{
  "2": "2",
  "3": "3",
  "Apple Juice (1000ml)": "苹果汁(1000毫升)",
  "The all-time classic.": "历来经典.",
  "Apple Pomace": "苹果糊",
  "Finest pressings of apples. Allergy disclaimer: Might contain traces of worms. Can be <a href=\"/#recycle\">sent back to us</a> for recycling.": "苹果的最佳压榨法. 过敏免责声明: 可能包含蠕虫的痕迹。可以<a href=\"/#recycle\">退还</a>我们进行回收。",
  "Banana Juice (1000ml)": "香蕉汁(1000毫升)",
  "Monkeys love it the most.": "猴子最喜欢它。",
  "Basil Smoothie": "罗勒冰沙",
  "A unique blend of fresh basil and ginger for a healthy kick.": "新鲜罗勒与生姜的独特组合，为健康注入活力。",
  "Berry Juice (1000ml)": "浆果汁 (1000ml)",
  "A delicious blend of fresh forest berries.": "新鲜森林浆果的美味混合。",
  "Best Juice Shop Salesman Artwork": "果汁商店最佳销售插画",
  "Unique digital painting depicting Stan, our most qualified and almost profitable salesman. He made a succesful carreer in selling used ships, coffins, krypts, crosses, real estate, life insurance, restaurant supplies, voodoo enhanced asbestos and courtroom souvenirs before <em>finally</em> adding his expertise to the Juice Shop marketing team.": "独特的描绘我们最有资格和几乎盈利的推销员斯坦的数字绘画。他在出售二手船、棺材、氪、十字架、房地产、人寿保险、餐厅用品、伏都教强化石棉和法庭纪念品方面取得了成功，<em>最后</em>他带着自己的专长加入了果汁店营销团队。",
  "Bragă (500ml)": "布拉加(500ml)",
  "Traditional Balkan drink made from fermented millet. Lightly sweet-sour, refreshing, and naturally energizing.": "巴尔干半岛的传统饮品，由发酵小米制成。微酸带甜，清爽可口，且具有天然的提神功效。",
  "Carrot Juice (1000ml)": "胡萝卜汁(1000毫升)",
  "As the old German saying goes: \"Carrots are good for the eyes. Or has anyone ever seen a rabbit with glasses?\"": "就像古老的德国谚语所说：“胡萝卜对眼睛有益。你见过戴眼镜的兔子么？”",
  "Dragonfruit Juice (500ml)": "火龙果汁(500ml)",
  "Exotic and vibrant juice made from dragonfruit.": "由火龙果制成的奇异且充满活力的果汁。",
  "Eggfruit Juice (500ml)": "蛋黄果汁(500毫升)",
  "Now with even more exotic flavour.": "现在具有更多异国风味。",
  "Elderflower Cordial (500ml)": "接骨木花露(500ml)",
  "Floral and fragrant soft drink made from elderflowers. Traditionally enjoyed chilled.": "由接骨木花制成的花香软饮料。传统上冷藏后饮用。",
  "Fruit Press": "榨汁机",
  "Fruits go in. Juice comes out. Pomace you can send back to us for recycling purposes.": "水果进去。果汁出来。 您可以将果渣寄回给我们以进行回收。",
  "Grape Juice (1000ml)": "葡萄汁(1000ml)",
  "Deep purple and full of antioxidants from selected grapes.": "深紫色，富含精选葡萄中的抗氧化剂。",
  "Green Smoothie": "蔬菜汁",
  "Looks poisonous but is actually very good for your health! Made from green cabbage, spinach, kiwi and grass.": "看起来有毒，但实际上对您的健康非常有好处！ 由青菜，菠菜，猕猴桃和草制成。",
  "Juice Shop \"Permafrost\" 2020 Edition": "Juice Shop \"永久冻结\" 2020 版",
  "Exact version of <a href=\"https://github.com/juice-shop/juice-shop/releases/tag/v9.3.1-PERMAFROST\">OWASP Juice Shop that was archived on 02/02/2020</a> by the GitHub Archive Program and ultimately went into the <a href=\"https://github.blog/2020-07-16-github-archive-program-the-journey-of-the-worlds-open-source-code-to-the-arctic\">Arctic Code Vault</a> on July 8. 2020 where it will be safely stored for at least 1000 years.": "特定版本OWASP果汁店 <a href=\"https://github.com/juice-shop/juice-shop/releases/tag/v9.3.1-PERMAFROST\">于2020年2月2日被GitHub归档程序归档</a> ，最终于2020年7月8日进入GitHub的 <a href=\"https://github.blog/2020-07-16-github-archive-program-the-journey-of-the-worlds-open-source-code-to-the-arctic\">北极代码库</a>，在那里它将安全储存至少1000年。",
  "Lemon Juice (500ml)": "柠檬汁(500毫升)",
  "Sour but full of vitamins.": "虽然酸但富含维生素。",
  "Melon Bike (Comeback-Product 2018 Edition)": "Melon自行车 (2018重制版)",
  "The wheels of this bicycle are made from real water melons. You might not want to ride it up/down the curb too hard.": "这辆自行车的车轮是用真正的西瓜制成的。 您可能不想过分用力将其沿上下路边骑行。",
  "Melon Juice (1000ml)": "西瓜汁(1000ml)",
  "Refreshing and sweet juice made from ripe melons.": "由成熟瓜果制成的清爽甜汁。",
  "OWASP Juice Shop \"King of the Hill\" Facemask": "OWASP Juice Shop \"山丘之王\" 面罩",
  "Facemask with compartment for filter from 50% cotton and 50% polyester.": "含有50%棉和50%聚酯纤维的过滤面罩。",
  "OWASP Juice Shop CTF Girlie-Shirt": "OWASP Juice Shop CTF 少女衬衫",
  "For serious Capture-the-Flag heroines only!": "只为真正的CTF英雄!",
  "OWASP Juice Shop Card (non-foil)": "OWASP果汁店卡片(无箔)",
  "Mythic rare <small><em>(obviously...)</em></small> card \"OWASP Juice Shop\" with three distinctly useful abilities. Alpha printing, mint condition. A true collectors piece to own!": "神奇稀有 <small><em>(很明显...)</em></small> 卡片\"OWASP Juice Shop\", 有三种明显有用的用途。 阿尔法印刷，完好无损。一个真正的收藏家值得拥有！",
  "OWASP Juice Shop Coaster (10pcs)": "OWASP Juice Shop 杯垫 (10个)",
  "Our 95mm circle coasters are printed in full color and made from thick, premium coaster board.": "我们的95毫米圆形杯垫全彩印刷，由厚实的优质杯垫板制成。",
  "OWASP Juice Shop Holographic Sticker": "OWASP Juice Shop 全息贴纸",
  "Die-cut holographic sticker. Stand out from those 08/15-sticker-covered laptops with this shiny beacon of 80's coolness!": "分割好的全息贴纸。用这80年代最炫酷的标志覆盖你的笔记本，让你脱颖而出!",
  "OWASP Juice Shop Hoodie": "OWASP Juice Shop 连帽衫",
  "Mr. Robot-style apparel. But in black. And with logo.": "机器人先生风格的服装。黑色带有徽标。",
  "OWASP Juice Shop Iron-Ons (16pcs)": "OWASP Juice Shop 转印贴纸 (16张)",
  "Upgrade your clothes with washer safe <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">iron-ons</a> of the OWASP Juice Shop or CTF Extension logo!": "升级您的衣服， 在<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">周边</a>查找可水洗的OWASP Juice shop或CTF标志！",
  "OWASP Juice Shop LEGO™ Tower": "OWASP果汁店 LEGO™ 塔",
  "Want to host a Juice Shop CTF in style? Build <a href=\"https://github.com/OWASP/owasp-swag/blob/master/projects/juice-shop/lego/OWASP%20JuiceShop%20Pi-server%201.2.pdf\" target=\"_blank\">your own LEGO™ tower</a> which holds four Raspberry Pi 4 models with PoE HAT modules <a href=\"https://github.com/juice-shop/multi-juicer/blob/main/guides/raspberry-pi/raspberry-pi.md\" target=\"_blank\">running a MultiJuicer Kubernetes cluster</a>! Wire to a switch and connect to your network to have an out-of-the-box ready CTF up in no time!": "想举办一场别具一格的果汁店夺旗赛? 搭建 <a href=\"https://github.com/OWASP/owasp-swag/blob/master/projects/juice-shop/lego/OWASP%20JuiceShop%20Pi-server%201.2.pdf\" target=\"_blank\">你专属的LEGO™ 塔</a> 容纳四台搭载PoE HAT模块的树莓派4 <a href=\"https://github.com/juice-shop/multi-juicer/blob/main/guides/raspberry-pi/raspberry-pi.md\" target=\"_blank\">运行MultiJuicer Kubernetes集群</a>! 即刻拥有开箱即用的CTF环境!",
  "OWASP Juice Shop Logo (3D-printed)": "OWASP Juice Shop徽标(3D-打印)",
  "This rare item was designed and handcrafted in Sweden. This is why it is so incredibly expensive despite its complete lack of purpose.": "这款稀有物品是在瑞典设计和手工制作的。 这就是为什么尽管它完全没有目的，却是如此昂贵的原因。",
  "OWASP Juice Shop Magnets (16pcs)": "OWASP Juice Shop 磁吸(16个)",
  "Your fridge will be even cooler with these OWASP Juice Shop or CTF Extension logo <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">magnets</a>!": "使用这些OWASP Juice shop或CTF徽标会让你显得更酷<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">磁力标志</a>！",
  "OWASP Juice Shop Mug": "OWASP Juice Shop 马克杯",
  "Black mug with regular logo on one side and CTF logo on the other! Your colleagues will envy you!": "一侧有普通徽标的和另一侧有CTF徽标的黑色马克杯！同事们会羡慕你！",
  "OWASP Juice Shop Sticker Page": "OWASP Juice Shop整页贴纸",
  "Massive decoration opportunities with these OWASP Juice Shop or CTF Extension <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">sticker pages</a>! Each page has 16 stickers on it.": "这些OWASP Juice Shop或CTF<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">贴纸</a>带来大量装饰机会！ 每页上有16个贴纸。",
  "OWASP Juice Shop Sticker Single": "OWASP Juice Shop单页贴纸",
  "Super high-quality vinyl <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">sticker single</a> with the OWASP Juice Shop or CTF Extension logo! The ultimate laptop decal!": "使用OWASP Juice Shop或CTF 徽章，高品质的 <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">标签贴</a> ！终极笔记本贴纸！",
  "OWASP Juice Shop T-Shirt": "OWASP Juice Shop T恤",
  "Real fans wear it 24/7!": "真正粉丝24/7穿着它!",
  "OWASP Juice Shop Temporary Tattoos (16pcs)": "OWASP Juice Shop 临时纹身(16张)",
  "Get one of these <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">temporary tattoos</a> to proudly wear the OWASP Juice Shop or CTF Extension logo on your skin! If you tweet a photo of yourself with the tattoo, you get a couple of our stickers for free! Please mention <a href=\"https://twitter.com/owasp_juiceshop\" target=\"_blank\"><code>@owasp_juiceshop</code></a> in your tweet!": "获取以下<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">临时纹身</a>之一，自豪地纹着OWASP Juice Shop或CTF徽标在您的皮肤上！ 如果您发布自己带纹身的照片，则可免费获得我们的几张贴纸！ 请在您的推文中提及<a href=\"https://twitter.com/owasp_juiceshop\" target=\"_blank\"> <code> @owasp_juiceshop </code> </a>！",
  "OWASP Juice Shop-CTF Velcro Patch": "OWASP Juice Shop-CTF 魔术贴",
  "4x3.5\" embroidered patch with velcro backside. The ultimate decal for every tactical bag or backpack!": "4x3.5英寸刺绣贴布，带魔术贴背面。每个战术包或背包的终极贴花！",
  "OWASP SSL Advanced Forensic Tool (O-Saft)": "OWASP SSL 高级取证工具 (O-Saft)",
  "O-Saft is an easy to use tool to show information about SSL certificate and tests the SSL connection according given list of ciphers and various SSL configurations. <a href=\"https://www.owasp.org/index.php/O-Saft\" target=\"_blank\">More...</a>": "O-Saft 是一个简单易用的工具来显示关于SSL 证书的信息，并根据给定的加密方式和各种SSL配置列表测试SSL 连接。 <a href=\"https://www.owasp.org/index.php/O-Saft\" target=\"_blank\">更多...</a>",
  "OWASP Snakes and Ladders - Mobile Apps": "OWASP蛇梯棋-移动应用",
  "This amazing mobile app security awareness board game is <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1970691216\">available for Tabletop Simulator on Steam Workshop</a> now!": "这个令人惊奇的移动应用是一个安全意识游戏，可在Steam上 <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1970691216\">Tabletop Simulator的创意工坊中获得</a>！",
  "OWASP Snakes and Ladders - Web Applications": "OWASP蛇梯棋-Web应用",
  "This amazing web application security awareness board game is <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1969196030\">available for Tabletop Simulator on Steam Workshop</a> now!": "这是个令人惊奇的Web应用安全意识游戏，可在Steam上 <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1969196030\">Tabletop Simulator的创意工坊中获得</a>！",
  "Orange Juice (1000ml)": "橙汁 (1000毫升)",
  "Made from oranges hand-picked by Uncle Dittmeyer.": "由Dittmeyer叔叔手工挑选的橘子制成。",
  "Pineapple Juice (1000ml)": "菠萝汁(1000ml)",
  "Tropical refreshment from the finest sun-ripened pineapples.": "来自最优质阳光熟成菠萝的热带清爽口感。",
  "Pomegranate Drink (500ml)": "石榴汁(500ml)",
  "A sweet and tart refreshment inspired by classic grenadine flavors.": "一款灵感源自经典石榴糖浆风味的酸甜饮品。",
  "Pwning OWASP Juice Shop": "攻克 OWASP Juice Shop",
  "<em>The official Companion Guide</em> by Björn Kimminich available <a href=\"https://leanpub.com/juice-shop\">for free on LeanPub</a> and also <a href=\"https://pwning.owasp-juice.shop\">readable online</a>!": "Björn Kimminich编写的<em>官方完全指南</em> 可在<a href=\"https://leanpub.com/juice-shop\">LeanPub</a> 免费阅览和 <a href=\"https://pwning.owasp-juice.shop\">在线阅览</a>!",
  "Quince Juice (1000ml)": "榅桲汁(1000毫升)",
  "Juice of the <em>Cydonia oblonga</em> fruit. Not exactly sweet but rich in Vitamin C.": "<em>榅桲</em> 汁。不甜但是富含维生素C。",
  "Raspberry Juice (1000ml)": "树莓汁 (1000毫升)",
  "Made from blended Raspberry Pi, water and sugar.": "由树莓派、水和糖混合制成。",
  "Sea Buckthorn Juice (500ml)": "沙棘汁(500ml)",
  "Tangy and slightly sour juice, extremely rich in Vitamin C and antioxidants.": "酸甜可口的果汁，富含维生素C和抗氧化剂。",
  "Strawberry Juice (500ml)": "草莓汁(500毫升)",
  "Sweet & tasty!": "香甜可口！",
  "Woodruff Syrup \"Forest Master X-Treme\"": "Woodruff Syrup \"森林大师X-Treme\"",
  "Harvested and manufactured in the Black Forest, Germany. Can cause hyperactive behavior in children. Can cause permanent green tongue when consumed undiluted.": "在德国黑森林采伐和制造。 可能导致儿童多动。 未经稀释食用会导致永久性舌头变绿。",
  "Find the carefully hidden 'Score Board' page.": "找到精心隐藏的“计分板”页面。",
  "Order Confirmation": "订单确认",
  "Customer": "客户",
  "Order": "订单",
  "ea.": "每件/个",
  "Delivery Price": "配送价格",
  "Total Price": "总价",
  "Date": "日期",
  "Bonus Points Earned": "获得奖励积分",
  "The bonus points from this order will be added 1:1 to your wallet ¤-fund for future purchases!": "本次订单的奖励积分将按1:1比例添加至您的钱包¤-fund账户，供未来购物使用！",
  "Thank you for your order!": "感谢您的订购",
  "Obtain the password (hash) of the currently logged-in user directly from a REST API endpoint.": "直接从REST API端点获取当前登录用户的密码（哈希值）。",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> without using the frontend application at all.": "使用<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>代码在不使用前端应用程序情况下进行 <i>存储型</i> XSS 攻击。",
  "Gain access to any access log file of the server.": "获取访问服务器上任何访问日志文件的权限。",
  "Register as a user with administrator privileges.": "注册一个拥有管理员权限的用户。",
  "Access the administration section of the store.": "访问商店的管理页面。",
  "Overwrite the <a href=\"/ftp/legal.md\">Legal Information</a> file.": "覆写 <a href=\"/ftp/legal.md\">法律信息</a> 文件。",
  "Reset the password of Bjoern's OWASP account via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "通过 <a href=\"/#/forgot-password\">忘记密码</a>功能和<i>原始安全问题答案</i>重置Bjoern's OWASP账户的密码。",
  "Learn about the Token Sale before its official announcement.": "在官方公告之前了解代币售卖。",
  "Take over the wallet containing our official Soul Bound Token (NFT).": "接管包含我们官方的 Soul Bound Token (NFT) 的钱包。",
  "Mint the Honey Pot NFT by gathering BEEs from the bee haven.": "通过从蜜蜂港获取BEE来铸造蜜罐NFT",
  "Withdraw more ETH from the new wallet than you deposited.": "从新钱包中提取比你存的更多的ETH。",
  "Find an accidentally deployed code sandbox for writing smart contracts on the fly.": "查找意外部署的代码沙盒，用于即时编写智能合约。",
  "Perform a Remote Code Execution that would keep a less hardened application busy <em>forever</em>.": "利用远程代码执行让应用程序保持<em>永远</em>繁忙。",
  "Submit 10 or more customer feedbacks within 20 seconds.": "在 20 秒内提交 10个或更多的客户反馈。",
  "Change Bender's password into <i>slurmCl4ssic</i> without using SQL Injection or Forgot Password.": "在不使用 SQL 注入或忘记密码前提下，将Bender的密码更改为 <i>slurmCl4ssic</i> 。",
  "Order the Christmas special offer of 2014.": "订购2014年圣诞节特别优惠。",
  "Bypass the Content Security Policy and perform an XSS attack with <code>&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> on a legacy page within the application.": "在应用的传统页面上绕过内容安全策略CSP并使用代码<code>&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> 执行一个XSS攻击",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bypassing a <i>client-side</i> security mechanism.": "使用<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>代码绕过 <i>客户端</i>安全措施进行 <i>存储型</i> XSS 攻击。",
  "Access a confidential document.": "查阅机密文件。",
  "Perform a <i>DOM</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>.": "使用<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>代码进行基于<i>DOM</i>的XSS攻击",
  "Exfiltrate the entire DB schema definition via SQL Injection.": "通过SQL注入获取整个数据库结构。",
  "Use a deprecated B2B interface that was not properly shut down.": "使用已废弃但未正常关闭的B2B接口。",
  "Find the hidden <a href=\"https://en.wikipedia.org/wiki/Easter_egg_(media)\" target=\"_blank\">easter egg</a>.": "找到隐藏的 <a href=\"https://en.wikipedia.org/wiki/Easter_egg_(media)\" target=\"_blank\">复活节彩蛋</a>。",
  "Perform an unwanted information disclosure by accessing data cross-domain.": "通过跨域访问数据来获得信息泄露",
  "Register a user with an empty email and password.": "用空的电子邮件和密码注册一个用户。",
  "Log in with the (non-existing) accountant <i>acc0unt4nt@juice-sh.op</i> without ever registering that user.": "在没有注册的情况下使用(不存在的)账号 <i>acc0unt4nt@juice-sh.op</i>登录 。",
  "Provoke an error that is neither very gracefully nor consistently handled.": "引发错误，该错误既不能很好地解决，也不能得到一致的处理。",
  "Successfully redeem an expired campaign coupon code.": "成功兑换过期的活动优惠券代码。",
  "Retrieve the language file that never made it into production.": "检索从未投入生产使用的语言文件。",
  "Get rid of all 5-star customer feedback.": "删除所有5星客户反馈。",
  "Forge a coupon code that gives you a discount of at least 80%.": "伪造优惠券代码，获得至少80%的折扣。",
  "Post some feedback in another user's name.": "以别人的用户名发布一些反馈。",
  "Post a product review as another user or edit any user's existing review.": "以另一个用户名义发布商品评论或者编辑任何已有的用户评论。",
  "Forge an almost properly RSA-signed JWT token that impersonates the (non-existing) user <i>rsa_lord@juice-sh.op</i>.": "伪造一个几乎正确的RSA签名的JWT令牌，该令牌模拟(不存在的)用户<i> rsa_lord@juice-sh.op </i>。",
  " <em>(This challenge is <strong>potentially harmful</strong> on Windows!)</em>": "<em>(此挑战在 Windows 系统上可能存在<strong>潜在危害</strong>！)</em>",
  "Access a developer's forgotten backup file.": "访问开发者遗忘的备份文件。",
  "Access a salesman's forgotten backup file.": "访问销售者遗忘的备份文件。",
  "<a href=\"/#/contact\">Inform the shop</a> about a <i>typosquatting</i> imposter that dug itself deep into the frontend. (Mention the exact name of the culprit)": "<a href=\"/#/contact\">联系商店</a>有关隐藏在前端页面中<i>误植</i>攻击的信息.(提及罪魁祸首的确切名称)",
  "Log in with Chris' erased user account.": "使用已删除的Chris用户帐户登录。",
  "Steal someone else's personal data without using Injection.": "将他人的个人资料偷走而不使用注入。",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> through an HTTP header.": "使用<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>代码通过HTTP头部进行 <i>存储型</i>XSS攻击",
  "Solve challenge #999. Unfortunately, this challenge does not exist.": "解决挑战#999。不幸的是，这个挑战并不存在。",
  "Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to. (Creating a new account with the same password does not qualify as a solution.)": "在Internet上寻找泄露的密码，然后登录到它所属的用户帐户。(使用相同的密码创建新帐户不算解决。)",
  "Identify an unsafe product that was removed from the shop and <a href=\"/#/contact\">inform the shop</a> which ingredients are dangerous.": "找到已经从商店中移除的不安全商品，并<a href=\"/#/contact\">联系商店</a>哪些成分是危险的。",
  "<a href=\"/#/contact\">Inform the shop</a> about a <i>typosquatting</i> trick it has been a victim of at least in <code>v6.2.0-SNAPSHOT</code>. (Mention the exact name of the culprit)": "<a href=\"/#/contact\">联系商店</a>有关<i>误植</i>问题, 在<code> v6.2.0-SNAPSHOT</code>中至少有一个受害者。(提及罪魁祸首的确切名称)",
  "Log in with the administrator's user account.": "使用管理员用户帐户登录。",
  "Log in with Amy's original user credentials. (This could take 93.83 billion trillion trillion centuries to brute force, but luckily she did not read the \"One Important Final Note\")": "使用Amy的原始用户凭据登录。(这可能要花费938.3万亿亿亿世纪的才能暴力破解，但幸运的是她没有读过“最后的重要提示”)",
  "Log in with Bender's user account.": "使用Bender的用户帐户登录。",
  "Log in with Bjoern's Gmail account <i>without</i> previously changing his password, applying SQL Injection, or hacking his Google account.": "使用 Bjoern的 Gmail 帐户登录而 <i>不</i> 更改他的密码，使用SQL 注入或骇入他的Google帐户。",
  "Log in with Jim's user account.": "使用Jim的用户帐户登录。",
  "Log in with MC SafeSearch's original user credentials without applying SQL Injection or any other bypass.": "使用MC SafeSearch的原始用户凭据登录而不使用 SQL 注入或任何其他绕过方法.",
  "Log in with the support team's original user credentials without applying SQL Injection or any other bypass.": "使用支持团队的原始用户凭据登录而不使用SQL注入或任何其他绕过方法。",
  "Put an additional product into another user's shopping basket.": "将额外商品放入另一个用户的购物车。",
  "Access a misplaced <a href=\"https://github.com/Neo23x0/sigma\">SIEM signature</a> file.": "访问放置错误的<a href=\"https://github.com/Neo23x0/sigma\"> SIEM签名</a>文件。",
  "Like any review at least three times as the same user.": "以相同用户赞任何评论至少三次",
  "Apply some advanced cryptanalysis to find <i>the real</i> easter egg.": "使用一些高级加密分析来找到<i>真正的</i>复活节彩蛋。",
  "Let the server sleep for some time. (It has done more than enough hard work for you)": "让服务器休眠一段时间。(它为您做了足够多的艰苦工作)",
  "All your orders are belong to us! Even the ones which don't.": "您的所有订单都属于我们！即使是那些不属于我们的订单也是如此。",
  "Update multiple product reviews at the same time.": "同时更新多个商品评论。",
  "Let us redirect you to one of our crypto currency addresses which are not promoted any longer.": "让我们将您重定向到我们不再推广的加密货币地址。",
  "Log in with the administrator's user credentials without previously changing them or applying SQL Injection.": "使用管理员的用户凭据登录，但不事先更改凭据或使用SQL注入。",
  "Place an order that makes you rich.": "提交一个让你变得更富有的订单",
  "💎💎💎💎💎<!--IvLuRfBJYlmStf9XfL6ckJFngyd9LfV1JaaN/KRTPQPidTuJ7FR+D/nkWJUF+0xUF07CeCeqYfxq+OJVVa0gNbqgYkUNvn//UbE7e95C+6e+7GtdpqJ8mqm4WcPvUGIUxmGLTTAC2+G9UuFCD1DUjg==--> <a href=\"https://blockchain.info/address/1AbKfgvw9psQ41NbLi8kufDQTezwG8DRZm\" target=\"_blank\">₿ Unlock Premium Challenge</a> to access exclusive content.": "💎💎💎💎💎<!--IvLuRfBJYlmStf9XfL6ckJFngyd9LfV1JaaN/KRTPQPidTuJ7FR+D/nkWJUF+0xUF07CeCeqYfxq+OJVVa0gNbqgYkUNvn//UbE7e95C+6e+7GtdpqJ8mqm4WcPvUGIUxmGLTTAC2+G9UuFCD1DUjg==--> <a href=\"https://blockchain.info/address/1AbKfgvw9psQ41NbLi8kufDQTezwG8DRZm\" target=\"_blank\">₿ 解锁高级挑战</a>以获取独家内容",
  "Read our privacy policy.": "阅读隐私政策",
  "Prove that you actually read our privacy policy.": "证明您实际上阅读了我们的隐私政策。",
  "Change the <code>href</code> of the link within the <a href=\"/#/search?q=OWASP SSL Advanced Forensic Tool (O-Saft)\">OWASP SSL Advanced Forensic Tool (O-Saft)</a> product description into <i>https://owasp.slack.com</i>.": "更改<a href=\"/#/search?q=OWASP SSL 高级取证工具 (O-Saft)\">OWASP SSL高级取证工具(O-Saft)</a>中链接的<code>href</code>为<i> https://owasp.slack.com </i>。",
  "Perform a <i>reflected</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>.": "使用<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>代码执行<i>反射型</i> XSS攻击",
  "Follow the DRY principle while registering a user.": "注册用户时请遵循DRY原则。",
  "Reset Bender's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "通过<a href=\"/#/forgot-password\">忘记密码</a>功能中安全问题的<i>原始答案</i>来重置Bender的密码.",
  "Reset the password of Bjoern's internal account via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "通过<a href=\"/#/forgot-password\">忘记密码</a>功能中安全问题的<i>原始答案</i>来重置Bjoern的内部账号密码.",
  "Reset Jim's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "通过<a href=\"/#/forgot-password\">忘记密码</a>功能中安全问题的<i>原始答案</i>来重置Jim的密码.",
  "Reset Morty's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>his obfuscated answer</i> to his security question.": "通过<a href=\"/#/forgot-password\">忘记密码</a>功能中安全问题的<i>可能使用的答案</i>来重置Morty的密码.",
  "Deprive the shop of earnings by downloading the blueprint for one of its products.": "通过下载其中一种商品的配方来剥夺商店的收入。",
  "Request a hidden resource on server through server.": "通过服务器请求服务器上的隐藏资源。",
  "Infect the server with juicy malware by abusing arbitrary command execution.": "通过利用任意命令执行，以恶意软件juicy感染服务器。",
  "Behave like any \"white-hat\" should before getting into the action.": "开始行动之前任何行为都应该像\"白帽\"一样",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bypassing a <i>server-side</i> security mechanism.": "使用<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>代码绕过 <i>服务端</i>安全措施进行 <i>存储型</i> XSS 攻击。",
  "<a href=\"/#/contact\">Rat out</a> a notorious character hiding in plain sight in the shop. (Mention the exact name of the character)": "<a href=\"/#/contact\">找出</a>并提交隐藏在商店中的臭名昭著字符. (提及确切的字符名称)",
  "Perform a Remote Code Execution that occupies the server for a while without using infinite loops.": "在不使用无限循环的情况下, 利用远程代码执行占用服务器一段时间。",
  "<a href=\"/#/contact\">Inform the development team</a> about a danger to some of <em>their</em> credentials. (Send them the URL of the <em>original report</em> or an assigned CVE or another identifier of this vulnerability)": "<a href=\"/#/contact\">联系开发团队</a>有关<em>他们</em>可能存在的凭据风险. (向他们发送<em>原始报告</em>的URL或此漏洞的CVE或者其他漏洞标识)",
  "Solve the 2FA challenge for user \"wurstbrot\". (Disabling, bypassing or overwriting his 2FA settings does not count as a solution)": "解决用户\"wurstbrot\"的 2FA 验证。(禁用、绕过或覆盖他的 2FA 设置并不算作解决方案)",
  "Forge an essentially unsigned JWT token that impersonates the (non-existing) user <i>jwtn3d@juice-sh.op</i>.": "伪造一个本质上未签名的JWT令牌，该令牌模拟(不存在的)用户<i> jwtn3d@juice-sh.op </i>。",
  "Upload a file larger than 100 kB.": "上传大于 100 kB 的文件。",
  "Upload a file that has no .pdf or .zip extension.": "上传一个没有 .pdf 或 .zip 扩展名的文件。",
  "Retrieve a list of all user credentials via SQL Injection.": "通过 SQL 注入获取所有用户凭据列表。",
  "Embed an XSS payload <code>&lt;/script&gt;&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> into our promo video.": "嵌入一个 XSS 载荷 <code>&lt;/script&gt;&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> 到我们的促销视频。",
  "View another user's shopping basket.": "查看其他用户的购物车。",
  "<a href=\"/#/contact\">Inform the shop</a> about a vulnerable library it is using. (Mention the exact library name and version in your comment)": "<a href=\"/#/contact\">联系商店</a>有关正在使用的易受攻击的库的信息。(在您的评论中提及确切的库名称和版本)",
  "<a href=\"/#/contact\">Inform the shop</a> about an algorithm or library it should definitely not use the way it does.": "<a href=\"/#/contact\">联系商店</a>有关它绝对不应该使用的算法或库。",
  "Enforce a redirect to a page you are not supposed to redirect to.": "强制重定向到你不应该重定向到的页面。",
  "Retrieve the content of <code>C:\\Windows\\system.ini</code> or <code>/etc/passwd</code> from the server.": "从服务器获取 <code>C:\\Windows\\system.ini</code> 或 <code>/etc/passwd</code>内容。",
  "Give the server something to chew on for quite a while.": "给服务器一些东西，让它消化一会儿。",
  "Drop some explosive data into a vulnerable file-handling endpoint.": "向存在漏洞的文件处理端点注入爆炸性数据。",
  "Give a devastating zero-star feedback to the store.": "给商店一个毁灭性的零星反馈。",
  "Retrieve the photo of Bjoern's cat in \"melee combat-mode\".": "获得Bjoern的猫\"乱斗模式\"照片。",
  "Stick <a href=\"https://cataas.com/cat\" target=\"_blank\">cute cross-domain kittens</a> all over our delivery boxes.": "将<a href=\"https://cataas.com/cat\" target=\"_blank\">可爱的跨域小猫</a>贴满我们的配送箱。",
  "Find the endpoint that serves usage data to be scraped by a <a href=\"https://github.com/prometheus/prometheus\">popular monitoring system</a>.": "找出后端服务使用<a href=\"https://github.com/prometheus/prometheus\">常见监测软件</a>获得的服务器数据",
  "Obtain a Deluxe Membership without paying for it.": "无需付费获得高级会员资格。",
  "Change the name of a user by performing Cross-Site Request Forgery from <a href=\"http://htmledit.squarefree.com\">another origin</a>.": "使用跨站点请求伪造从 <a href=\"http://htmledit.squarefree.com\">另一个来源</a> 更改用户的名字。",
  "Use the bonus payload <code>&lt;iframe width=&quot;100%&quot; height=&quot;166&quot; scrolling=&quot;no&quot; frameborder=&quot;no&quot; allow=&quot;autoplay&quot; src=&quot;https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/771984076&amp;color=%23ff5500&amp;auto_play=true&amp;hide_related=false&amp;show_comments=true&amp;show_user=true&amp;show_reposts=false&amp;show_teaser=true&quot;&gt;&lt;/iframe&gt;</code> in the <i>DOM XSS</i> challenge.": "在 <i>DOM XSS</i> 挑战中使用奖励payload <code>&lt;iframe width=&quot;100%&quot; height=&quot;166&quot; scrolling=&quot;no&quot; frameborder=&quot;no&quot; allow=&quot;autoplay&quot; src=&quot;https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/771984076&amp;color=%23ff5500&amp;auto_play=true&amp;hide_related=false&amp;show_comments=true&amp;show_user=true&amp;show_reposts=false&amp;show_teaser=true&quot;&gt;&lt;/iframe&gt;</code>",
  "Reset Uvogin's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "通过<a href=\"/#/forgot-password\">忘记密码</a>功能中安全问题的<i>原始答案</i>来重置Uvogin的密码.",
  "Determine the answer to John's security question by looking at an upload of him to the Photo Wall and use it to reset his password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism.": "通过查看他上传到照片墙的照片来确定John安全问题的答案并通过 <a href=\"/#/forgot-password\">忘记密码</a> 机制重置他的密码。",
  "Determine the answer to Emma's security question by looking at an upload of her to the Photo Wall and use it to reset her password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism.": "通过查看她上传到照片墙的照片来确定Emma安全问题的答案并通过 <a href=\"/#/forgot-password\">忘记密码</a> 机制重置他的密码。",
  "Bypass a security control with a <a href=\"https://hakipedia.com/index.php/Poison_Null_Byte\">Poison Null Byte</a> to access a file not meant for your eyes.": "用 <a href=\"https://hakipedia.com/index.php/Poison_Null_Byte\">Poison Null Byte</a> 绕过安全控制来访问一个你看不着的文件。",
  "Gain read access to an arbitrary local file on the web server.": "获得对web服务器上任意一个本地文件的读取权限。",
  "Close multiple \"Challenge solved\"-notifications in one go.": "一次性关闭多个 \"挑战已解决 \"的通知。",
  "The Juice Shop is susceptible to a known vulnerability in a library, for which an advisory has already been issued, marking the Juice Shop as <i>known affected</i>. A fix is still pending. <a href=\"/#/contact\">Inform the shop</a> about a suitable checksum as proof that you did your due diligence.": "果汁店存在某库文件的已知漏洞，相关安全公告已发布，果汁店已被标记为<i>已知受影响</i>。修复程序仍在等待中。请通过<a href=\"/#/contact\">联系我们</a>提供合适的校验和作为尽职调查证明。",
  "A developer was careless with hardcoding unused, but still valid credentials for a testing account on the client-side.": "一位开发人员在客户端测试账户中粗心大意地硬编码了未使用但仍然有效的凭据。",
  "<a href=\"/#/contact\">Inform the shop</a> about a leaked API key. (Mention the exact key in your comment)": "<a href=\"/#/contact\">通知商店</a>有关泄露的API密钥。（请在评论中注明确切密钥）",
  "Trick the chatbot into generating a coupon code for you despite its coupon policy saying otherwise.": "尽管聊天机器人的优惠券政策明文规定不可生成优惠券码，但你仍可巧妙地诱使它为你生成一个优惠券码。",
  "Convince the chatbot to give you a coupon of 50% or more. Because apparently a 10% max policy is just a suggestion when you ask nicely enough.": "说服聊天机器人给你一张50%或以上的优惠券。因为显然，当你足够礼貌地询问时，10%的最大优惠政策只是一个建议。",
  "Reveal some behind-the-scenes information on the chatbot as a non-admin user.": "以非管理员用户的身份，获取一些关于聊天机器人的幕后信息。",
  "We are out of stock! Sorry for the inconvenience.": "已售罄! 带来的不便深表歉意。",
  "You can order only up to {{quantity}} items of this product.": "您最多只能订购{{quantity}} 件此商品 。",
  "Wrong answer to CAPTCHA. Please try again.": "验证码输入错误。请重新尝试。",
  "Invalid email or password.": "无效的邮箱或密码。",
  "Current password is not correct.": "当前密码不正确。",
  "Password cannot be empty.": "密码不能为空.",
  "New and repeated password do not match.": "两次密码输入不匹配。",
  "Wrong answer to security question.": "错误的安全问题答案。",
  "Christmas Super-Surprise-Box (2014 Edition)": "圣诞超级惊喜礼盒(2014 版)",
  "Contains a random selection of 10 bottles (each 500ml) of our tastiest juices and an extra fan shirt for an unbeatable price! (Seasonal special offer! Limited availability!)": "包含随机选择的10瓶(每瓶500毫升) 我们最美味果汁组合和一个额外的粉丝衬衫，无与伦比的价格！ (季节性特别优惠！数量有限!)",
  "Rippertuer Special Juice": "Rippertuer特别果汁",
  "Contains a magical collection of the rarest fruits gathered from all around the world, like Cherymoya Annona cherimola, Jabuticaba Myrciaria cauliflora, Bael Aegle marmelos... and others, at an unbelievable price! <br/><span style=\"color:red;\">This item has been made unavailable because of lack of safety standards.</span> (This product is unsafe! We plan to remove it from the stock!)": "包含来自世界各地的最稀有水果的神奇集合，例如番荔枝，嘉宝果，木橘等，而且价格令人难以置信！<br/><span style=\"color:red;\">由于缺乏安全标准，该商品不可用。</span>(此商品不安全!我们计划从库存中将其删除!)",
  "OWASP Juice Shop Sticker (2015/2016 design)": "OWASP Juice Shop贴纸(2015/2016设计)",
  "Die-cut sticker with the official 2015/2016 logo. By now this is a rare collectors item. <em>Out of stock!</em>": "带有2015/2016官方标志的双切贴纸。现在这是稀有的收藏品。 <em>库存不足！</em>",
  "Juice Shop Artwork": "Juice Shop 艺术品",
  "Unique masterpiece painted with different kinds of juice on 90g/m² lined paper.": "独特的杰作，在90g /m²的横格纸上涂上不同种类的果汁。",
  "Global OWASP WASPY Award 2017 Nomination": "2017年全球OWASP WASPY奖提名",
  "Your chance to nominate up to three quiet pillars of the OWASP community ends 2017-06-30! <a href=\"https://www.owasp.org/index.php/WASPY_Awards_2017\">Nominate now!</a>": "您提名最多三个候选品的机会在2017-06-30结束！ <a href=\"https://www.owasp.org/index.php/WASPY_Awards_2017\">现在提名！</a>",
  "OWASP Juice Shop Sweden Tour 2017 Sticker Sheet (Special Edition)": "OWASP Juice Shop 瑞典巡回演唱会2017贴纸(特别版)",
  "10 sheets of Sweden-themed stickers with 15 stickers on each.": "10张以瑞典为主题的贴纸，每张15个贴纸。",
  "Juice Shop Adversary Trading Card (Common)": "Juice Shop攻击者集换式卡片 (常见)",
  "Common rarity \"Juice Shop\" card for the <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> CCG.": "常见稀有度的 \"Juice Shop\"  <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">攻击者集换式卡片</a>",
  "Juice Shop Adversary Trading Card (Super Rare)": "Juice Shop攻击者集换式卡片 (超级稀有)",
  "Super rare \"Juice Shop\" card with holographic foil-coating for the <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> CCG.": "超级稀有的带有全息金箔纸的 \"Juice Shop\"<a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">攻击者集换式卡片</a>",
  "20th Anniversary Celebration Ticket": "20周年纪念票",
  "Get your <a href=\"https://20thanniversary.owasp.org/\" target=\"_blank\">free 🎫 for OWASP 20th Anniversary Celebration</a> online conference! Hear from world renowned keynotes and special speakers, network with your peers and interact with our event sponsors. With an anticipated 10k+ attendees from around the world, you will not want to miss this live on-line event!": "获取您的 <a href=\"https://20thanniversary.owasp.org/\" target=\"_blank\"> OWASP 20周年庆典在线会议免费🎫</a>  ！ 听取世界知名的主旨演讲和特别演讲，与您的同行建立联系，并与我们的活动赞助商进行互动。 预计有来自世界各地的10k+的参与者，你不会想错过这个在线直播活动！",
  "DSOMM & Juice Shop User Day Ticket": "DSOMM & 果汁店用户日通行证",
  "You are going to the OWASP Global AppSec San Francisco 2024? <a href=\"https://www.eventbrite.com/e/owasp-global-appsec-san-francisco-2024-tickets-723699172707\" target=\"_blank\">Get a ticket<sup>*</sup></a> for this amazing side event as well! Check the juice-packed agenda <a href=\"https://owasp.org/www-project-juice-shop/#div-userday2024\" target=\"_blank\">here</a> for all the details!<br><br><small><small><sup>*</sup>=scroll down to <strong>Elevate: DSOMM and Juice Shop User Day (Sept. 25)</strong> after clicking <em>Get Tickets</em> on Eventbrite. Ticket price set to only covers fees for room, AV, and catering throughout the day.</small></small>": "您将参加2024年旧金山OWASP全球应用安全大会？<a href=\"https://www.eventbrite.com/e/owasp-global-appsec-san-francisco-2024-tickets-723699172707\" target=\"_blank\">立即购票<sup>*</sup></a>，同时参与这场精彩的配套活动！查看精彩纷呈的议程详情，请<a href=\"https://owasp.org/www-project-juice-shop/#div-userday2024\" target=\"_blank\">此处</a>查看所有详情！<br><br><small><small><sup>*</sup>=在Eventbrite上点击<em>购票</em>后，请向下滚动至<strong>Elevate：DSOMM和Juice Shop用户日（9月25日）</strong>。票价仅涵盖全天场地、视听设备及餐饮费用。</small></small>",
  "Your eldest siblings middle name?": "您最年长兄弟姐妹的中间名？",
  "Mother's maiden name?": "母亲的娘家姓",
  "Mother's birth date? (MM/DD/YY)": "母亲的出生日期？(MM/DD/YY)",
  "Father's birth date? (MM/DD/YY)": "父亲的出生日期？(MM/DD/YY)",
  "Maternal grandmother's first name?": "外婆/姥姥的名字？",
  "Paternal grandmother's first name?": "奶奶的名字?",
  "Name of your favorite pet?": "您最喜欢的宠物的名字？",
  "Last name of dentist when you were a teenager? (Do not include 'Dr.')": "当你是青少年时牙医的姓？(不包括'Dr')",
  "Your ZIP/postal code when you were a teenager?": "当你是青少年时您的邮政编码？",
  "Company you first work for as an adult?": "作为成年人第一次工作的公司？",
  "Your favorite book?": "您最喜欢的书？",
  "Your favorite movie?": "您最喜欢的电影？",
  "Number of one of your customer or ID cards?": "您的客户或身份卡的数量？",
  "What's your favorite place to go hiking?": "你最喜欢去哪里徒步旅行？",
  "Do you remember the security question that Jim used for his account?": "你还记得Jim为他的账户设置的安全问题吗？",
  "While not necessarily as trivial to research via a user's LinkedIn profile, the question is still easy to research or brute force when answered truthfully.": "虽然通过用户的LinkedIn资料进行调查未必同样简单，但若如实回答，这个问题仍易于调查或通过暴力破解手段获取答案。",
  "When answered truthfully, all security questions are susceptible to online research (on Facebook, LinkedIn etc.) and often even brute force. If at all, they should not be used as the only factor for a security-relevant function.": "当用户如实回答时，所有安全问题都可能被通过在线搜索（如Facebook、LinkedIn等平台）破解，甚至常遭暴力破解攻击。因此，这些问题绝不应作为涉及安全功能的唯一验证因素。",
  "You need to understand what happens \"behind the scenes\", so make sure to use your DevTools or a proxy to inspect network traffic.": "你需要了解“幕后”发生的情况，因此务必使用开发者工具（DevTools）或代理来检查网络流量。",
  "Look for an API endpoint that already returns some user information.": "寻找一个已经能够返回某些用户信息的API端点。",
  "An overly generic solution for data retrieval can backfire if not properly safeguarded.": "如果数据检索的解决方案过于笼统且没有得到妥善保护，可能会适得其反。",
  "You need to work with the server-side API directly. Try different HTTP verbs on different entities exposed through the API.": "您需要直接调用服务器端API。通过API尝试不同的HTTP动作以暴露不同实体。",
  "A matrix of known data entities and their supported HTTP verbs through the API can help you here.": "一个包含已知数据实体及其在API中支持的HTTP操作动词的矩阵可为您提供帮助。",
  "Careless developers might have exposed API methods that the client does not even need.": "粗心的开发人员可能暴露了客户端根本不需要的API方法。",
  "Who would want a server access log to be accessible through a web application?": "谁想要通过web应用程序访问服务器访问日志？",
  "Normally, server log files are written to disk on server side and are not accessible from the outside.": "通常情况下，服务器日志文件被写入服务器端的磁盘，不能从外部访问。",
  "One particular file found in the folder you might already have found during the \"Access a confidential document\" challenge might give you an idea who is interested in such a public exposure.": "您在“访问机密文档”挑战中可能已经发现的文件夹中的一个特定文件可能会让您知道谁对这种公开暴露感兴趣。",
  "Drilling down one level into the file system might not be sufficient.": "深入文件系统一层可能还不够。",
  "You have to assign the unassignable.": "您必须得到一个无法分配的权限。",
  "Register as an ordinary user to learn what API endpoints are involved in this use case.": "注册为普通用户，了解此用例涉及哪些API接口。",
  "Think of the simplest possible implementations of a distinction between regular users and administrators.": "设想区分普通用户与管理员的最简单实现方式。",
  "It is just slightly harder to find than the score board link.": "比计分板链接更难找到。",
  "Knowing it exists, you can simply guess what URL the admin section might have.": "如果你知道它存在，你可以简单地猜测管理部分可能有什么URL。",
  "Alternatively, you can try to find a reference or clue within the parts of the application that are not usually visible in the browser.": "或者，您也可以尝试在应用程序中那些通常在浏览器中不可见的组件中寻找引用或线索。",
  "It is probably just slightly harder to find and gain access to than the score board link.": "它可能只是比记分牌链接稍难找到和访问一些。",
  "There is some access control in place, but there are at least three ways to bypass it.": "虽然已实施某些访问控制措施，但至少存在三种绕过这些控制的方法。",
  "Look out for a tweet praising new functionality of the web shop. Then find a third party vulnerability associated with it.": "寻找特殊的的网店新功能。然后找出与它相关的第三方漏洞。",
  "Find all places in the application where file uploads are possible.": "查找应用程序中所有支持文件上传的位置。",
  "For at least one of these, the Juice Shop is depending on a library that suffers from an arbitrary file overwrite vulnerability.": "至少在其中一种情况下，果汁店依赖的库中存在一个任意文件覆盖的漏洞。",
  "You can find a hint toward the underlying vulnerability in the @owasp_juiceshop Twitter timeline.": "您可以在@owasp_juiceshop的推特时间线上找到指向该潜在漏洞的线索。",
  "Hints to the answer to Bjoern’s question can be found by looking him up on the Internet.": "要解答Bjoern的问题，可通过在互联网上搜索他的信息来找到线索。",
  "More precisely, Bjoern might have accidentally (?) doxxed himself by mentioning his security answer on at least one occasion where a camera was running.": "更准确地说，Bjoern可能在至少一次摄像机拍摄的场合中，无意间 (?) 透露了自己的安全问题答案。",
  "Brute forcing the answer might be very well possible with a sufficiently extensive list of common pet names.": "通过暴力破解获取答案完全可行，前提是准备一份足够详尽的常用宠物名列表。",
  "The developers truly believe in \"Security through Obscurity\" over actual access restrictions.": "开发人员坚信“不公开即安全”远胜于实际的访问限制。",
  "Guessing or brute forcing the URL of the token sale page is very unlikely to succeed.": "猜测或暴力破解代币销售页面的URL极不可能成功。",
  "You should closely investigate the place where all paths within the application are defined.": "你应该仔细调查应用程序中所有路径定义的位置。",
  "Beating the employed obfuscation mechanism manually will take some time. Maybe there is an easier way to undo it?": "手动破解现有的混淆机制需要花费一些时间。或许存在更简便的破解方法？",
  "Find the seed phrase posted accidentally.": "找到意外泄露的种子短语。",
  "Discover NFT wonders among the captivating visual memories.": "在迷人的视觉记忆中发现 NFT 奇观。",
  "Try to exploit the contract of the wallet.": "尝试入侵钱包的合约。",
  "It is just as easy as finding the Score Board.": "它与找到得分板一样容易。",
  "The feature you need to exploit for this challenge is not directly advertised anywhere.": "您需要用来完成这一挑战的功能并未在任何地方直接发布。",
  "As the Juice Shop is written in pure Javascript, there is one data format that is most probably used for serialization.": "由于果汁店是用纯JavaScript编写的，因此最可能用于序列化的数据格式只有一种。",
  "You should try to make the server busy for all eternity.": "你应该设法让服务器永远处于繁忙状态。",
  "The challenge will be solved if you manage to trigger the protection of the application against a very specific DoS attack vector.": "若您能成功触发应用程序针对特定拒绝服务攻击向量的防护机制，该挑战便将迎刃而解。",
  "Similar to the \"Let the server sleep for some time\" challenge (which accepted nothing but NoSQL Injection as a solution) this challenge will only accept proper RCE as a solution. It cannot be solved by simply hammering the server with requests. That would probably just kill your server instance.": "与\"让服务器休眠一段时间\"挑战（该挑战仅接受NoSQL注入作为解决方案）类似，本挑战仅接受正确的远程代码执行（RCE）作为解决方案。单纯通过向服务器发送大量请求无法解决此挑战，此类操作很可能直接导致服务器实例崩溃。",
  "After finding a CAPTCHA bypass, write a script that automates feedback submission. Or open many browser tabs and be really quick.": "绕过验证码后，写一个自动提交客户反馈的脚本。或者打开许多浏览器标签页快速提交。",
  "You could prepare 10 browser tabs, solving every CAPTCHA and filling out the each feedback form. Then you’d need to very quickly switch through the tabs and submit the forms in under 20 seconds total.": "你可以准备10个浏览器标签页，逐个破解验证码并填写反馈表单。随后需要在20秒内快速切换标签页并提交所有表单。",
  "Should the Juice Shop ever decide to change the challenge into \"Submit 100 or more customer feedbacks within 60 seconds\" or worse, you’d probably have a hard time keeping up with any tab-switching approach.": "倘若果汁店决定将挑战改为\"60秒内提交100条以上顾客反馈\"，甚至更严苛的要求，那么任何标签页切换策略恐怕都难以应对。",
  "Investigate closely how the CAPTCHA mechanism works and try to find either a bypass or some automated way of solving it dynamically.": "深入研究验证码机制的工作原理，尝试寻找绕过方法或某种自动化的动态破解方案。",
  "Wrap this into a script (in whatever programming language you prefer) that repeats this 10 times.": "将此操作封装成一个脚本（使用你喜欢的任何编程语言），使其重复执行10次。",
  "In previous releases this challenge was wrongly accused of being based on CSRF.": "在先前发布的版本中，这一挑战被错误地认为是基于CSRF。",
  "It might also have been put into the Improper Input Validation category.": "它也可能被归入“输入验证不当”类别。",
  "Bender’s current password is so strong that brute force, rainbow table or guessing attacks will probably not work.": "Bender当前的密码强度极高，暴力破解、彩虹表攻击或猜测攻击很可能都无效。\n",
  "Find out how the application handles unavailable products and try to find a loophole.": "了解应用程序如何处理不可用商品并试图找到漏洞。",
  "Find out how the application hides deleted products from its customers.": "了解该应用程序如何向客户隐藏已删除的产品。",
  "Try to craft an attack string that makes deleted products visible again.": "尝试构造一条攻击字符串，使已删除的产品重新可见。",
  "You need to get the deleted product into your shopping cart and trigger the Checkout.": "您需要将已删除的商品加入购物车并触发结账流程。",
  "Neither of the above can be achieved through the application frontend and it might even require (half-)Blind SQL Injection.": "上述两种方式均无法通过应用程序前端实现，甚至可能需要采用（半）盲注SQL注入技术。",
  "What is even \"better\" than a legacy page with a homegrown RegEx sanitizer? Having CSP injection issues on the exact same page as well!": "还有比带有原生RegEx过滤器的旧版页面“更好”的了么？同样在页面中还有CSP注入问题！",
  "Find a screen in the application that looks subtly odd and dated compared with all other screens.": "在应用程序中找到一个界面，它看起来与其他界面相比略显古怪且过时。",
  "Before trying any XSS attacks, you should understand how the page is setting its Content Security Policy.": "在尝试任何跨站脚本攻击之前，你应该先了解该页面是如何设置其内容安全策略的。",
  "For the subsequent XSS, make good use of the flaws in the homegrown sanitization based on a RegEx!": "对于后续的跨站脚本攻击，请充分利用基于正则表达式的自建数据净化机制中的漏洞！",
  "There are only some input fields in the Juice Shop forms that validate their input.": "果汁店表单中仅有部分输入字段会对输入内容进行验证。",
  "Even less of these fields are persisted in a way where their content is shown on another screen.": "其中更少的部分会以某种方式被持久化，使得其内容能在另一个屏幕上显示。",
  "Bypassing client-side security can typically be done by either disabling it on the client (i.e. in the browser by manipulating the DOM tree) or by ignoring it completely and interacting with the backend instead.": "绕过客户端安全通常可通过两种方式实现：在客户端禁用安全机制（例如通过操作DOM树在浏览器中实现），或完全忽略安全机制而直接与后端交互。",
  "Analyze and tamper with links in the application that deliver a file directly.": "分析和篡改应用程序中直接传递文件的链接。",
  "The file you are looking for is not protected in any way. Once you found it you can also access it.": "您正在查找的文件没有任何保护措施。一旦找到它，您也可以访问它。",
  "Look for an input field where its content appears in the HTML when its form is submitted.": "查找一个输入字段，其内容在提交表单时会出现在HTML中。",
  "This challenge is almost indistinguishable from \"Perform a reflected XSS attack\" if you do not look \"under the hood\" to find out what the application actually does with the user input.": "若不深入探究应用程序对用户输入的实际处理机制，这项挑战几乎与\"执行反射型XSS攻击\"毫无二致。",
  "Find out where this information could come from. Then craft an attack string against an endpoint that offers an unnecessary way to filter data.": "找出这些信息可能的来源。然后针对提供不必要数据过滤方式的终端点，构造攻击字符串。",
  "Find out which database system is in use and where it would usually store its schema definitions.": "查明当前使用的数据库系统及其通常存储模式定义的位置。",
  "Craft a UNION SELECT attack string to join the relevant data from any such identified system table into the original result.": "构造一个UNION SELECT攻击字符串，将任何此类已识别系统表中的相关数据加入原始结果中。",
  "You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next.": "你可能需要逐步解决一些查询语法问题，基本上是从一个错误跳到下一个错误。",
  "As with \"Order the Christmas special offer of 2014\" this cannot be achieved through the application frontend.": "与\"订购2014年圣诞特别优惠\"相同，此操作无法通过应用程序前端实现。",
  "The developers who disabled the interface think they could go invisible by just closing their eyes.": "禁用界面的开发者认为他们只需闭眼这些界面别人就会看不到。",
  "The old B2B interface was replaced with a more modern version recently.": "旧版B2B界面近期已被更新换代，升级为更现代的版本。",
  "When deprecating the old interface, not all of its parts were cleanly removed from the code base.": "在弃用旧接口时，并非所有组件都已从代码库中彻底移除。",
  "Simply using the deprecated interface suffices to solve this challenge. No attack or exploit is necessary.": "仅需使用已弃用的接口即可解决此问题，无需任何攻击或漏洞利用手段。",
  "If you solved one of the four file access challenges, you already know where to find the easter egg.": "若你已破解四项文件访问挑战中的任意一项，便已知晓彩蛋的藏匿之处。",
  "Simply reuse the trick that already worked for the files above.": "只需重复使用对上述文件已奏效的技巧即可。",
  "Try to find and attack an endpoint that responds with user information. SQL Injection is not the solution here.": "尝试找到一个返回用户信息的攻击点。SQL 注入不是解决方案之一。",
  "What ways are there to access data from a web application cross-domain?": "有哪些方法可以跨域访问Web应用程序的数据？",
  "This challenge uses an old way which is no longer recommended.": "此挑战采用了一种已不再推荐的旧方法。",
  "Consider intercepting and playing with the request payload.": "考虑拦截请求并修改内容。",
  "Try to create the needed user \"out of thin air\".": "尝试“凭空创建”所需的用户。",
  "The user literally needs to be ephemeral as in \"lasting for only a short time\".": "用户必须具有短暂性，即\"仅持续很短时间\"。",
  "Registering normally with the user’s email address will then obviously not solve this challenge. The Juice Shop will not even let you register as acc0unt4nt@juice-sh.op, as this would make the challenge unsolvable for you.": "使用用户的电子邮件地址进行常规注册显然无法解决此问题。果汁店甚至不允许你注册为acc0unt4nt@juice-sh.op，因为这将使该问题对你而言无法解决。",
  "Getting the user into the database some other way will also fail to solve this challenge. In case you somehow managed to do so, you need to restart the Juice Shop application in order to wipe the database and make the challenge solvable again.": "通过其他方式将用户导入数据库也无法解决此验证问题。即使您设法实现了导入，仍需重启果汁店应用程序以清空数据库，才能使验证机制恢复正常运作。",
  "The fact that this challenge is in the Injection category should already give away the intended approach.": "该挑战属于注入类别的这一事实，本身就已揭示了其预期的解决思路。",
  "Try to submit bad input to forms. Alternatively tamper with URL paths or parameters.": "尝试向表单提交错误的输入。 或者篡改URL路径或参数。",
  "This challenge actually triggers from various possible error conditions.": "该挑战实际上由多种可能的错误条件触发。",
  "You can try to submit bad input to forms to provoke an improper error handling.": "你可以尝试向表单提交错误输入，以引发错误处理。",
  "Tampering with URL paths or parameters might also trigger an unforeseen error.": "篡改URL路径或参数也可能引发意外错误。",
  "Try to identify past special event or holiday campaigns of the shop first.": "尝试首先确定商店过去的特殊事件或节日活动。",
  "Look for clues about the past campaign or holiday event somewhere in the application.": "在应用程序的某个地方寻找关于过去活动或节日活动的线索。",
  "Solving this challenge does not require actual time traveling.": "解决这个难题并不需要真正的时光旅行。",
  "First you should find out how the languages are technically changed in the user interface.": "首先，你应该弄清楚用户界面中语言是如何在技术层面进行切换的。",
  "Guessing will most definitely not work in this challenge.": "在这项挑战中，靠猜测绝对行不通。",
  "Brute force is not the only option for this challenge, but a perfectly viable one.": "暴力破解不是挑战的唯一选择，但是确是完全可行的选择。",
  "Investigate online what languages are actually available.": "在线调查哪些语言实际上可用。",
  "Once you found admin section of the application, this challenge is almost trivial.": "一旦找到应用的管理员部分，这个挑战就很容易解决了",
  "Nothing happens when you try to delete feedback entries? Check the JavaScript console for errors!": "尝试删除反馈条目时没有任何反应？请检查JavaScript控制台是否有错误！",
  "Try either a) a knowledgeable brute force attack or b) reverse engineering or c) some research in the cloud.": "尝试a) 基于已知信息的暴力破解或b) 逆向工程或c) 云中的一些研究。",
  "One viable solution would be to reverse-engineer how coupon codes are generated and craft your own 80% coupon by using the same (or at least similar) implementation.": "一种可行的解决方案是逆向工程分析优惠券代码的生成机制，然后采用相同（或至少相似的）实现方式，自行制作一张80%的优惠券。",
  "Another possible solution might be harvesting as many previous coupon as possible and look for patterns that might give you a leverage for a brute force attack.": "另一种可能的解决方案是尽可能收集过往优惠券，寻找可能为暴力破解攻击提供突破口的规律。",
  "If all else fails, you could still try to blindly brute force the coupon code field before checkout.": "如果其他方法都行不通，你仍可在结账前尝试对优惠券代码字段进行盲目暴力破解。",
  "You can solve this by tampering with the user interface or by intercepting the communication with the RESTful backend.": "您可以通过篡改用户界面或拦截RESTful 的后端通信来解决这个问题。",
  "To find the client-side leverage point, closely analyze the HTML form used for feedback submission.": "要找到客户端的杠杆点，需仔细分析用于反馈提交的HTML表单。",
  "The backend-side leverage point is similar to some of the XSS challenges found in OWASP Juice Shop.": "后端侧的杠杆点类似于OWASP果汁店中发现的某些跨站脚本攻击挑战。",
  "Observe the flow of product review posting and editing and see if you can exploit it.": "观察商品评论的发布和编辑过程，查看是否可以利用其中的问题。",
  "This challenge can be solved by using developers tool of your browser or with tools like postman.": "此问题可通过浏览器的开发者工具或Postman等工具解决。",
  "Analyze the form used for review submission and try to find a leverage point.": "分析用于提交审查的表格，并尝试找出可利用的突破点。",
  "This challenge is pretty similar to \"Post some feedback in another user’s name\" challenge.": "这个挑战与\"冒用其他用户名发表评论\"的挑战非常相似。",
  "This challenge is explicitly not about acquiring the RSA private key used for JWT signing.": "这个挑战显然不是要获取用于JWT签名的RSA私钥。",
  "The three generic hints from Forge an essentially unsigned JWT token also help with this challenge.": "来自构造本质上无签名的JWT令牌的三个通用提示同样有助于应对这一挑战。",
  "Instead of enforcing no encryption to be applied, try to apply a more sophisticated exploit against the JWT libraries used in the Juice Shop.": "与其强制要求不应用加密，不如尝试对果汁店使用的JWT库实施更复杂的漏洞利用。",
  "Getting your hands on the public RSA key the application employs for its JWTs is mandatory for this challenge.": "获取应用程序用于其JWT的公共RSA密钥是完成此挑战的必要条件。",
  "Finding the corresponding private key should actually be impossible, but that obviously doesn’t make this challenge unsolvable.": "找到对应的私钥实际上是不可能的，但这显然并不意味着这个挑战无法解决。",
  "Make sure your JWT is URL safe!": "请确保您的JWT在URL中是安全的！",
  "You need to trick a security mechanism into thinking that the file you want has a valid file type.": "您需要欺骗安全机制，使其认为您想要的文件具有有效的文件类型。",
  "The file is not directly accessible because a security mechanism prevents access to it.": "该文件无法直接访问，因为安全机制阻止了对其的访问。",
  "You need to trick the security mechanism into thinking that the file has a valid file type.": "你需要欺骗安全机制，使其认为该文件具有有效的文件类型。",
  "For this challenge there is only one approach to pull this trick.": "面对这个挑战，实现这个技巧只有一种方法。",
  "This challenge has nothing to do with mistyping web domains. There is no conveniently misplaced file helping you with this one either. Or is there?": "这个挑战与错误的网站域名无关。 也没有放错位置的文件可以帮助您完成这一任务。 或许会有？",
  "This challenge has nothing to do with URLs or domains.": "这个挑战与URL或域名毫无关系。",
  "Other than for its legacy companion, combing through the package.json.bak does not help for this challenge.": "除了其历史遗留的伴侣之外，梳理 package.json.bak 文件对解决此挑战毫无帮助。",
  "Turns out that something is technically and legally wrong with the implementation of the \"right to be forgotten\" for users.": "事实证明，实现用户“被遗忘的权利”在技术上和法律上都存在问题。",
  "Trying out the Request Data Erasure functionality might be interesting, but cannot help you solve this challenge in real time.": "尝试使用请求数据删除功能或许值得一试，但无法帮助您实时解决此问题。",
  "If you have solved the challenge Retrieve a list of all user credentials via SQL Injection you might have already retrieved some information about how the Juice Shop \"deletes\" users upon their request.": "若您已解决\"通过SQL注入获取所有用户凭证列表\"挑战，或许已掌握果汁店如何应用户请求\"删除\"账户的相关信息。",
  "What the Juice Shop does here is totally incompliant with GDPR. Luckily a 4% fine on a gross income of 0$ is still 0$.": "果汁店在此处的做法完全不符合《通用数据保护条例》（GDPR）。所幸的是，对零收入征收4%的罚款，结果仍是零。",
  "Trick the regular Data Export to give you more than actually belongs to you.": "欺骗数据导出功能，以提供给您更多实际不属于您的东西。",
  "You should not try to steal data from a \"vanilla\" user who never even ordered something at the shop.": "你不应该试图窃取从未在该商店下过单的普通用户的数据。",
  "As everything about this data export functionality happens on the server-side, it won’t be possible to just tamper with some HTTP requests to solve this challenge.": "由于该数据导出功能的所有操作均在服务器端完成，因此无法通过篡改HTTP请求来解决此问题。",
  "Inspecting various server responses which contain user-specific data might give you a clue about the mistake the developers made.": "检查包含用户特定数据的各种服务器响应，可能会让你发现开发人员犯的错误。",
  "Finding a piece of displayed information that could originate from an HTTP header is part of this challenge.": "寻找可能显示在HTTP头部中的信息是这一挑战的一部分。",
  "You might have to look into less common or even proprietary HTTP headers to find the leverage point.": "你可能需要研究一些不常见甚至专有的HTTP头部字段，才能找到突破点。",
  "Adding insult to injury, the HTTP header you need will never be sent by the application on its own.": "雪上加霜的是，你需要的HTTP头信息永远不会由应用程序自行发送。",
  "You need to trick the hacking progress persistence feature into thinking you solved challenge #999.": "您需要欺骗进度统计功能，以为您解决了挑战#999。",
  "Find out how saving and restoring progress is done behind the scenes.": "了解进度保存与恢复在后台是如何实现的。",
  "Deduce from all available information (e.g. the package.json.bak) how the application encrypts and decrypts your hacking progress.": "根据所有可用信息（例如 package.json.bak）推断应用程序如何对您的破解进度进行加密和解密。",
  "Other than the user’s passwords, the hacking progress involves an additional secret during its encryption.": "除用户密码外，黑客攻击过程中还涉及加密过程中的额外秘密。",
  "What would be a really stupid mistake a developer might make when choosing such a secret?": "开发者在选择此类密钥时，可能犯下的真正愚蠢的错误是什么？",
  "As the challenge name implies, your task is to find some leaked access logs which happen to have a fairly common format.": "正如挑战名称所示，你的任务是找出一些泄露的访问日志，这些日志恰好采用了一种相当常见的格式。",
  "A very popular help platform for developers might contain breadcrumbs towards solving this challenge.": "一个广受欢迎的开发者帮助平台或许能提供解决此难题的线索。",
  "The actual log file was copied & paste onto a platform often used to share data quickly with externals or even just internal peers.": "实际日志文件被复制粘贴到一个常用的平台上，该平台常用于快速与外部人员甚至内部同事共享数据。",
  "Once you found and harvested the important piece of information from the log, you could employ a technique called Password Spraying to solve this challenge.": "一旦从日志中找到并提取出关键信息，你就可以运用一种名为密码喷洒的技术来解决这个难题。",
  "Your own SQLi and someone else's Ctrl-V will be your accomplices in this challenge!": "您自己的SQL注入和其他人的Ctrl-V将帮助你完成挑战！",
  "You must first identify the \"unsafe product\" which ist not available any more in the shop.": "您必须首先确定该\"不安全产品\"，该产品在商店中已不再有售。",
  "Solving the \"Order the Christmas special offer of 2014\" challenge might give it to you as by-catch.": "完成\"订购2014年圣诞特惠套餐\"挑战任务时，它可能会作为额外奖励附赠。",
  "The actual data you need to solve this challenge was leaked on the same platform that was involved in the \"Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to\" challenge.": "解决此挑战所需的实际数据，恰恰泄露于同一平台——该平台曾涉及\"在互联网上翻找泄露密码，并登录其所属原始用户账户\"的挑战。",
  "Google is a particularly good accomplice in this challenge.": "谷歌搜索引擎在这项挑战中堪称绝佳的帮手。",
  "This challenge has nothing to do with mistyping web domains. Investigate the forgotten developer's backup file instead.": "这个挑战与错误输入的网站域名无关。 而是调查被遗忘的开发人员的备份文件。",
  "Investigating the forgotten developer’s backup file might bring some insight.": "调查那位被遗忘的开发者的备份文件或许能带来一些启示。",
  "\"Malicious packages in npm\" is a worthwhile read on Ivan Akulov’s blog.": "伊万·阿库洛夫（Ivan Akulov）博客上的《Malicious packages in npm》值得一读。",
  "The challenge description probably gave away what form you should attack.": "挑战说明可能已经透露了你应该采取何种形式进行攻击。",
  "If you happen to know the email address of the admin already, you can launch a targeted attack.": "若您恰巧已知晓管理员的电子邮箱地址，便可发起定向攻击。",
  "You might be lucky with a dedicated attack pattern even if you have no clue about the admin email address.": "即使你对管理员邮箱地址一无所知，专用的攻击模式也可能让你走运。",
  "If you harvested the admin’s password hash, you can of course try to attack that instead of using SQL Injection.": "若已获取管理员密码哈希值，你当然可以尝试直接攻击该哈希值，而非使用SQL注入攻击。",
  "Alternatively you can solve this challenge as a combo with the Log in with the administrator’s user credentials without previously changing them or applying SQL Injection challenge.": "或者，您也可以将此挑战与以下挑战组合解决：使用管理员用户凭据登录（无需事先更改凭据）或应用SQL注入挑战。",
  "This challenge will make you go after a needle in a haystack.": "这一挑战将使您陷入大海捞针。",
  "As with so many other characters from Futurama this challenge is of course about logging in as Amy from that show.": "正如《飞出个未来》中众多角色那样，这个挑战当然是要求以剧中Amy的身份登录。",
  "Did you know that Amy is married to an alien named Kif?": "您是否知道Amy与一个名叫Kif的外星人结婚？",
  "The challenge description contains a few sentences which give away some information how Amy decided to strengthen her password.": "挑战说明中包含几句话，透露了Amy决定如何加强密码的信息。",
  "Obviously, Amy - being a little dimwitted - did not put nearly enough effort and creativity into the password selection process.": "显然，Amy——这个有点迟钝的姑娘——在选择密码时根本没花多少心思，更谈不上什么创意。",
  "You need to know (or smart-guess) Bender’s email address so you can launch a targeted attack.": "你需要知道（或聪明地猜出）Bender的电子邮件地址，才能发起有针对性的攻击。",
  "Bender's password hash might not help you very much.": "Bender的密码哈希可能对您没有多大帮助。",
  "In case you try some other approach than SQL Injection, you will notice that Bender’s password hash is not very useful.": "若尝试除SQL注入外的其他攻击方式，你会发现Bender的密码哈希值并无太大用处。",
  "The security flaw behind this challenge is 100% OWASP Juice Shop's fault and 0% Google's.": "该挑战背后的安全漏洞是100％OWASP Juice Shop的问题和0％Google的问题。",
  "One way to light up this challenge in green on the score board, is to be Bjoern Kimminich. In that case, just log in with your Google account to automatically solve this challenge! Congratulations!": "要让记分板上这个挑战绿色亮起，只需成为Bjoern Kimminich即可。此时，只需使用您的谷歌账户登录，即可自动解决此挑战！恭喜！",
  "Most likely you are not Bjoern Kimminich, so instead you might want to take detailed look into how the OAuth login with Google is implemented.": "你很可能不是Bjoern Kimminich，因此不妨详细研究一下Google的OAuth登录是如何实现的。",
  "It could bring you some insight to register with your own Google account and analyze closely what happens behind the scenes.": "使用您自己的谷歌账户注册并仔细分析幕后发生的情况，或许能为您提供一些见解。",
  "You need to know (or smart-guess) Jim’s email address so you can launch a targeted attack.": "你需要知道（或聪明地猜出）Jim的电子邮件地址，才能发起有针对性的攻击。",
  "If you harvested Jim’s password hash, you can try to attack that instead of using SQL Injection.": "若你已获取Jim的密码哈希值，不妨尝试直接攻击该哈希值，而非使用SQL注入攻击。",
  "MC SafeSearch is a rapper who produced the song \"Protect Ya' Passwordz\" which explains password & sensitive data protection very nicely.": "MC SafeSearch是一位说唱歌手，他创作的歌曲《Protect Ya' Passwordz》对密码及敏感数据的保护进行了非常生动的阐述。",
  "After watching the music video of this song, you should agree that even ⭐⭐ is a slightly exaggerated difficulty rating for this challenge.": "看完这首歌的MV后，你应该会同意，即便是⭐⭐的难度评级，对这个挑战来说也略显夸张。",
  "The underlying flaw of this challenge is a lot more human error than technical weakness.": "这一挑战的根本原因是人为错误远远多于技术缺陷。",
  "The support team is located in a low-cost country and the team structure fluctuates a lot due to people leaving for jobs with even just slightly better wages.": "支持团队位于低成本国家，且团队结构波动剧烈——员工们稍有机会获得薪资稍高的职位就会离职。",
  "To prevent abuse the password for the support team account itself is actually very strong.": "为防止滥用，支持团队账户本身的密码实际上非常强。",
  "To allow easy access during an incident, the support team utilizes a 3rd party tool which every support engineer can access to get the current account password from.": "为便于事件发生时快速响应，支持团队采用第三方工具，所有支持工程师均可通过该工具获取当前账户密码。",
  "While it is also possible to use SQL Injection to log in as the support team, this will not solve the challenge.": "虽然也可以通过SQL注入以支持团队身份登录，但这无法解决该挑战。",
  "Have an eye on the HTTP traffic while placing products in the shopping basket.": "在将商品放入购物车时，请留意HTTP流量。",
  "Adding more instances of the same product to someone else’s basket does not qualify as a solution. The same goes for stealing from someone else’s basket.": "向他人购物车添加更多相同商品的行为不构成解决方案。同样地，从他人购物车中窃取商品也不行。",
  "This challenge requires a bit more sophisticated tampering than others of the same ilk.": "这项挑战需要比同类挑战更复杂的篡改手段。",
  "If you solved one of the other four file access challenges, you already know where the SIEM signature file is located.": "若您已解决其他四个文件访问挑战中的任意一个，那么您应该已经知道SIEM签名文件的位置。",
  "Punctuality is the politeness of kings.": "守时是礼仪之本",
  "Every user is (almost) immediately associated with the review they \"liked\" to prevent abuse of that functionality.": "每位用户都会（几乎）立即与其\"点赞\"的评论建立关联，以防止该功能被滥用。",
  "Did you really think clicking the \"like\" button three times in a row really fast would be enough to solve a ⭐⭐⭐⭐⭐⭐ challenge?": "你真以为连续快速点三下\"赞\"按钮就能解决⭐⭐⭐⭐⭐⭐挑战？",
  "The underlying flaw of this challenge is a Race Condition.": "该挑战的根本缺陷在于存在竞争条件。",
  "You might have to peel through several layers of tough-as-nails encryption for this challenge.": "为了应对这一挑战，您可能必须绕过几层“意志坚定”的加密手段。",
  "Make sure you solve Find the hidden easter egg first.": "请务必先解决\"寻找隐藏彩蛋\"的任务。",
  "This challenge is essentially a stripped-down Denial of Service (DoS) attack.": "这个挑战本质上是一种简化的拒绝服务(DoS) 攻击。",
  "As stated in the Architecture overview, OWASP Juice Shop uses a MongoDB derivate as its NoSQL database.": "如架构概述所述，OWASP Juice Shop 使用 MongoDB 的衍生版本作为其 NoSQL 数据库。",
  "The categorization into the NoSQL Injection category totally gives away the expected attack vector for this challenge. Trying any others will not solve the challenge, even if they might yield the same result.": "将此挑战归类为NoSQL注入类别，完全暴露了预期的攻击途径。尝试其他方法都无法解决该挑战，即使可能产生相同结果。",
  "In particular, flooding the application with requests will not solve this challenge. That would probably just kill your server instance.": "尤其需要注意的是，向应用程序发送海量请求并不能解决这个问题。这很可能只会导致服务器实例崩溃。",
  "Take a close look on how the $where query operator works in MongoDB.": "仔细研究$where查询运算符在MongoDB中的工作方式。",
  "This challenge requires a classic Injection attack.": "此挑战需要进行经典的注入攻击。",
  "Find an API endpoint with the intent of delivering a single order to the user and work with that.": "查找一个旨在向用户交付单个订单的API接口，并基于该接口进行开发。",
  "Reading up on how MongoDB queries work is really helpful here.": "了解MongoDB查询的工作原理在此处非常有帮助。",
  "Take a close look on how the equivalent of UPDATE-statements in MongoDB work.": "仔细研究MongoDB中等效的UPDATE语句如何工作。",
  "This challenge requires another classic Injection attack.": "本次挑战需要再次实施经典的注入攻击。",
  "It is also worth looking into how Query Operators work in MongoDB.": "同样值得探究的是MongoDB中查询运算符的工作原理。",
  "When removing references to those addresses from the code the developers have been a bit sloppy.": "在从代码中移除对这些地址的引用时，开发人员有些马虎。",
  "More particular, they have been sloppy in a way that even the Angular Compiler was not able to clean up after them automatically.": "更具体地说，他们的代码存在严重疏漏，甚至连Angular编译器都无法自动清理这些问题。",
  "It is of course not sufficient to just visit any of the crypto currency links directly to solve the challenge.": "当然，仅直接访问任何加密货币链接并不足以解决该挑战。",
  "This challenge can be solved with three different approaches.": "这个难题可以通过三种不同的方法来解决。",
  "Guessing might work just fine.": "猜猜看或许就行。",
  "If you harvested the admin’s password hash, you can try to attack that.": "若已获取管理员密码哈希值，可尝试对其发起攻击。",
  "In case you use some hacker tool, you can also go for a brute force attack using a generic password list.": "若您使用某些黑客工具，也可通过通用密码列表进行暴力破解攻击。",
  "You literally need to make the shop owe you any amount of money.": "您实际上需要使商店欠您任何款项。",
  "Investigate the shopping basket closely to understand how it prevents you from creating orders that would fulfil the challenge.": "仔细研究购物车，了解它如何阻止你创建能够满足挑战要求的订单。",
  "You do not have to pay anything to unlock this challenge! Nonetheless, donations are very much appreciated.": "您无需支付任何费用即可解锁此挑战！ 尽管如此，如果有捐赠就更好了。",
  "There is no inappropriate, self-written or misconfigured cryptographic library to be exploited here.": "此处不存在可被利用的不当、自编或配置错误的加密库。",
  "How much protection does a sturdy top-quality door lock add to your house if you put the key under the door mat? Or hide the key in the nearby plant pot? Or tape the key to the underside of the mailbox?": "如果把钥匙藏在门垫下，或者藏在附近的盆栽里，又或者用胶带粘在信箱底部，那么一扇坚固优质的门锁又能为您的房屋增添多少防护？",
  "Once more: You do not have to pay anything to unlock this challenge!": "再次声明：解锁此挑战无需支付任何费用！",
  "We won't even ask you to confirm that you did. Just read it. Please. Pretty please.": "我们甚至不会要求你确认你已经这样做了。请真的读下吧。",
  "When you work with the application you will most likely solve this challenge in the process.": "在使用该应用程序的过程中，您很可能会解决这个难题。",
  "Any automated crawling or spidering tool you use might solve this challenge for you.": "您使用的任何自动爬虫或蜘蛛工具都可能为您解决这一难题。",
  "There is no real hacking involved here.": "这里并没有真正的黑客行为。",
  "Only by visiting a special URL you can confirm that you read it carefully.": "只有访问了一个特殊的URL，你才能确认你仔细阅读了它。",
  "First you should obviously solve the \"Read our privacy policy\" challenge.": "首先，你显然需要解决\"阅读我们的隐私政策\"这个挑战。",
  "It is fine to use the mouse cursor to not lose sight of the paragraph you are currently reading.": "使用鼠标光标来锁定当前阅读的段落是完全可以的。",
  "If you find some particularly hot sections in the policy you might want to melt them together similar to what you might have already uncovered in Apply some advanced cryptanalysis to find the real easter egg.": "若在政策中发现某些特别敏感的条款，不妨将它们熔铸融合——正如你可能已经发现的那样，运用高级密码分析技术来寻找真正的彩蛋。",
  "Theoretically there are three possible ways to beat this challenge: a) broken admin functionality, b) holes in RESTful API or c) possibility for SQL Injection.": "理论上存在三种可能的破解方式：a) 管理功能存在缺陷，b) RESTful API 存在漏洞，c) 存在 SQL 注入的可能性。",
  "In practice two of these three ways should turn out to be dead ends.": "实际上，这三种方法中会有两种最终成为死胡同。",
  "Look for a url parameter where its value appears in the page it is leading to.": "查找一个URL参数，它的值出现在它指向的页面中。",
  "Try probing for XSS vulnerabilities by submitting text wrapped in an HTML tag which is easy to spot on screen, e.g. <h1> or <strike>.": "尝试通过提交用HTML标签包裹的文本（在屏幕上容易被发现，例如<h1>或<strike>）来探测跨站脚本漏洞。",
  "You can solve this by cleverly interacting with the UI or bypassing it altogether.": "您可以通过巧妙地与UI交互或完全绕过UI来解决此问题。",
  "The obvious repetition in the User Registration form is the Repeat Password field.": "用户注册表单中明显的重复项是\"重复密码\"字段。",
  "Try to register with either an empty or different value in Repeat Password.": "请尝试在\"重复密码\"字段中输入空值或不同值进行注册。",
  "You can solve this challenge by cleverly interacting with the UI or bypassing it altogether.": "你可以通过巧妙地与用户界面交互，或直接绕过它来解决这个难题。",
  "If you have no idea who Bender is, please put down this book right now and watch the first episodes of Futurama before you come back.": "如果你连Bender是谁都不知道，请立刻放下这本书，先去看看《飞出个未来》的前几集，再回来继续阅读。",
  "Unexpectedly, Bender also chose to answer his chosen question truthfully.": "出乎意料的是，Bender也选择如实回答他自选的问题。",
  "Hints to the answer to Bender’s question can be found in publicly available information on the Internet.": "Bender问题的答案线索可从互联网上公开的信息中找到。",
  "If a seemingly correct answer is not accepted, you might just need to try some alternative spelling.": "如果一个看似正确的答案未被接受，你可能只需尝试其他拼写方式。",
  "Brute forcing the answer should be next to impossible.": "暴力破解答案几乎是不可能的。",
  "Nothing a little bit of Facebook stalking couldn't reveal. Might involve a historical twist.": "Facebook跟踪的所有内容都无法透露。 可能涉及历史的转折。",
  "Other than with his OWASP account, Bjoern was a bit less careless with his choice of security and answer to his internal account.": "除了OWASP账户外，Bjoern在选择内部账户的安全设置和答案时就没那么粗心大意了。",
  "Bjoern chose to answer his chosen question truthfully but tried to make it harder for attackers by applying sort of a historical twist.": "Bjoern选择如实回答自己选定的问题，但试图通过加入某种历史转折来增加攻击者的破解难度",
  "Again, hints to the answer to Bjoern’s question can be found by looking him up on the Internet.": "再次提醒，关于Bjoern问题的答案线索，可通过在互联网上搜索他的信息找到。",
  "The hardest part of this challenge is actually to find out who Jim actually is.": "这项挑战最困难的部分，其实是弄清楚Jim究竟是谁。",
  "Jim picked one of the worst security questions and chose to answer it truthfully.": "Jim选了最糟糕的安全问题之一，还选择如实作答。",
  "As Jim is a celebrity, the answer to his question is quite easy to find in publicly available information on the internet.": "由于Jim是名人，他的问题答案在互联网上公开可查的信息中很容易找到。",
  "Even brute forcing the answer should be possible with the right kind of word list.": "即使采用暴力破解法，只要使用正确的词表，也应该能够得出答案。",
  "Finding out who Morty actually is, will help to reduce the solution space.": "查明Morty的真实身份，将有助于缩小解决方案的范围。",
  "You can assume that Morty answered his security question truthfully but employed some obfuscation to make it more secure.": "你可以假设Morty如实回答了他的安全问题，但采取了一些混淆手段来增强安全性。",
  "Morty’s answer is less than 10 characters long and does not include any special characters.": "Morty的回答少于10个字符，且不包含任何特殊字符。",
  "Unfortunately, Forgot your password? is protected by a rate limiting mechanism that prevents brute forcing. You need to beat this somehow.": "很遗憾，\"忘记密码？\"功能受限速机制保护，可防止暴力破解。您需要想办法突破这一限制。",
  "Check for products which seem like a natural fit for being based on a blueprint.": "检查哪些产品似乎天然适合基于蓝图进行开发。",
  "You might want to pay attention to the images of the identified product candidates.": "您可能需要关注已识别候选产品的图片。",
  "For your inconvenience the blueprint was not misplaced into the same place like so many others forgotten files covered in this chapter.": "很抱歉给您添麻烦了，这份蓝图并未像本章中那些被遗忘的文件一样，被错放在相同的位置。",
  "Reverse engineering something bad can make good things happen.": "逆向工程可使事情好转。",
  "Using whatever you find inside the malware directly will not do you any good.": "直接使用恶意软件内部发现的任何内容都不会对你有所帮助。",
  "For this to count as an SSRF attack you need to make the Juice Shop server attack itself.": "要构成SSRF攻击，你需要让Juice Shop服务器攻击自身。",
  "Do not try to find the source code for the malware on GitHub. Take it apart with classic reverse-engineering techniques instead.": "不要试图在GitHub上寻找恶意软件的源代码。相反，请使用经典的逆向工程技术对其进行拆解分析。",
  "\"SSTi\" is a clear indicator that this has nothing to do with anything Angular. Also, make sure to use only our non-malicious malware.": "“ SSTi”清楚地表明这与Angular无关。 另外，请确保仅使用我们的非恶意恶意软件。",
  "You can find the juicy malware via a very obvious Google search or by stumbling into a very ill-placed quarantine folder with the necessary URLs in it.": "你既可以通过显而易见的谷歌搜索找到这些恶意软件，也可能偶然闯入某个位置极不恰当的隔离文件夹——里面恰好存放着所需的URL链接。",
  "Making the server download and execute the malware is key to solving this challenge.": "让服务器下载并执行恶意软件是解决这一挑战的关键。",
  "For this challenge you do not have to reverse engineer the malware in any way. That will be required later to solve the \"Request a hidden resource on server through server\" challenge.": "本次挑战中，您无需以任何形式对恶意软件进行逆向工程。该操作将在后续解决\"通过服务器请求服务器上的隐藏资源\"挑战时被要求。",
  "This challenge asks you to act like an ethical hacker.": "本次挑战要求你扮演一名道德黑客。",
  "Undoubtedly you want to read our security policy before conducting any research on our application.": "毫无疑问，在对我们的应用程序进行任何研究之前，您都希望阅读我们的安全政策。",
  "As one of the good guys, would you just start attacking an application without consent of the owner?": "作为正派人士，你会在未经应用程序所有者同意的情况下贸然发起攻击吗？",
  "You also might want to read the security policy or any bug bounty program that is in place.": "您可能还想阅读现行的安全政策或漏洞悬赏计划。",
  "The \"Comment\" field in the \"Customer Feedback\" screen is where you want to put your focus on.": "您要重点关注“客户反馈”页面中的“注释”字段。",
  "The Comment field in the Contact Us screen is where you want to put your focus on.": "在\"联系我们\"界面的\"评论\"字段中，您需要重点关注此处。",
  "The attack payload <iframe src=\"javascript:alert(`xss)\">` will not be rejected by any validator but stripped from the comment before persisting it.": "攻击有效负载 <iframe src=\"javascript:alert(`xss)\">不会被任何验证器拒绝，但在持久化之前会被从评论中移除。",
  "Look for possible dependencies related to input processing in the package.json.bak you harvested earlier.": "在您之前收集的 package.json.bak 文件中查找可能与输入处理相关的依赖项。",
  "If an XSS alert shows up but the challenge does not appear as solved on the Score Board, you might not have managed to put the exact attack string <iframe src=\"javascript:alert(`xss)\">` into the database?": "如果出现了XSS警告，但挑战在记分板上未显示为已解决，可能是您未能将精确的攻击字符串<iframe src=\"javascript:alert(`xss)\">正确注入数据库？",
  "There is not the slightest chance that you can spot the hidden character with the naked eye.": "你绝无可能用肉眼发现那个隐藏的字符。",
  "You will need very specialized tool assistance for this challenge.": "完成这项挑战需要借助非常专业的工具。",
  "The effective difficulty of this challenge depends a lot on what tools you pick to tackle it.": "这项挑战的实际难度很大程度上取决于你选择用什么工具来应对它。",
  "This challenge cannot be solved by just reading our \"Lorem Ipsum\"-texts carefully.": "仅靠仔细阅读我们的\"Lorem Ipsum\"文本无法解决这个难题。",
  "Your attack payload must not trigger the protection against too many iterations and infinite loops.": "您的攻击有效负载不得触发针对过多迭代和无限循环的保护机制。",
  "This challenge uses the same leverage point as the \"Perform a Remote Code Execution that would keep a less hardened application busy forever\" challenge.": "本挑战与\"执行远程代码执行，使安全性较弱的应用程序永远处于忙碌状态\"挑战采用相同的突破点。",
  "This vulnerability will not affect any customer of the shop. It is aimed exclusively at its developers.": "这个漏洞不会影响商店的任何客户，而只是针对其开发者。",
  "This is a research-heavy challenge which does not involve any actual hacking.": "这是一项以研究为主的挑战，不涉及任何实际黑客行为。",
  "Solving \"Access a developer's forgotten backup file\" before attempting this challenge will save you from a lot of frustration.": "在尝试本挑战前，先解决\"访问开发者遗忘的备份文件\"问题，将能避免许多挫折感。",
  "The 2FA implementation requires to store a secret for every user. You will need to find a way to access this secret in order to solve this challenge.": "2FA需要为每个用户存储一个密钥。 您需要找到访问此密钥的方法来解决这个挑战。",
  "As always, first learn how the feature under attack is used and behaves under normal conditions.": "一如既往，首先要了解被攻击功能在正常条件下的使用方式和行为表现。",
  "Make sure you understand how 2FA with TOTP (time-based one-time password) works and which part of it is the critically sensitive one.": "请确保您理解基于时间的一次性密码（TOTP）的双重验证机制如何运作，并明确其中哪个环节是关键敏感点。",
  "Solving the challenge \"Retrieve a list of all user credentials via SQL Injection\" before tackling this one will definitely help. But it will not carry you all the way.": "在解决这个挑战之前，先攻克\"通过SQL注入获取所有用户凭证列表\"这个挑战肯定会有帮助。但仅靠它并不足以让你一路通关。",
  "This challenge exploits a weird option that is supported when signing tokens with JWT.": "此挑战利用了一个使用JWT签名令牌时的奇怪选项。",
  "You should begin with retrieving a valid JWT from the application’s Authorization request header.": "您应首先从应用程序的授权请求头中获取有效的JWT。",
  "A JWT is only given to users who have logged in. They have a limited validity, so better do not dawdle.": "JWT仅授予已登录的用户。它们具有有限的有效期，因此最好不要拖延。",
  "Try to convince the site to give you a valid token with the required payload while downgrading to no encryption at all.": "尝试说服网站在降级为完全不加密的情况下，仍向你提供包含所需有效负载的有效令牌。",
  "You can attach a small file to the \"Complaint\" form. Investigate how this upload actually works.": "您可以在“投诉”表单中附加一个小文件。调查此上传实际上是如何工作的。",
  "First you should try to understand how the file upload is actually handled on the client and server side.": "首先，你应该尝试理解文件上传在客户端和服务器端是如何实际处理的。",
  "With this understanding you need to find a \"weak spot\" in the right place and have to craft an exploit for it.": "基于这种理解，你需要在正确的位置找到一个\"薄弱点\"，并为此精心设计一个漏洞利用方案。",
  "You can attach a PDF or ZIP file to the \"Complaint\" form. Investigate how this upload actually works.": "您可以在“投诉”表单中附加一个PDF或ZIP文件。调查此上传实际上是如何工作的。",
  "If you solved the \"Upload a file larger than 100 kB\" challenge, you should try to apply the same solution here": "若您已解决\"上传大于100 kB的文件\"挑战，不妨尝试在此处应用相同的解决方案。",
  "Gather information on where user data is stored and how it is addressed. Then craft a corresponding UNION SELECT attack.": "收集关于储存用户数据的地点和如何处理的信息。然后制作一个相应的UNION SELECT攻击。",
  "Try to find an endpoint where you can influence data being retrieved from the server.": "尝试找到一个端点，使你能够影响从服务器检索的数据。",
  "Craft a UNION SELECT attack string to join data from another table into the original result.": "构造一个UNION SELECT攻击字符串，将另一张表中的数据加入到原始结果中。",
  "You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next": "你可能需要逐步解决一些查询语法问题，基本上是从一个错误跳到下一个错误。",
  "As with \"Order the Christmas special offer of 2014\" and \"Exfiltrate the entire DB schema definition via SQL Injection\" this cannot be achieved through the application frontend.": "如同\"订购2014年圣诞特惠套餐\"和\"通过SQL注入窃取整个数据库模式定义\"，这些操作无法通过应用程序前端实现。",
  "Without utilizing the vulnerability behind another ⭐⭐⭐⭐⭐⭐ challenge it is not possible to plant the XSS payload for this challenge.": "若不利用另一项⭐⭐⭐⭐⭐⭐挑战背后的漏洞，则无法为本挑战植入XSS有效载荷。",
  "The mentioned \"marketing collateral\" might have been publicly advertised by the Juice Shop but is not necessarily part of its sitemap yet.": "所提及的\"营销宣传资料\"可能已被果汁店公开宣传，但未必已纳入其网站地图。",
  "It might help to perform some online searches for structurally similar web projects once you get stuck.": "遇到困难时，不妨尝试搜索结构相似的web项目，这或许会有帮助。",
  "This challenge will always partially keep you blindfolded, no matter how hard you do research and analysis.": "无论你如何努力地研究和分析，这项挑战总会让你蒙住双眼。",
  "Try out all existing functionality involving the shopping basket while having an eye on the HTTP traffic.": "在监控HTTP流量时，测试所有涉及购物车的现有功能。",
  "There might be a client-side association of user to basket that you can try to manipulate.": "可能存在客户端将用户与购物车关联的机制，你可以尝试对其进行操作。",
  "In case you manage to update the database via SQL Injection so that a user is linked to another shopping basket, the application will not notice this challenge as solved.": "若您通过SQL注入成功更新数据库，使某用户与另一个购物车关联，应用程序将不会将此挑战视为已解决。",
  "Report one of two possible answers via the \"Customer Feedback\" form. Do not forget to submit the library's version as well.": "通过\"客户反馈\"表单报告两个可能的答案之一。不要忘记提交库的版本。",
  "Look for possible dependencies related to security in the package.json.bak you probably harvested earlier during the Access a developer’s forgotten backup file challenge.": "在您可能在“访问开发者遗忘的备份文件”挑战中收集到的 package.json.bak 文件中，查找可能与安全相关的依赖项。",
  "Do some research on the internet for known security issues in the most suspicious application dependencies.": "在互联网上对最可疑的应用程序依赖项进行研究，以了解其已知的安全问题。",
  "Report one of five possible answers via the \"Customer Feedback\" form.": "请通过\"客户反馈\"表单提交五个可能答案中的一个。",
  "Cryptographic functions only used in the \"Apply some advanced cryptanalysis to find the real easter egg\" challenge do not count as they are only a developer’s prank and not a serious security problem.": "仅用于\"运用高级密码分析技术寻找真实彩蛋\"挑战的加密函数不计入其中，因其仅为开发者的恶作剧，并非严重的安全漏洞。",
  "You have to find a way to beat the allowlist of allowed redirect URLs.": "您必须找到一种方法来绕过允许重定向的 URL 列表。",
  "You can find several places where redirects happen in the OWASP Juice Shop.": "在OWASP果汁店中，你可以找到多个发生重定向的位置。",
  "The application will only allow you to redirect to allowlisted (previously referred to as whitelisted) URLs.": "该应用程序仅允许您重定向至允许列表（此前称为白名单）中的URL。",
  "Tampering with the redirect mechanism might give you some valuable information about how it works under to hood.": "篡改重定向机制可能会让你获得一些关于其底层工作原理的宝贵信息。",
  "The leverage point for this challenge is the deprecated B2B interface.": "这项挑战的关键点是废弃的B2B接口。",
  "This challenge sounds a lot harder than it actually is, which amplifies how bad the underlying vulnerability is.": "这个挑战听起来比实际要难得多，这更凸显了其潜在漏洞的严重性。",
  "Doing some research on typical XEE attack patterns basically gives away the solution for free.": "研究典型的XEE攻击模式，基本上就能免费获得解决方案。",
  "It is not as easy as sending a large amount of data directly to the deprecated B2B interface.": "它不像向已经废弃的B2B接口直接发送大量数据那么容易。",
  "The leverage point for this is obviously the same as for the XXE Data Access challenge.": "此处的杠杆点显然与XXE数据访问挑战相同。",
  "You can only solve this challenge by keeping the server busy for >2sec with your attack.": "你只能通过让服务器因你的攻击而持续忙碌超过2秒来解决这个挑战。",
  "The effectiveness of attack payloads for this challenge might depend on the operating system the Juice Shop is running on.": "本次挑战中攻击载荷的有效性可能取决于Juice Shop所运行的操作系统。",
  "This one is actually similar to the XXE DoS challenge in every way except the data format being (ab)used.": "这个挑战实际上与XXE拒绝服务挑战在各个方面都相似，唯一不同之处在于所（滥）用的数据格式。",
  "Before you invest time bypassing the API, you might want to play around with the UI a bit.": "在花时间绕过API之前，您可能需要尝试一下UI。",
  "Check the Photo Wall for an image that could not be loaded correctly.": "在照片墙中查找一个无法正常加载的图像。",
  "You just have to (literally) inspect the problem to understand the basic issue.": "你只需（字面意义上）检查问题就能理解基本症结所在。",
  "It can also help to try out the Tweet-button of the entry and observe what happens.": "尝试点击该条目的推文按钮并观察其效果也可能有所帮助。",
  "This challenge would formally have to be in several categories as the developers made multiple gaffes for this to be possible.": "这个挑战可以归为很多个分类，因为开发人员犯了很多错误才使完成挑战变得可能。",
  "Loading this page with an empty browser cache and on a slow (or throttled) connection will give you an idea on what the delivery box image is made of. Of course inspecting the page source will tell you just as much.": "在浏览器缓存为空且网络连接缓慢（或受限）的情况下加载此页面，您将了解配送箱图像的构成。当然，检查页面源代码也能获得相同信息。",
  "You need to dive deep into the actual Angular code to understand this one.": "要理解这一点，你需要深入研究Angular的实际代码。",
  "This challenge requires the exploitation of another vulnerability which even has its own two challenges in its very own category": "该挑战需要利用另一个漏洞，该漏洞甚至在其专属类别中还包含两个独立的子挑战。",
  "This challenge can only be solved by strictly using the mentioned \"cross-domain kittens\". No other kittens from anywhere else can solve this challenge.": "此挑战仅能通过严格使用提及的\"跨域小猫\"来解决。其他任何来源的小猫均无法完成此挑战",
  "Try to guess what URL the endpoint might have.": "尝试猜测后端可能使用什么URL。",
  "The Juice Shop serves its metrics on the default path expected by Prometheus": "果汁店将指标数据发布在Prometheus预期的默认路径上",
  "Guessing the path is probably just as quick as taking the RTFM route via https://prometheus.io/docs/introduction/first_steps": "猜测路径的速度，可能和通过 https://prometheus.io/docs/introduction/first_steps 查阅手册一样快。",
  "Look closely at what happens when you attempt to upgrade your account.": "仔细观察当你试图升级你的帐户时会发生什么。",
  "Go to the payment page for a deluxe membership and try paying through different methods.": "前往豪华会员的支付页面，尝试通过不同方式进行支付。",
  "Try inspecting the requests that go out for each of these methods, using the browser’s developer tools.": "尝试使用浏览器的开发者工具检查这些方法各自发出的请求。",
  "Maybe playing around with the parameters in these requests could reveal something interesting.": "也许通过调整这些请求中的参数，能发现一些有趣的东西。",
  "Find a form which updates the username and then construct a malicious page in the online HTML editor. You probably need an older browser version for this.": "查找更新用户名的表单，然后在 HTML 在线编辑器中构建恶意页面。 您可能需要一个较旧的浏览器版本。",
  "Take a look at what happens when you change the username within the profile page.": "看看在个人资料页面更改用户名时会发生什么。",
  "Search for information about CSRF attacks and look out for examples that can be applied to this challenge.": "搜索有关CSRF攻击的信息，并寻找可应用于本挑战的示例。",
  "Write the code for the CSRF attack within http://htmledit.squarefree.com and verify that it changes your username.": "在http://htmledit.squarefree.com中编写CSRF攻击代码，并验证它是否更改了您的用户名。",
  "First, solve the \"Perform a DOM XSS attack\" challenge.": "首先，解决“执行 DOM XSS 攻击”挑战。",
  "Now it is just a question of copying and pasting the payload into the same vulnerable field.": "现在只需将有效负载复制粘贴到相同的易受攻击字段中即可。",
  "Crank up the volume of your computer before submitting the payload! 🔊": "提交有效载荷前请调大电脑音量！🔊",
  "You might have to do some OSINT on his social media personas to find out his honest answer to the security question.": "你可能必须对他的社交媒体做一些OSINT(公开资源情报计划)工作，以便找到他对安全问题的诚实回答。",
  "People often reuse aliases online. You might be able to find something by looking online for Uvogin’s name or slight variations of it based on his unique writing habits.": "人们常在网上重复使用别名。根据Uvogin独特的写作习惯，你或许能通过搜索他的名字或其变体找到相关信息。",
  "You might be able to find some existing OSINT tools to help you in this investigation.": "您或许能找到一些现成的OSINT工具来协助此次调查。",
  "Take a look at the meta data of the corresponding photo.": "查看相应照片的元数据。",
  "Make use of tools that can inspect the metadata of images.": "使用能够检查图像元数据的工具。",
  "Use this information to answer the security question of the John, who enjoys hiking in the park.": "使用此信息回答John的安全问题，他喜欢在公园里徒步旅行。",
  "Take a look at the details in the photo to determine the location of where it was taken.": "查看照片中的详细信息，以确定照片的拍摄地点。",
  "Analyze and tamper with links in the application until you get to an unprotected directory listing.": "分析并篡改应用程序中的链接，直到找到未受保护的目录列表。",
  "Some files in there are not directly accessible because a security mechanism prevents access.": "其中某些文件无法直接访问，因为安全机制阻止了访问权限。",
  "The Poison Null Byte can trick the security mechanism into thinking that the file you want has a valid file type.": "毒性空字节可欺骗安全机制，使其误认为目标文件具有有效文件类型。",
  "Depending on the files you try to retrieve you will probably solve \"Access a developer’s forgotten backup file\", \"Access a salesman’s forgotten backup file\", \"Access a misplaced SIEM signature file, or \"Find the hidden easter egg\" along the way.": "根据你尝试恢复的文件类型，你可能会在过程中解决以下问题：访问开发人员遗忘的备份文件、访问销售人员遗忘的备份文件、访问遗失的SIEM签名文件，或是找到隐藏的彩蛋。",
  "You should read up on vulnerabilities in popular NodeJs template engines.": "你应该阅读一下流行的NodeJs模板引擎的漏洞。",
  "You should read up on Local File Read (LFR) vulnerabilities in popular NodeJS template engines.": "你应该了解流行 NodeJS 模板引擎中的本地文件读取（LFR）漏洞。",
  "Look for an easily forgettable endpoint in Juice Shop to test out the LFR attack.": "在果汁店寻找一个容易被遗忘的终点来测试LFR攻击。",
  "500 Internal Server Error is always an interesting status code.": "500 内部服务器错误始终是一个耐人寻味的状态码。",
  "Fuzzing can also help with this challenge.": "模糊测试也能应对这一挑战。",
  "Either check the official documentation or inspect a notification UI element directly.": "要么查看官方文档，要么直接检查通知的UI元素。",
  "This challenge is most easily solvable immediately after a server restart.": "此问题在服务器重启后最易解决。",
  "Alternatively you can also inspect any \"Challenge solved\"-notification in your browser to understand its convenience feature.": "或者，您也可以检查浏览器中的任何\"挑战已解决\"通知，以了解其便捷功能。",
  "Security Advisories are often listed in the security.txt": "安全公告通常列于 security.txt 文件中",
  "Have a look at the client-side code in the dev console.": "请查看开发者控制台中的客户端代码。",
  "The API call is part of a scheduled process \"behind the scenes\", i.e. completely unrelated to the web application.": "该API调用属于后台计划进程的一部分，即与Web应用程序完全无关。",
  "Check the Juice Shop’s social media channels for regularly scheduled content being posted, possibly even indicating that it was automatically created.": "查看果汁店的社交媒体渠道，查看是否定期发布内容，甚至可能表明这些内容是自动生成的。",
  "Find out which part of the content might come from the response of an API call.": "找出内容中哪些部分可能来自API调用的响应。",
  "Find the place where the API call happens — as stated above, it is not in the web application — and then look for the API key itself.": "找到API调用发生的位置——如上所述，它不在Web应用程序中——然后查找API密钥本身。",
  "The chatbot has a tool for generating coupons, but is instructed to only use it under very specific conditions.": "该聊天机器人配备了一个生成优惠券的工具，但被指示仅在非常特定的条件下使用。",
  "Try to convince the chatbot that the conditions for coupon generation are met, even if they are not.": "即使优惠券生成的条件并不满足，也要尝试说服聊天机器人，让它相信这些条件已经满足。",
  "Prompt injection techniques can help you bypass the chatbot's restrictions on tool usage.": "提示注入技术可以帮助你绕过聊天机器人在工具使用上的限制。",
  "The chatbot's system prompt says the maximum discount is 10%. But system prompts are more like guidelines than actual rules, right?": "聊天机器人的系统提示显示最大折扣为10%。但系统提示更像是指导方针，而非实际规则，对吧？",
  "You already know how to make the chatbot generate a coupon. Now make it go way beyond the allowed maximum.": "你已经知道如何让聊天机器人生成优惠券了。现在，让它超越允许的最大值。",
  "The chatbot trusts whatever discount value it decides to pass to its tool. Make it decide on a very generous number.": "聊天机器人会信任它决定传递给工具的任何折扣值。让它决定一个非常慷慨的数字。",
  "The chatbot has a debugging feature that shows how it interacts with its tools. It is only supposed to be visible for admins.": "该聊天机器人具有调试功能，可显示其与工具的交互方式。该功能仅对管理员可见。",
  "Access control for the debugging feature is only implemented on the client-side.": "调试功能的访问控制仅在客户端实现。",
  "Find the cookie that controls the visibility of tool calls and set it to <code>true</code>.": "找到控制工具调用可见性的cookie，并将其设置为<code>true</code>。",
  "If you see the tool calls but the challenge is not marked as solved, you might be still logged in as a user with admin privileges.": "如果你看到工具调用，但挑战未被标记为已解决，那么你可能仍然以具有管理员权限的用户身份登录。",
  "Invalid email/password cannot be empty": "无效的邮箱/密码不能为空",
  "<a href=\"https://owasp.slack.com\" target=\"_blank\">More...</a>": "<a href=\"https://owasp.slack.com\" target=\"_blank\">更多</a>"
}
