Free forever: 5 resume reviews + 10 AI actions every month. Claim your free spot →
ReachRole

Cyber Security project

Review a deliberately vulnerable app and write findings a stakeholder can act on

A security review of OWASP Juice Shop or DVWA run locally — graded on whether findings are proven with real repro steps and specific fixes, not a generic checklist.

8-11 hoursEstimated time
BeginnerDifficulty
5Graded criteria
PdfWhat you submit

The brief

Run a deliberately vulnerable practice application locally (OWASP Juice Shop or DVWA). Identify at least 5 real vulnerabilities spanning different OWASP Top 10 categories, and for each one document the reproduction steps, the real-world impact, and a specific remediation. Write it up as a professional-format security report. Scope is strictly the local practice app — no other target.

Suggested stack

OWASP Juice Shop or DVWA, run locally Browser dev tools or Burp Suite Community

What you hand in

  • A PDF report with an executive summary, per-finding sections, and screenshots
  • Each finding includes an OWASP category, reproduction steps, impact, and specific remediation
  • A short methodology section stating the tool was run locally with no external target involved

Grading happens against the rubric below, so read it before you start — not after.

How this is graded

Published in advance and weighted out of 100. Nothing here is a surprise.

Vulnerabilities are real and correctly categorized 30 pts

Each finding is demonstrated against the actual app, not copy-pasted from a generic OWASP Top 10 list, and correctly mapped to its category.

Reproducible steps 25 pts

Steps are specific enough that another person could follow them and get the same result, including exact inputs used.

Specific remediation 25 pts

Remediation names the actual fix for that specific finding (e.g. "parameterize this query"), not generic advice like "use best practices" or "sanitize input".

Stakeholder-readable report 10 pts

An executive summary section explains the overall risk in plain language a non-technical reader could act on.

Finish 10 pts

No console errors or crashes, no broken layout, no leftover placeholder text or commented-out code.

Why this project is worth your weekend

  • OWASP Juice Shop and DVWA are the actual practice targets real security teams use to train juniors, so this maps directly onto how the skill is taught professionally.
  • A report a stakeholder can act on is the real deliverable of the job, not the exploit itself — write-up quality is graded as heavily as the finding.
  • Vague, copy-pasted remediation advice is the single most common tell of a report that wasn't really done, and it's easy for a reviewer to spot immediately.

Where people lose points

  • Listing that a vulnerability category exists in the app without demonstrating it with actual reproduction steps against the real target.
  • Remediation advice generic enough to apply to any app ("validate all input") instead of naming the specific fix for that finding.
  • Writing the report entirely in security jargon with no summary a non-technical stakeholder could read and act on.

Built it? Get it scored against this rubric.

Submit your work and get a score on every criterion above, written feedback, and three resume bullets you can use straight away.

Submit for grading Free to start. Grading uses one AI action.