Manila/Install OWASP Juice Shop in Ubuntu

Hello Guys today we are going to discuss in this tutorial on how to install OWASP Juice Shop in Ubuntu 16.04.3-desktop-amd.iso, i just want to share this to help other security enthusiast like me who likes to share and teach something to help the community grow.

First we need to know what is OWASP JUICE SHOP is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. for more information you can visit : Juice Shop

Before we start we need the following tools: Once you bootup your Ubuntu Machine we need to execute the following command:
 * 1) Ubuntu 16.04.3-desktop-amd.iso
 * 2) Download
 * 3) * vmware working station
 * 4) * virtualbox
 * 5) Download the latest version of OWASP Juice Shop
 * 6) * Download: Here
 * 7) make sure to install everything from software to your Ubuntu Linux Box in your virtual machine that you choose

once the update and upgrade we are going to install all the dependencies we need to run our OWASP Juice Shop, make your terminal available on your desktop we still need it to install.

you can download the repo directly on the github but when i try to clone the github repo directly there is some error on the source code, that's why i prepare to download this file directly Here

now we need to install jode.js on our ubuntu machine, we can install it by typing the following commands

The latest update for node.js 8.0 is the current Node.js release available:

Use LTS Release: using Node.js 6.11 is the LTS release available

wait until the installation is done, after the installation is finish lets install the noje.js



again wait until the installation is done!

Take note we install the    because this version is stable you can install the version 8 if you like :)

once the installation is done extract the file you downloaded on https://github.com/bkimminich/juice-shop/releases/tag/v5.0.1 make sure you download the file that is compatible on the version of the node.js you install.

Next step is navigate to your directory location where you save the Juice Shop file directory in my case i save it on the Documents for tutorial purpose only.

once your on the directory run the following command:



after the installation if there is no errors on the installation proceed on the next step run the applicaiton

if there is not error your vulnerable web application is now running and you are good to go! make sure you run every code in "sudo" you will get an error in directory and file permissions.



Note: in any case i tried to install this in ubuntu machine many times, for experiment purpose first i use ubuntu x32bit architecture but there is to many errors on the source code because the OWASP Juice Shop is compatible with Ubuntu x64 bit Architecture, i encounter many error and all you need to do is to troubleshoot the error messages sometimes there is a missing libraries or module on your system that needs to install first in my case the error i encounter is the sqlite3 is not installed in my system. after installing the sqlite3 there is no error and may application run smoothly.

Special thanks to the behind this awesome project!


 * Björn Kimminich aka
 * Bitdeli Chef aka
 * The Gitter Badger aka
 * Aaron Edwards aka
 * Dinis Cruz aka
 * Timo Pagel aka
 * Gorka Vicente aka
 * Alvaro Viebrantz aka
 * Johanna A aka
 * Stephen OBrien aka
 * Joe Butler aka
 * Abhishek bundela aka
 * ninoseki
 * Jannik Hollenbach aka
 * Viktor Lindström aka
 * Achim Grimm aka

Thank you guys!

Created By:

John Patrick Lita | OWASP Manila

Cyber Security Philippines -CERT : VAPT Operations Manager