Hackers of India

SCAGoat - Exploiting Damn Vulnerable SCA Application

By  Hare Krishna Rai   Gaurav Joshi   Prashant Venkatesh  on 11 Dec 2024 @ Blackhat : Arsenal

This Tool Demo covers following tools where the speaker has contributed or authored
SCAGOAT

Abstract

SCAGoat is a deliberately insecure web application designed for learning and testing Software Composition Analysis (SCA) tools. It offers a hands-on environment to explore vulnerabilities in Node.js and Java Springboot applications, including actively exploitable CVEs like CVE-2023-42282 and CVE-2021-44228 (log4j). This application can be utilized to evaluate various SCA and container security tools, assessing their capability to identify vulnerable packages and code reachability. As part of our independent research, the README includes reports from SCA tools like semgrep, snyk, and endor labs. Future research plans include incorporating compromised or malicious packages to test SCA tool detection and exploring supply chain attack scenarios.