Cyber Security project
Review a deliberately vulnerable app and write findings a stakeholder can act on
A security review of OWASP Juice Shop or DVWA run locally — graded on whether findings are proven with real repro steps and specific fixes, not a generic checklist.
The brief
Run a deliberately vulnerable practice application locally (OWASP Juice Shop or DVWA). Identify at least 5 real vulnerabilities spanning different OWASP Top 10 categories, and for each one document the reproduction steps, the real-world impact, and a specific remediation. Write it up as a professional-format security report. Scope is strictly the local practice app — no other target.
Suggested stack
What you hand in
- A PDF report with an executive summary, per-finding sections, and screenshots
- Each finding includes an OWASP category, reproduction steps, impact, and specific remediation
- A short methodology section stating the tool was run locally with no external target involved
Grading happens against the rubric below, so read it before you start — not after.
How this is graded
Published in advance and weighted out of 100. Nothing here is a surprise.
Each finding is demonstrated against the actual app, not copy-pasted from a generic OWASP Top 10 list, and correctly mapped to its category.
Steps are specific enough that another person could follow them and get the same result, including exact inputs used.
Remediation names the actual fix for that specific finding (e.g. "parameterize this query"), not generic advice like "use best practices" or "sanitize input".
An executive summary section explains the overall risk in plain language a non-technical reader could act on.
No console errors or crashes, no broken layout, no leftover placeholder text or commented-out code.
Why this project is worth your weekend
- OWASP Juice Shop and DVWA are the actual practice targets real security teams use to train juniors, so this maps directly onto how the skill is taught professionally.
- A report a stakeholder can act on is the real deliverable of the job, not the exploit itself — write-up quality is graded as heavily as the finding.
- Vague, copy-pasted remediation advice is the single most common tell of a report that wasn't really done, and it's easy for a reviewer to spot immediately.
Where people lose points
- Listing that a vulnerability category exists in the app without demonstrating it with actual reproduction steps against the real target.
- Remediation advice generic enough to apply to any app ("validate all input") instead of naming the specific fix for that finding.
- Writing the report entirely in security jargon with no summary a non-technical stakeholder could read and act on.
Other Cyber Security projects
Two or three of these turn an empty resume into a portfolio.
Built it? Get it scored against this rubric.
Submit your work and get a score on every criterion above, written feedback, and three resume bullets you can use straight away.