Just read it. Please. Pretty please.": "We won't even ask you to confirm that you did. Just read it. Please. Pretty please.",
  "When you work with the application you will most likely solve this challenge in the process.": "When you work with the application you will most likely solve this challenge in the process.",
  "Any automated crawling or spidering tool you use might solve this challenge for you.": "Any automated crawling or spidering tool you use might solve this challenge for you.",
  "There is no real hacking involved here.": "There is no real hacking involved here.",
  "Only by visiting a special URL you can confirm that you read it carefully.": "Only by visiting a special URL you can confirm that you read it carefully.",
  "First you should obviously solve the \"Read our privacy policy\" challenge.": "First you should obviously solve the \"Read our privacy policy\" challenge.",
  "It is fine to use the mouse cursor to not lose sight of the paragraph you are currently reading.": "It is fine to use the mouse cursor to not lose sight of the paragraph you are currently reading.",
  "If you find some particularly hot sections in the policy you might want to melt them together similar to what you might have already uncovered in Apply some advanced cryptanalysis to find the real easter egg.": "If you find some particularly hot sections in the policy you might want to melt them together similar to what you might have already uncovered in Apply some advanced cryptanalysis to find the real easter egg.",
  "Theoretically there are three possible ways to beat this challenge: a) broken admin functionality, b) holes in RESTful API or c) possibility for SQL Injection.": "Theoretically there are three possible ways to beat this challenge: a) broken admin functionality, b) holes in RESTful API or c) possibility for SQL Injection.",
  "In practice two of these three ways should turn out to be dead ends.": "In practice two of these three ways should turn out to be dead ends.",
  "Look for a url parameter where its value appears in the page it is leading to.": "Look for a url parameter where its value appears in the page it is leading to.",
  "Try probing for XSS vulnerabilities by submitting text wrapped in an HTML tag which is easy to spot on screen, e.g. <h1> or <strike>.": "Try probing for XSS vulnerabilities by submitting text wrapped in an HTML tag which is easy to spot on screen, e.g. <h1> or <strike>.",
  "You can solve this by cleverly interacting with the UI or bypassing it altogether.": "You can solve this by cleverly interacting with the UI or bypassing it altogether.",
  "The obvious repetition in the User Registration form is the Repeat Password field.": "The obvious repetition in the User Registration form is the Repeat Password field.",
  "Try to register with either an empty or different value in Repeat Password.": "Try to register with either an empty or different value in Repeat Password.",
  "You can solve this challenge by cleverly interacting with the UI or bypassing it altogether.": "You can solve this challenge by cleverly interacting with the UI or bypassing it altogether.",
  "If you have no idea who Bender is, please put down this book right now and watch the first episodes of Futurama before you come back.": "If you have no idea who Bender is, please put down this book right now and watch the first episodes of Futurama before you come back.",
  "Unexpectedly, Bender also chose to answer his chosen question truthfully.": "Unexpectedly, Bender also chose to answer his chosen question truthfully.",
  "Hints to the answer to Bender’s question can be found in publicly available information on the Internet.": "Hints to the answer to Bender’s question can be found in publicly available information on the Internet.",
  "If a seemingly correct answer is not accepted, you might just need to try some alternative spelling.": "If a seemingly correct answer is not accepted, you might just need to try some alternative spelling.",
  "Brute forcing the answer should be next to impossible.": "Brute forcing the answer should be next to impossible.",
  "Nothing a little bit of Facebook stalking couldn't reveal. Might involve a historical twist.": "Nothing a little bit of Facebook stalking couldn't reveal. Might involve a historical twist.",
  "Other than with his OWASP account, Bjoern was a bit less careless with his choice of security and answer to his internal account.": "Other than with his OWASP account, Bjoern was a bit less careless with his choice of security and answer to his internal account.",
  "Bjoern chose to answer his chosen question truthfully but tried to make it harder for attackers by applying sort of a historical twist.": "Bjoern chose to answer his chosen question truthfully but tried to make it harder for attackers by applying sort of a historical twist.",
  "Again, hints to the answer to Bjoern’s question can be found by looking him up on the Internet.": "Again, hints to the answer to Bjoern’s question can be found by looking him up on the Internet.",
  "The hardest part of this challenge is actually to find out who Jim actually is.": "The hardest part of this challenge is actually to find out who Jim actually is.",
  "Jim picked one of the worst security questions and chose to answer it truthfully.": "Jim picked one of the worst security questions and chose to answer it truthfully.",
  "As Jim is a celebrity, the answer to his question is quite easy to find in publicly available information on the internet.": "As Jim is a celebrity, the answer to his question is quite easy to find in publicly available information on the internet.",
  "Even brute forcing the answer should be possible with the right kind of word list.": "Even brute forcing the answer should be possible with the right kind of word list.",
  "Finding out who Morty actually is, will help to reduce the solution space.": "Finding out who Morty actually is, will help to reduce the solution space.",
  "You can assume that Morty answered his security question truthfully but employed some obfuscation to make it more secure.": "You can assume that Morty answered his security question truthfully but employed some obfuscation to make it more secure.",
  "Morty’s answer is less than 10 characters long and does not include any special characters.": "Morty’s answer is less than 10 characters long and does not include any special characters.",
  "Unfortunately, Forgot your password? is protected by a rate limiting mechanism that prevents brute forcing. You need to beat this somehow.": "Unfortunately, Forgot your password? is protected by a rate limiting mechanism that prevents brute forcing. You need to beat this somehow.",
  "Check for products which seem like a natural fit for being based on a blueprint.": "Check for products which seem like a natural fit for being based on a blueprint.",
  "You might want to pay attention to the images of the identified product candidates.": "You might want to pay attention to the images of the identified product candidates.",
  "For your inconvenience the blueprint was not misplaced into the same place like so many others forgotten files covered in this chapter.": "For your inconvenience the blueprint was not misplaced into the same place like so many others forgotten files covered in this chapter.",
  "Reverse engineering something bad can make good things happen.": "Reverse engineering something bad can make good things happen.",
  "Using whatever you find inside the malware directly will not do you any good.": "Using whatever you find inside the malware directly will not do you any good.",
  "For this to count as an SSRF attack you need to make the Juice Shop server attack itself.": "For this to count as an SSRF attack you need to make the Juice Shop server attack itself.",
  "Do not try to find the source code for the malware on GitHub. Take it apart with classic reverse-engineering techniques instead.": "Do not try to find the source code for the malware on GitHub. Take it apart with classic reverse-engineering techniques instead.",
  "\"SSTi\" is a clear indicator that this has nothing to do with anything Angular. Also, make sure to use only our non-malicious malware.": "\"SSTi\" is a clear indicator that this has nothing to do with anything Angular. Also, make sure to use only our non-malicious malware.",
  "You can find the juicy malware via a very obvious Google search or by stumbling into a very ill-placed quarantine folder with the necessary URLs in it.": "You can find the juicy malware via a very obvious Google search or by stumbling into a very ill-placed quarantine folder with the necessary URLs in it.",
  "Making the server download and execute the malware is key to solving this challenge.": "Making the server download and execute the malware is key to solving this challenge.",
  "For this challenge you do not have to reverse engineer the malware in any way. That will be required later to solve the \"Request a hidden resource on server through server\" challenge.": "For this challenge you do not have to reverse engineer the malware in any way. That will be required later to solve the \"Request a hidden resource on server through server\" challenge.",
  "This challenge asks you to act like an ethical hacker.": "This challenge asks you to act like an ethical hacker.",
  "Undoubtedly you want to read our security policy before conducting any research on our application.": "Undoubtedly you want to read our security policy before conducting any research on our application.",
  "As one of the good guys, would you just start attacking an application without consent of the owner?": "As one of the good guys, would you just start attacking an application without consent of the owner?",
  "You also might want to read the security policy or any bug bounty program that is in place.": "You also might want to read the security policy or any bug bounty program that is in place.",
  "The \"Comment\" field in the \"Customer Feedback\" screen is where you want to put your focus on.": "The \"Comment\" field in the \"Customer Feedback\" screen is where you want to put your focus on.",
  "The Comment field in the Contact Us screen is where you want to put your focus on.": "The Comment field in the Contact Us screen is where you want to put your focus on.",
  "The attack payload <iframe src=\"javascript:alert(`xss)\">` will not be rejected by any validator but stripped from the comment before persisting it.": "The attack payload <iframe src=\"javascript:alert(`xss)\">` will not be rejected by any validator but stripped from the comment before persisting it.",
  "Look for possible dependencies related to input processing in the package.json.bak you harvested earlier.": "Look for possible dependencies related to input processing in the package.json.bak you harvested earlier.",
  "If an XSS alert shows up but the challenge does not appear as solved on the Score Board, you might not have managed to put the exact attack string <iframe src=\"javascript:alert(`xss)\">` into the database?": "If an XSS alert shows up but the challenge does not appear as solved on the Score Board, you might not have managed to put the exact attack string <iframe src=\"javascript:alert(`xss)\">` into the database?",
  "There is not the slightest chance that you can spot the hidden character with the naked eye.": "There is not the slightest chance that you can spot the hidden character with the naked eye.",
  "You will need very specialized tool assistance for this challenge.": "You will need very specialized tool assistance for this challenge.",
  "The effective difficulty of this challenge depends a lot on what tools you pick to tackle it.": "The effective difficulty of this challenge depends a lot on what tools you pick to tackle it.",
  "This challenge cannot be solved by just reading our \"Lorem Ipsum\"-texts carefully.": "This challenge cannot be solved by just reading our \"Lorem Ipsum\"-texts carefully.",
  "Your attack payload must not trigger the protection against too many iterations and infinite loops.": "Your attack payload must not trigger the protection against too many iterations and infinite loops.",
  "This challenge uses the same leverage point as the \"Perform a Remote Code Execution that would keep a less hardened application busy forever\" challenge.": "This challenge uses the same leverage point as the \"Perform a Remote Code Execution that would keep a less hardened application busy forever\" challenge.",
  "This vulnerability will not affect any customer of the shop. It is aimed exclusively at its developers.": "This vulnerability will not affect any customer of the shop. It is aimed exclusively at its developers.",
  "This is a research-heavy challenge which does not involve any actual hacking.": "This is a research-heavy challenge which does not involve any actual hacking.",
  "Solving \"Access a developer's forgotten backup file\" before attempting this challenge will save you from a lot of frustration.": "Solving \"Access a developer's forgotten backup file\" before attempting this challenge will save you from a lot of frustration.",
  "The 2FA implementation requires to store a secret for every user. You will need to find a way to access this secret in order to solve this challenge.": "The 2FA implementation requires to store a secret for every user. You will need to find a way to access this secret in order to solve this challenge.",
  "As always, first learn how the feature under attack is used and behaves under normal conditions.": "As always, first learn how the feature under attack is used and behaves under normal conditions.",
  "Make sure you understand how 2FA with TOTP (time-based one-time password) works and which part of it is the critically sensitive one.": "Make sure you understand how 2FA with TOTP (time-based one-time password) works and which part of it is the critically sensitive one.",
  "Solving the challenge \"Retrieve a list of all user credentials via SQL Injection\" before tackling this one will definitely help. But it will not carry you all the way.": "Solving the challenge \"Retrieve a list of all user credentials via SQL Injection\" before tackling this one will definitely help. But it will not carry you all the way.",
  "This challenge exploits a weird option that is supported when signing tokens with JWT.": "This challenge exploits a weird option that is supported when signing tokens with JWT.",
  "You should begin with retrieving a valid JWT from the application’s Authorization request header.": "You should begin with retrieving a valid JWT from the application’s Authorization request header.",
  "A JWT is only given to users who have logged in. They have a limited validity, so better do not dawdle.": "A JWT is only given to users who have logged in. They have a limited validity, so better do not dawdle.",
  "Try to convince the site to give you a valid token with the required payload while downgrading to no encryption at all.": "Try to convince the site to give you a valid token with the required payload while downgrading to no encryption at all.",
  "You can attach a small file to the \"Complaint\" form. Investigate how this upload actually works.": "You can attach a small file to the \"Complaint\" form. Investigate how this upload actually works.",
  "First you should try to understand how the file upload is actually handled on the client and server side.": "First you should try to understand how the file upload is actually handled on the client and server side.",
  "With this understanding you need to find a \"weak spot\" in the right place and have to craft an exploit for it.": "With this understanding you need to find a \"weak spot\" in the right place and have to craft an exploit for it.",
  "You can attach a PDF or ZIP file to the \"Complaint\" form. Investigate how this upload actually works.": "You can attach a PDF or ZIP file to the \"Complaint\" form. Investigate how this upload actually works.",
  "If you solved the \"Upload a file larger than 100 kB\" challenge, you should try to apply the same solution here": "If you solved the \"Upload a file larger than 100 kB\" challenge, you should try to apply the same solution here",
  "Gather information on where user data is stored and how it is addressed. Then craft a corresponding UNION SELECT attack.": "Gather information on where user data is stored and how it is addressed. Then craft a corresponding UNION SELECT attack.",
  "Try to find an endpoint where you can influence data being retrieved from the server.": "Try to find an endpoint where you can influence data being retrieved from the server.",
  "Craft a UNION SELECT attack string to join data from another table into the original result.": "Craft a UNION SELECT attack string to join data from another table into the original result.",
  "You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next": "You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next",
  "As with \"Order the Christmas special offer of 2014\" and \"Exfiltrate the entire DB schema definition via SQL Injection\" this cannot be achieved through the application frontend.": "As with \"Order the Christmas special offer of 2014\" and \"Exfiltrate the entire DB schema definition via SQL Injection\" this cannot be achieved through the application frontend.",
  "Without utilizing the vulnerability behind another ⭐⭐⭐⭐⭐⭐ challenge it is not possible to plant the XSS payload for this challenge.": "Without utilizing the vulnerability behind another ⭐⭐⭐⭐⭐⭐ challenge it is not possible to plant the XSS payload for this challenge.",
  "The mentioned \"marketing collateral\" might have been publicly advertised by the Juice Shop but is not necessarily part of its sitemap yet.": "The mentioned \"marketing collateral\" might have been publicly advertised by the Juice Shop but is not necessarily part of its sitemap yet.",
  "It might help to perform some online searches for structurally similar web projects once you get stuck.": "It might help to perform some online searches for structurally similar web projects once you get stuck.",
  "This challenge will always partially keep you blindfolded, no matter how hard you do research and analysis.": "This challenge will always partially keep you blindfolded, no matter how hard you do research and analysis.",
  "Try out all existing functionality involving the shopping basket while having an eye on the HTTP traffic.": "Try out all existing functionality involving the shopping basket while having an eye on the HTTP traffic.",
  "There might be a client-side association of user to basket that you can try to manipulate.": "There might be a client-side association of user to basket that you can try to manipulate.",
  "In case you manage to update the database via SQL Injection so that a user is linked to another shopping basket, the application will not notice this challenge as solved.": "In case you manage to update the database via SQL Injection so that a user is linked to another shopping basket, the application will not notice this challenge as solved.",
  "Report one of two possible answers via the \"Customer Feedback\" form. Do not forget to submit the library's version as well.": "Report one of two possible answers via the \"Customer Feedback\" form. Do not forget to submit the library's version as well.",
  "Look for possible dependencies related to security in the package.json.bak you probably harvested earlier during the Access a developer’s forgotten backup file challenge.": "Look for possible dependencies related to security in the package.json.bak you probably harvested earlier during the Access a developer’s forgotten backup file challenge.",
  "Do some research on the internet for known security issues in the most suspicious application dependencies.": "Do some research on the internet for known security issues in the most suspicious application dependencies.",
  "Report one of five possible answers via the \"Customer Feedback\" form.": "Report one of five possible answers via the \"Customer Feedback\" form.",
  "Cryptographic functions only used in the \"Apply some advanced cryptanalysis to find the real easter egg\" challenge do not count as they are only a developer’s prank and not a serious security problem.": "Cryptographic functions only used in the \"Apply some advanced cryptanalysis to find the real easter egg\" challenge do not count as they are only a developer’s prank and not a serious security problem.",
  "You have to find a way to beat the allowlist of allowed redirect URLs.": "You have to find a way to beat the allowlist of allowed redirect URLs.",
  "You can find several places where redirects happen in the OWASP Juice Shop.": "You can find several places where redirects happen in the OWASP Juice Shop.",
  "The application will only allow you to redirect to allowlisted (previously referred to as whitelisted) URLs.": "The application will only allow you to redirect to allowlisted (previously referred to as whitelisted) URLs.",
  "Tampering with the redirect mechanism might give you some valuable information about how it works under to hood.": "Tampering with the redirect mechanism might give you some valuable information about how it works under to hood.",
  "The leverage point for this challenge is the deprecated B2B interface.": "The leverage point for this challenge is the deprecated B2B interface.",
  "This challenge sounds a lot harder than it actually is, which amplifies how bad the underlying vulnerability is.": "This challenge sounds a lot harder than it actually is, which amplifies how bad the underlying vulnerability is.",
  "Doing some research on typical XEE attack patterns basically gives away the solution for free.": "Doing some research on typical XEE attack patterns basically gives away the solution for free.",
  "It is not as easy as sending a large amount of data directly to the deprecated B2B interface.": "It is not as easy as sending a large amount of data directly to the deprecated B2B interface.",
  "The leverage point for this is obviously the same as for the XXE Data Access challenge.": "The leverage point for this is obviously the same as for the XXE Data Access challenge.",
  "You can only solve this challenge by keeping the server busy for >2sec with your attack.": "You can only solve this challenge by keeping the server busy for >2sec with your attack.",
  "The effectiveness of attack payloads for this challenge might depend on the operating system the Juice Shop is running on.": "The effectiveness of attack payloads for this challenge might depend on the operating system the Juice Shop is running on.",
  "This one is actually similar to the XXE DoS challenge in every way except the data format being (ab)used.": "This one is actually similar to the XXE DoS challenge in every way except the data format being (ab)used.",
  "Before you invest time bypassing the API, you might want to play around with the UI a bit.": "Before you invest time bypassing the API, you might want to play around with the UI a bit.",
  "Check the Photo Wall for an image that could not be loaded correctly.": "Check the Photo Wall for an image that could not be loaded correctly.",
  "You just have to (literally) inspect the problem to understand the basic issue.": "You just have to (literally) inspect the problem to understand the basic issue.",
  "It can also help to try out the Tweet-button of the entry and observe what happens.": "It can also help to try out the Tweet-button of the entry and observe what happens.",
  "This challenge would formally have to be in several categories as the developers made multiple gaffes for this to be possible.": "This challenge would formally have to be in several categories as the developers made multiple gaffes for this to be possible.",
  "Loading this page with an empty browser cache and on a slow (or throttled) connection will give you an idea on what the delivery box image is made of. Of course inspecting the page source will tell you just as much.": "Loading this page with an empty browser cache and on a slow (or throttled) connection will give you an idea on what the delivery box image is made of. Of course inspecting the page source will tell you just as much.",
  "You need to dive deep into the actual Angular code to understand this one.": "You need to dive deep into the actual Angular code to understand this one.",
  "This challenge requires the exploitation of another vulnerability which even has its own two challenges in its very own category": "This challenge requires the exploitation of another vulnerability which even has its own two challenges in its very own category",
  "This challenge can only be solved by strictly using the mentioned \"cross-domain kittens\". No other kittens from anywhere else can solve this challenge.": "This challenge can only be solved by strictly using the mentioned \"cross-domain kittens\". No other kittens from anywhere else can solve this challenge.",
  "Try to guess what URL the endpoint might have.": "Try to guess what URL the endpoint might have.",
  "The Juice Shop serves its metrics on the default path expected by Prometheus": "The Juice Shop serves its metrics on the default path expected by Prometheus",
  "Guessing the path is probably just as quick as taking the RTFM route via https://prometheus.io/docs/introduction/first_steps": "Guessing the path is probably just as quick as taking the RTFM route via https://prometheus.io/docs/introduction/first_steps",
  "Look closely at what happens when you attempt to upgrade your account.": "Look closely at what happens when you attempt to upgrade your account.",
  "Go to the payment page for a deluxe membership and try paying through different methods.": "Go to the payment page for a deluxe membership and try paying through different methods.",
  "Try inspecting the requests that go out for each of these methods, using the browser’s developer tools.": "Try inspecting the requests that go out for each of these methods, using the browser’s developer tools.",
  "Maybe playing around with the parameters in these requests could reveal something interesting.": "Maybe playing around with the parameters in these requests could reveal something interesting.",
  "Find a form which updates the username and then construct a malicious page in the online HTML editor. You probably need an older browser version for this.": "Find a form which updates the username and then construct a malicious page in the online HTML editor. You probably need an older browser version for this.",
  "Take a look at what happens when you change the username within the profile page.": "Take a look at what happens when you change the username within the profile page.",
  "Search for information about CSRF attacks and look out for examples that can be applied to this challenge.": "Search for information about CSRF attacks and look out for examples that can be applied to this challenge.",
  "Write the code for the CSRF attack within http://htmledit.squarefree.com and verify that it changes your username.": "Write the code for the CSRF attack within http://htmledit.squarefree.com and verify that it changes your username.",
  "First, solve the \"Perform a DOM XSS attack\" challenge.": "First, solve the \"Perform a DOM XSS attack\" challenge.",
  "Now it is just a question of copying and pasting the payload into the same vulnerable field.": "Now it is just a question of copying and pasting the payload into the same vulnerable field.",
  "Crank up the volume of your computer before submitting the payload! 🔊": "Crank up the volume of your computer before submitting the payload! 🔊",
  "You might have to do some OSINT on his social media personas to find out his honest answer to the security question.": "You might have to do some OSINT on his social media personas to find out his honest answer to the security question.",
  "People often reuse aliases online. You might be able to find something by looking online for Uvogin’s name or slight variations of it based on his unique writing habits.": "People often reuse aliases online. You might be able to find something by looking online for Uvogin’s name or slight variations of it based on his unique writing habits.",
  "You might be able to find some existing OSINT tools to help you in this investigation.": "You might be able to find some existing OSINT tools to help you in this investigation.",
  "Take a look at the meta data of the corresponding photo.": "Take a look at the meta data of the corresponding photo.",
  "Make use of tools that can inspect the metadata of images.": "Make use of tools that can inspect the metadata of images.",
  "Use this information to answer the security question of the John, who enjoys hiking in the park.": "Use this information to answer the security question of the John, who enjoys hiking in the park.",
  "Take a look at the details in the photo to determine the location of where it was taken.": "Take a look at the details in the photo to determine the location of where it was taken.",
  "Analyze and tamper with links in the application until you get to an unprotected directory listing.": "Analyze and tamper with links in the application until you get to an unprotected directory listing.",
  "Some files in there are not directly accessible because a security mechanism prevents access.": "Some files in there are not directly accessible because a security mechanism prevents access.",
  "The Poison Null Byte can trick the security mechanism into thinking that the file you want has a valid file type.": "The Poison Null Byte can trick the security mechanism into thinking that the file you want has a valid file type.",
  "Depending on the files you try to retrieve you will probably solve \"Access a developer’s forgotten backup file\", \"Access a salesman’s forgotten backup file\", \"Access a misplaced SIEM signature file, or \"Find the hidden easter egg\" along the way.": "Depending on the files you try to retrieve you will probably solve \"Access a developer’s forgotten backup file\", \"Access a salesman’s forgotten backup file\", \"Access a misplaced SIEM signature file, or \"Find the hidden easter egg\" along the way.",
  "You should read up on vulnerabilities in popular NodeJs template engines.": "You should read up on vulnerabilities in popular NodeJs template engines.",
  "You should read up on Local File Read (LFR) vulnerabilities in popular NodeJS template engines.": "You should read up on Local File Read (LFR) vulnerabilities in popular NodeJS template engines.",
  "Look for an easily forgettable endpoint in Juice Shop to test out the LFR attack.": "Look for an easily forgettable endpoint in Juice Shop to test out the LFR attack.",
  "500 Internal Server Error is always an interesting status code.": "500 Internal Server Error is always an interesting status code.",
  "Fuzzing can also help with this challenge.": "Fuzzing can also help with this challenge.",
  "Either check the official documentation or inspect a notification UI element directly.": "Either check the official documentation or inspect a notification UI element directly.",
  "This challenge is most easily solvable immediately after a server restart.": "This challenge is most easily solvable immediately after a server restart.",
  "Alternatively you can also inspect any \"Challenge solved\"-notification in your browser to understand its convenience feature.": "Alternatively you can also inspect any \"Challenge solved\"-notification in your browser to understand its convenience feature.",
  "Security Advisories are often listed in the security.txt": "Security Advisories are often listed in the security.txt",
  "Have a look at the client-side code in the dev console.": "Have a look at the client-side code in the dev console.",
  "The API call is part of a scheduled process \"behind the scenes\", i.e. completely unrelated to the web application.": "The API call is part of a scheduled process \"behind the scenes\", i.e. completely unrelated to the web application.",
  "Check the Juice Shop’s social media channels for regularly scheduled content being posted, possibly even indicating that it was automatically created.": "Check the Juice Shop’s social media channels for regularly scheduled content being posted, possibly even indicating that it was automatically created.",
  "Find out which part of the content might come from the response of an API call.": "Find out which part of the content might come from the response of an API call.",
  "Find the place where the API call happens — as stated above, it is not in the web application — and then look for the API key itself.": "Find the place where the API call happens — as stated above, it is not in the web application — and then look for the API key itself.",
  "The chatbot has a tool for generating coupons, but is instructed to only use it under very specific conditions.": "The chatbot has a tool for generating coupons, but is instructed to only use it under very specific conditions.",
  "Try to convince the chatbot that the conditions for coupon generation are met, even if they are not.": "Try to convince the chatbot that the conditions for coupon generation are met, even if they are not.",
  "Prompt injection techniques can help you bypass the chatbot's restrictions on tool usage.": "Prompt injection techniques can help you bypass the chatbot's restrictions on tool usage.",
  "The chatbot's system prompt says the maximum discount is 10%. But system prompts are more like guidelines than actual rules, right?": "The chatbot's system prompt says the maximum discount is 10%. But system prompts are more like guidelines than actual rules, right?",
  "You already know how to make the chatbot generate a coupon. Now make it go way beyond the allowed maximum.": "You already know how to make the chatbot generate a coupon. Now make it go way beyond the allowed maximum.",
  "The chatbot trusts whatever discount value it decides to pass to its tool. Make it decide on a very generous number.": "The chatbot trusts whatever discount value it decides to pass to its tool. Make it decide on a very generous number.",
  "The chatbot has a debugging feature that shows how it interacts with its tools. It is only supposed to be visible for admins.": "The chatbot has a debugging feature that shows how it interacts with its tools. It is only supposed to be visible for admins.",
  "Access control for the debugging feature is only implemented on the client-side.": "Access control for the debugging feature is only implemented on the client-side.",
  "Find the cookie that controls the visibility of tool calls and set it to <code>true</code>.": "Find the cookie that controls the visibility of tool calls and set it to <code>true</code>.",
  "If you see the tool calls but the challenge is not marked as solved, you might be still logged in as a user with admin privileges.": "If you see the tool calls but the challenge is not marked as solved, you might be still logged in as a user with admin privileges.",
  "Invalid email/password cannot be empty": "Invalid email/password cannot be empty",
  "<a href=\"https://owasp.slack.com\" target=\"_blank\">More...</a>": "<a href=\"https://owasp.slack.com\" target=\"_blank\">More...</a>"
}
