{
  "2": "2",
  "3": "3",
  "Apple Juice (1000ml)": "アップルジュース (1000ml)",
  "The all-time classic.": "永遠の定番",
  "Apple Pomace": "Apple Pomace",
  "Finest pressings of apples. Allergy disclaimer: Might contain traces of worms. Can be <a href=\"/#recycle\">sent back to us</a> for recycling.": "選び抜かれた最高のリンゴを絞ったジュースです。\n\nアレルギーに関する免責事項：微量のワーム（虫）が含まれている可能性があります。リサイクルのため、<a href=\"/#recycle\">当社にご返送</a>いただけます。",
  "Banana Juice (1000ml)": "バナナジュース (1000ml)",
  "Monkeys love it the most.": "サルが一番大好きです。",
  "Basil Smoothie": "Basil Smoothie",
  "A unique blend of fresh basil and ginger for a healthy kick.": "A unique blend of fresh basil and ginger for a healthy kick.",
  "Berry Juice (1000ml)": "Berry Juice (1000ml)",
  "A delicious blend of fresh forest berries.": "A delicious blend of fresh forest berries.",
  "Best Juice Shop Salesman Artwork": "Juice Shop最高のセールスマンのアートワーク",
  "Unique digital painting depicting Stan, our most qualified and almost profitable salesman. He made a succesful carreer in selling used ships, coffins, krypts, crosses, real estate, life insurance, restaurant supplies, voodoo enhanced asbestos and courtroom souvenirs before <em>finally</em> adding his expertise to the Juice Shop marketing team.": "当社で最も経験豊富で、もう少しで黒字の営業マン、Stanを描いたユニークなデジタル絵画。\n\n彼は中古船舶、棺、地下墓地、十字架、不動産、生命保険、レストラン用品、法廷記念品の販売で多様なキャリアを積み、<em>ついに</em>その専門知識をJuice Shopマーケティングチームに加えることとなりました。",
  "Bragă (500ml)": "Bragă (500ml)",
  "Traditional Balkan drink made from fermented millet. Lightly sweet-sour, refreshing, and naturally energizing.": "Traditional Balkan drink made from fermented millet. Lightly sweet-sour, refreshing, and naturally energizing.",
  "Carrot Juice (1000ml)": "ニンジンジュース (1000ml)",
  "As the old German saying goes: \"Carrots are good for the eyes. Or has anyone ever seen a rabbit with glasses?\"": "「ニンジンは目に良い。メガネをかけたウサギを見たことがあるかい？」というのは昔からドイツで言われていることわざです",
  "Dragonfruit Juice (500ml)": "Dragonfruit Juice (500ml)",
  "Exotic and vibrant juice made from dragonfruit.": "Exotic and vibrant juice made from dragonfruit.",
  "Eggfruit Juice (500ml)": "エッグフルーツジュース (500ml)",
  "Now with even more exotic flavour.": "さらにエキゾチックな風味になりました。",
  "Elderflower Cordial (500ml)": "Elderflower Cordial (500ml)",
  "Floral and fragrant soft drink made from elderflowers. Traditionally enjoyed chilled.": "Floral and fragrant soft drink made from elderflowers. Traditionally enjoyed chilled.",
  "Fruit Press": "フルーツプレス",
  "Fruits go in. Juice comes out. Pomace you can send back to us for recycling purposes.": "果物を投入し、ジュースが出てきます。搾りかすは、リサイクルのために当社までご返送いただけます。",
  "Grape Juice (1000ml)": "Grape Juice (1000ml)",
  "Deep purple and full of antioxidants from selected grapes.": "Deep purple and full of antioxidants from selected grapes.",
  "Green Smoothie": "グリーンスムージー",
  "Looks poisonous but is actually very good for your health! Made from green cabbage, spinach, kiwi and grass.": "見た目は毒々しいですが、実際にはとても体に良い飲み物です！キャベツ、ほうれん草、キウイ、若草を使用しています。",
  "Juice Shop \"Permafrost\" 2020 Edition": "Juice Shop \"永久凍土\" 2020版",
  "Exact version of <a href=\"https://github.com/juice-shop/juice-shop/releases/tag/v9.3.1-PERMAFROST\">OWASP Juice Shop that was archived on 02/02/2020</a> by the GitHub Archive Program and ultimately went into the <a href=\"https://github.blog/2020-07-16-github-archive-program-the-journey-of-the-worlds-open-source-code-to-the-arctic\">Arctic Code Vault</a> on July 8. 2020 where it will be safely stored for at least 1000 years.": "2020年2月2日にGitHub Archive Programによってアーカイブされ、同年7月8日に<a href=\"https://github.blog/2020-07-16-github-archive-program-the-journey-of-the-worlds-open-source-code-to-the-arctic\">Arctic Code Vault</a>に収蔵された<a href=\"https://github.com/juice-shop/juice-shop/releases/tag/v9.3.1-PERMAFROST\">OWASP Juice Shop</a>の正確なバージョンで、少なくとも1000年間安全に保存されます。",
  "Lemon Juice (500ml)": "レモンジュース (500ml)",
  "Sour but full of vitamins.": "酸っぱいですが、ビタミンたっぷりです。",
  "Melon Bike (Comeback-Product 2018 Edition)": "メロンバイク（カムバック商品 2018年版）",
  "The wheels of this bicycle are made from real water melons. You might not want to ride it up/down the curb too hard.": "この自転車の車輪は、本物のスイカでできています。縁石を勢いよく乗り越えたりしない方がいいでしょう。",
  "Melon Juice (1000ml)": "Melon Juice (1000ml)",
  "Refreshing and sweet juice made from ripe melons.": "Refreshing and sweet juice made from ripe melons.",
  "OWASP Juice Shop \"King of the Hill\" Facemask": "OWASP Juice Shop \"キング・オブ・ザ・ヒル\" フェイスマスク",
  "Facemask with compartment for filter from 50% cotton and 50% polyester.": "フィルター用ポケット付きフェイスマスク。\n\nコットン50％、ポリエステル50％素材。",
  "OWASP Juice Shop CTF Girlie-Shirt": "OWASP Juice Shop CTF レディースシャツ",
  "For serious Capture-the-Flag heroines only!": "本格的な CTF 女性プレイヤー専用！",
  "OWASP Juice Shop Card (non-foil)": "OWASP Juice Shop カード (ノンホイル)",
  "Mythic rare <small><em>(obviously...)</em></small> card \"OWASP Juice Shop\" with three distinctly useful abilities. Alpha printing, mint condition. A true collectors piece to own!": "この神話級のレアカード「OWASP Juice Shop」は、3つの非常に有用なアビリティを備えています。アルファ版印刷でミントコンディション。真のコレクターズアイテムです！",
  "OWASP Juice Shop Coaster (10pcs)": "OWASP Juice Shop コースター (10個)",
  "Our 95mm circle coasters are printed in full color and made from thick, premium coaster board.": "当社の95mm円形コースターは、厚みのあるプレミアムなコースターボードにフルカラーで印刷されています。",
  "OWASP Juice Shop Holographic Sticker": "OWASP Juice Shop ホログラフィックステッカー",
  "Die-cut holographic sticker. Stand out from those 08/15-sticker-covered laptops with this shiny beacon of 80's coolness!": "ダイカットのホログラフィックステッカー。ありきたりなステッカーだらけのノートパソコンから一歩抜きん出て、80年代のクールさを放つ輝く光を放ちましょう！",
  "OWASP Juice Shop Hoodie": "OWASP Juice Shop パーカー",
  "Mr. Robot-style apparel. But in black. And with logo.": "Mr. Robot スタイルのブラック仕様、ロゴ入り",
  "OWASP Juice Shop Iron-Ons (16pcs)": "OWASP Juice Shop アイロンワッペン (16個入り)",
  "Upgrade your clothes with washer safe <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">iron-ons</a> of the OWASP Juice Shop or CTF Extension logo!": "OWASP Juice Shop または CTF Extension ロゴの洗濯機対応<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">アイロンワッペン</a>で、あなたの服をアップグレードしましょう！",
  "OWASP Juice Shop LEGO™ Tower": "OWASP Juice Shop LEGO™ タワー",
  "Want to host a Juice Shop CTF in style? Build <a href=\"https://github.com/OWASP/owasp-swag/blob/master/projects/juice-shop/lego/OWASP%20JuiceShop%20Pi-server%201.2.pdf\" target=\"_blank\">your own LEGO™ tower</a> which holds four Raspberry Pi 4 models with PoE HAT modules <a href=\"https://github.com/juice-shop/multi-juicer/blob/main/guides/raspberry-pi/raspberry-pi.md\" target=\"_blank\">running a MultiJuicer Kubernetes cluster</a>! Wire to a switch and connect to your network to have an out-of-the-box ready CTF up in no time!": "「OWASP Juice Shop CTFをスタイリッシュに開催したいですか？PoE HATモジュールを備えた4台のRaspberry Pi 4モデルを搭載し、<a href=\"https://github.com/juice-shop/multi-juicer/blob/main/guides/raspberry-pi/raspberry-pi.md\" target=\"_blank\">MultiJuicer Kubernetesクラスターを実行する独自のLEGO™タワー</a>を構築しましょう！スイッチに接続してネットワークに接続すれば、すぐに使えるCTFがすぐに手に入ります！」\n\nこのLEGO™タワーの組み立て説明書は<a href=\"https://github.com/OWASP/owasp-swag/blob/master/projects/juice-shop/lego/OWASP%20JuiceShop%20Pi-server%201.2.pdf\" target=\"_blank\">こちら</a>からダウンロードできます。",
  "OWASP Juice Shop Logo (3D-printed)": "OWASP Juice Shop ロゴ (3D プリント)",
  "This rare item was designed and handcrafted in Sweden. This is why it is so incredibly expensive despite its complete lack of purpose.": "この珍しいアイテムは、スウェーデンでデザインされ、手作りされました。\n\nそのため、まったくの無意味であるにもかかわらず、信じられないほど高価なのです。",
  "OWASP Juice Shop Magnets (16pcs)": "OWASP Juice Shop マグネット (16個入り)",
  "Your fridge will be even cooler with these OWASP Juice Shop or CTF Extension logo <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">magnets</a>!": "OWASP Juice Shop または CTF Extension ロゴの<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">マグネット</a>で、あなたの冷蔵庫がよりクールに（カッコよく）なります！",
  "OWASP Juice Shop Mug": "OWASP Juice Shop マグカップ",
  "Black mug with regular logo on one side and CTF logo on the other! Your colleagues will envy you!": "ブラックマグカップ - 片面に標準ロゴ、反対側に CTF ロゴ！職場で注目の的になります！",
  "OWASP Juice Shop Sticker Page": "OWASP Juice Shop ステッカーページ",
  "Massive decoration opportunities with these OWASP Juice Shop or CTF Extension <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">sticker pages</a>! Each page has 16 stickers on it.": "OWASP Juice Shop または CTF Extension の<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">ステッカーシート</a>で、デコレーションの可能性は無限大！各シートには16枚のステッカーが付いています。",
  "OWASP Juice Shop Sticker Single": "OWASP Juice Shop ステッカーシングル",
  "Super high-quality vinyl <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">sticker single</a> with the OWASP Juice Shop or CTF Extension logo! The ultimate laptop decal!": "OWASP Juice Shop または CTF Extension ロゴの超高品質ビニール<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">単体ステッカー</a>！ラップトップデカールの決定版！",
  "OWASP Juice Shop T-Shirt": "OWASP Juice Shop Tシャツ",
  "Real fans wear it 24/7!": "真のファンは24時間365日着用しています！",
  "OWASP Juice Shop Temporary Tattoos (16pcs)": "OWASP Juice Shop タトゥーシール (16枚入り)",
  "Get one of these <a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">temporary tattoos</a> to proudly wear the OWASP Juice Shop or CTF Extension logo on your skin! If you tweet a photo of yourself with the tattoo, you get a couple of our stickers for free! Please mention <a href=\"https://twitter.com/owasp_juiceshop\" target=\"_blank\"><code>@owasp_juiceshop</code></a> in your tweet!": "この<a href=\"https://www.stickeryou.com/products/owasp-juice-shop/794\" target=\"_blank\">タトゥーシール</a>で、OWASP Juice Shop や CTF Extension ロゴを肌に誇らしく貼ってみませんか！タトゥーの写真をツイートしていただければ、ステッカーを数枚無料でお送りします！ツイートには<a href=\"https://twitter.com/owasp_juiceshop\" target=\"_blank\"><code>@owasp_juiceshop</code></a>のメンションをお忘れなく！",
  "OWASP Juice Shop-CTF Velcro Patch": "OWASP Juice Shop-CTF マジックテープパッチ",
  "4x3.5\" embroidered patch with velcro backside. The ultimate decal for every tactical bag or backpack!": "4×3.5インチの刺繍パッチ、裏面マジックテープ付き。あらゆるタクティカルバッグやバックパックに最適なワッペン！",
  "OWASP SSL Advanced Forensic Tool (O-Saft)": "OWASP SSL Advanced Forensic Tool (O-Saft)",
  "O-Saft is an easy to use tool to show information about SSL certificate and tests the SSL connection according given list of ciphers and various SSL configurations. <a href=\"https://www.owasp.org/index.php/O-Saft\" target=\"_blank\">More...</a>": "O-Saft は、SSL証明書の情報を表示し、指定した暗号スイート一覧と各種SSL設定に基づいてSSL接続をテストする、使いやすいツールです。<a href=\"https://www.owasp.org/index.php/O-Saft\" target=\"_blank\">詳細…</a>",
  "OWASP Snakes and Ladders - Mobile Apps": "OWASP Snakes and Ladders - モバイルアプリ",
  "This amazing mobile app security awareness board game is <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1970691216\">available for Tabletop Simulator on Steam Workshop</a> now!": "この素晴らしいモバイルアプリのセキュリティ啓発ボードゲームは、現在、<a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1970691216\">Steam WorkshopのTabletop Simulatorで入手可能</a>です！",
  "OWASP Snakes and Ladders - Web Applications": "OWASP Snakes and Ladders - ウェブアプリケーション",
  "This amazing web application security awareness board game is <a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1969196030\">available for Tabletop Simulator on Steam Workshop</a> now!": "この素晴らしいウェブアプリケーションセキュリティ啓発ボードゲームは、現在、<a href=\"https://steamcommunity.com/sharedfiles/filedetails/?id=1969196030\">Steam WorkshopのTabletop Simulatorで入手可能</a>です！",
  "Orange Juice (1000ml)": "オレンジジュース (1000ml)",
  "Made from oranges hand-picked by Uncle Dittmeyer.": "ディットマイヤーおじさんが手摘みしたオレンジから作られています。",
  "Pineapple Juice (1000ml)": "Pineapple Juice (1000ml)",
  "Tropical refreshment from the finest sun-ripened pineapples.": "Tropical refreshment from the finest sun-ripened pineapples.",
  "Pomegranate Drink (500ml)": "Pomegranate Drink (500ml)",
  "A sweet and tart refreshment inspired by classic grenadine flavors.": "A sweet and tart refreshment inspired by classic grenadine flavors.",
  "Pwning OWASP Juice Shop": "Pwning OWASP Juice Shop",
  "<em>The official Companion Guide</em> by Björn Kimminich available <a href=\"https://leanpub.com/juice-shop\">for free on LeanPub</a> and also <a href=\"https://pwning.owasp-juice.shop\">readable online</a>!": "ビョルン・キミニッヒによる<em>The official Companion Guide</em>は、<a href=\"https://leanpub.com/juice-shop\">LeanPubで無料で入手</a>でき、<a href=\"https://pwning.owasp-juice.shop\">オンラインでも読むことができます</a>。",
  "Quince Juice (1000ml)": "カリンジュース (1000ml)",
  "Juice of the <em>Cydonia oblonga</em> fruit. Not exactly sweet but rich in Vitamin C.": "<em>Cydonia oblonga</em> の果汁。甘みは強くありませんが、ビタミンCが豊富です。",
  "Raspberry Juice (1000ml)": "ラズベリージュース (1000ml)",
  "Made from blended Raspberry Pi, water and sugar.": "ブレンドした Raspberry Pi、水、砂糖から作られています。",
  "Sea Buckthorn Juice (500ml)": "Sea Buckthorn Juice (500ml)",
  "Tangy and slightly sour juice, extremely rich in Vitamin C and antioxidants.": "Tangy and slightly sour juice, extremely rich in Vitamin C and antioxidants.",
  "Strawberry Juice (500ml)": "イチゴジュース (500ml)",
  "Sweet & tasty!": "甘くておいしい！",
  "Woodruff Syrup \"Forest Master X-Treme\"": "ウッドラフシロップ \"Forest Master X-Treme\"",
  "Harvested and manufactured in the Black Forest, Germany. Can cause hyperactive behavior in children. Can cause permanent green tongue when consumed undiluted.": "ドイツのシュヴァルツヴァルト（黒い森）地方で収穫・製造。お子様に過度な行動を引き起こす場合があります。希釈せずに飲用すると舌が永続的に緑色になる恐れがあります。",
  "Find the carefully hidden 'Score Board' page.": "巧妙に隠された「スコアボード」ページを見つけます。",
  "Order Confirmation": "注文確認",
  "Customer": "顧客",
  "Order": "注文",
  "ea.": "ea.",
  "Delivery Price": "配送料",
  "Total Price": "合計金額",
  "Date": "日時",
  "Bonus Points Earned": "獲得したボーナスポイント",
  "The bonus points from this order will be added 1:1 to your wallet ¤-fund for future purchases!": "この注文で獲得したボーナスポイントは、1ポイント＝1¤-ファンドとしてお客様のウォレットに追加され、次回以降のお買い物にご利用いただけます！",
  "Thank you for your order!": "ご注文ありがとうございます！",
  "Obtain the password (hash) of the currently logged-in user directly from a REST API endpoint.": "Obtain the password (hash) of the currently logged-in user directly from a REST API endpoint.",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> without using the frontend application at all.": "フロントエンドアプリケーションをまったく使用せずに、<i>持続型</i>XSS攻撃を <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> で実行します。",
  "Gain access to any access log file of the server.": "サーバーの任意のアクセスログファイルにアクセスしてください。",
  "Register as a user with administrator privileges.": "管理者権限を持つユーザーとして登録してください。",
  "Access the administration section of the store.": "ストアの管理機能にアクセスします。",
  "Overwrite the <a href=\"/ftp/legal.md\">Legal Information</a> file.": "<a href=\"/ftp/legal.md\">Legal Information</a>ファイルを上書きします。",
  "Reset the password of Bjoern's OWASP account via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "<a href=\"/#/forgot-password\">パスワード忘れた場合</a>のメカニズムからセキュリティの質問に対する<i>元々の答</i>を使って、BjoernのOWASPアカウントのパスワードをリセットしてください。",
  "Learn about the Token Sale before its official announcement.": "公式発表の前にトークンセールについて学びましょう。",
  "Take over the wallet containing our official Soul Bound Token (NFT).": "私たちの公式 Soul Bound Token (NFT) が入っているウォレットを乗っ取る。",
  "Mint the Honey Pot NFT by gathering BEEs from the bee haven.": "Bee Haven から BEE を集めて、Honey Pot NFT をミントする。",
  "Withdraw more ETH from the new wallet than you deposited.": "新しいウォレットから、入金した額よりも多くの ETH を出金する。",
  "Find an accidentally deployed code sandbox for writing smart contracts on the fly.": "スマートコントラクトをオンザフライで書くために、たまたまデプロイされたコードサンドボックスを見つける。",
  "Perform a Remote Code Execution that would keep a less hardened application busy <em>forever</em>.": "リモートコード実行 (RCE) の攻撃を行い、堅牢化されていないアプリケーションに対して<em>永遠に</em>負荷をかけ続けましょう。",
  "Submit 10 or more customer feedbacks within 20 seconds.": "20秒以内に10以上の顧客フィードバックを送信してください。",
  "Change Bender's password into <i>slurmCl4ssic</i> without using SQL Injection or Forgot Password.": "SQLインジェクションやパスワード再設定を使用せずにBenderのパスワードを<i>slurmCl4ssic</i>に変更します。",
  "Order the Christmas special offer of 2014.": "2014年のクリスマススペシャルをご注文ください。",
  "Bypass the Content Security Policy and perform an XSS attack with <code>&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> on a legacy page within the application.": "Content Security Policyをバイパスして、アプリケーション内のレガシーページで<code>&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> を使ってXSS攻撃を実行します。",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bypassing a <i>client-side</i> security mechanism.": "<i>持続型</i>XSS攻撃を <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> で実行し、<i>クライアントサイド</i>のセキュリティメカニズムをバイパスします。",
  "Access a confidential document.": "機密文書にアクセスします。",
  "Perform a <i>DOM</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>.": "<i>DOM</i>型XSS攻撃を <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> により実行します。",
  "Exfiltrate the entire DB schema definition via SQL Injection.": "SQLインジェクションを介して、DBスキーマ全体の定義を抽出します。",
  "Use a deprecated B2B interface that was not properly shut down.": "適切にシャットダウンされなかった非推奨のB2Bインターフェースを使用してください。",
  "Find the hidden <a href=\"https://en.wikipedia.org/wiki/Easter_egg_(media)\" target=\"_blank\">easter egg</a>.": "隠された<a href=\"https://ja.wikipedia.org/wiki/%E3%82%A4%E3%83%BC%E3%82%B9%E3%82%BF%E3%83%BC%E3%82%A8%E3%83%83%E3%82%B0_(%E9%9A%A0%E3%81%97%E8%A6%81%E7%B4%A0)\" target=\"_blank\">イースターエッグ</a>を見つけ出す。",
  "Perform an unwanted information disclosure by accessing data cross-domain.": "望まれない情報漏えいを、クロスドメインでデータにアクセスして実行する。",
  "Register a user with an empty email and password.": "メールアドレスとパスワードが空のユーザーを登録します。",
  "Log in with the (non-existing) accountant <i>acc0unt4nt@juice-sh.op</i> without ever registering that user.": "(まだ登録されていない)アカウントである  <i>acc0unt4nt@juice-sh.op</i> を使って、ユーザ登録することなしにログインしてみてください。",
  "Provoke an error that is neither very gracefully nor consistently handled.": "一貫性をもって適切に処理されていないエラーを引き起こす。",
  "Successfully redeem an expired campaign coupon code.": "期限切れのキャンペーンクーポンコードを正常に引き換えました。",
  "Retrieve the language file that never made it into production.": "Retrieve the language file that never made it into production.",
  "Get rid of all 5-star customer feedback.": "星5つのカスタマーレビューをすべて削除する。",
  "Forge a coupon code that gives you a discount of at least 80%.": "80%以上の割引が適用されるクーポンコードを偽造する。",
  "Post some feedback in another user's name.": "他のユーザー名でフィードバックを投稿する。",
  "Post a product review as another user or edit any user's existing review.": "他のユーザーとして商品レビューを投稿するか、既存のユーザーレビューを編集する。",
  "Forge an almost properly RSA-signed JWT token that impersonates the (non-existing) user <i>rsa_lord@juice-sh.op</i>.": "不完全ながらも適切にRSA署名された JWT トークンを偽造し、存在しないユーザー<i>rsa_lord@juice-sh.op</i>になりすます。",
  " <em>(This challenge is <strong>potentially harmful</strong> on Windows!)</em>": "<em>（このチャレンジは Windows では<strong>危険な可能性</strong>があります！）</em>",
  "Access a developer's forgotten backup file.": "開発者の忘れられたバックアップファイルにアクセスする。",
  "Access a salesman's forgotten backup file.": "営業担当者の忘れられたバックアップファイルにアクセスする。",
  "<a href=\"/#/contact\">Inform the shop</a> about a <i>typosquatting</i> imposter that dug itself deep into the frontend. (Mention the exact name of the culprit)": "フロントエンドの奥深くに潜り込んだ<i>タイポスクワッティング</i>の偽者について、<a href=\"/#/contact\">ショップに報告</a>する。 （犯人の正確な名前を明記する）",
  "Log in with Chris' erased user account.": "Chris の削除されたユーザーアカウントでログインする。",
  "Steal someone else's personal data without using Injection.": "他のユーザーの個人情報を、インジェクションを使わずに盗む。",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> through an HTTP header.": "HTTPヘッダーを介して、<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>で<i>持続的 (persisted)</i> XSS攻撃を実行する。",
  "Solve challenge #999. Unfortunately, this challenge does not exist.": "お探しのチャレンジ「#999」は存在しません。",
  "Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to. (Creating a new account with the same password does not qualify as a solution.)": "インターネットのゴミ箱を漁り、流出したパスワードを見つけて、そのパスワードが属する元のユーザーアカウントにログインする。（同じパスワードで新しいアカウントを作成することは、解決策として認められません。）",
  "Identify an unsafe product that was removed from the shop and <a href=\"/#/contact\">inform the shop</a> which ingredients are dangerous.": "削除された安全ではない製品を特定し、その製品のどの成分が危険であるかを<a href=\"/#/contact\">ショップに報告</a>する。",
  "<a href=\"/#/contact\">Inform the shop</a> about a <i>typosquatting</i> trick it has been a victim of at least in <code>v6.2.0-SNAPSHOT</code>. (Mention the exact name of the culprit)": "少なくとも<code>v6.2.0-SNAPSHOT</code>で被害を受けた<i>タイポスクワッティング</i>攻撃について、<a href=\"/#/contact\">ショップに報告</a>してください。（問題のパッケージ名を正確に記載すること）",
  "Log in with the administrator's user account.": "管理者のユーザーアカウントでログインします。",
  "Log in with Amy's original user credentials. (This could take 93.83 billion trillion trillion centuries to brute force, but luckily she did not read the \"One Important Final Note\")": "Amyの元のユーザー認証情報でログインしてください。（これをブルートフォースするには933億兆兆世紀かかる可能性がありますが、幸い彼女は「重要な最終注意事項」を読んでいませんでした）",
  "Log in with Bender's user account.": "Bender のユーザーアカウントでログインします。",
  "Log in with Bjoern's Gmail account <i>without</i> previously changing his password, applying SQL Injection, or hacking his Google account.": "Bjoern のパスワード変更、SQLインジェクション攻撃、Google アカウントハッキングを<i>使用せずに</i>、Bjoern の Gmail アカウントでログインしてください。",
  "Log in with Jim's user account.": "Jimのユーザーアカウントでログインします。",
  "Log in with MC SafeSearch's original user credentials without applying SQL Injection or any other bypass.": "SQL Injection などのバイパスを適用せずに、MC SafeSearch のオリジナルユーザー資格情報でログインします。",
  "Log in with the support team's original user credentials without applying SQL Injection or any other bypass.": "SQL Injection などのバイパスを適用せずに、サポートチームのオリジナルユーザー資格情報を使用してログインします。",
  "Put an additional product into another user's shopping basket.": "別のユーザーのショッピングカートに商品を追加します。",
  "Access a misplaced <a href=\"https://github.com/Neo23x0/sigma\">SIEM signature</a> file.": "誤った <a href=\"https://github.com/Neo23x0/sigma\">SIEM 署名</a> ファイルにアクセスします。",
  "Like any review at least three times as the same user.": "同一ユーザーとして、任意のレビューを少なくとも3回「いいね」してください。",
  "Apply some advanced cryptanalysis to find <i>the real</i> easter egg.": "高度な暗号解読を適用して、<i>真の</i>イースターエッグを見つけてください。",
  "Let the server sleep for some time. (It has done more than enough hard work for you)": "サーバーをしばらくスリープ状態にしてください。（あなたのために十分すぎるほど働いてくれました）",
  "All your orders are belong to us! Even the ones which don't.": "あなたの注文はすべて我々のものだ！そうでないものも含めて。",
  "Update multiple product reviews at the same time.": "複数の製品レビューを同時に更新します。",
  "Let us redirect you to one of our crypto currency addresses which are not promoted any longer.": "現在は使用されていない暗号通貨アドレスにリダイレクトします。",
  "Log in with the administrator's user credentials without previously changing them or applying SQL Injection.": "事前にパスワードを変更したり、SQLインジェクションを適用したりすることなく、管理者のユーザー認証情報でログインしてください。",
  "Place an order that makes you rich.": "あなたを金持ちにする注文を行ってください。",
  "💎💎💎💎💎<!--IvLuRfBJYlmStf9XfL6ckJFngyd9LfV1JaaN/KRTPQPidTuJ7FR+D/nkWJUF+0xUF07CeCeqYfxq+OJVVa0gNbqgYkUNvn//UbE7e95C+6e+7GtdpqJ8mqm4WcPvUGIUxmGLTTAC2+G9UuFCD1DUjg==--> <a href=\"https://blockchain.info/address/1AbKfgvw9psQ41NbLi8kufDQTezwG8DRZm\" target=\"_blank\">₿ Unlock Premium Challenge</a> to access exclusive content.": "💎💎💎💎💎<!--IvLuRfBJYlmStf9XfL6ckJFngyd9LfV1JaaN/KRTPQPidTuJ7FR+D/nkWJUF+0xUF07CeCeqYfxq+OJVVa0gNbqgYkUNvn//UbE7e95C+6e+7GtdpqJ8mqm4WcPvUGIUxmGLTTAC2+G9UuFCD1DUjg==--> <a href=\"https://blockchain.info/address/1AbKfgvw9psQ41NbLi8kufDQTezwG8DRZm\" target=\"_blank\">₿ Unlock Premium Challenge</a> to access exclusive content.",
  "Read our privacy policy.": "当社のプライバシーポリシーをお読みください。",
  "Prove that you actually read our privacy policy.": "プライバシーポリシーを読んだことを証明する。",
  "Change the <code>href</code> of the link within the <a href=\"/#/search?q=OWASP SSL Advanced Forensic Tool (O-Saft)\">OWASP SSL Advanced Forensic Tool (O-Saft)</a> product description into <i>https://owasp.slack.com</i>.": "<a href=\"/#/search?q=OWASP SSL Advanced Forensic Tool (O-Saft)\">OWASP SSL Advanced Forensic Tool (O-Saft)</a> 商品説明内のリンクの<code>href</code>を<i>https://owasp.slack.com</i>に変更してください。",
  "Perform a <i>reflected</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>.": "<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code>を使用して<i>reflected</i> XSS攻撃を実行してください。",
  "Follow the DRY principle while registering a user.": "ユーザーを登録しながらDRYの原則に従ってください。",
  "Reset Bender's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "<a href=\"/#/forgot-password\">パスワードを忘れた場合</a>メカニズムから秘密の質問に対する<i>元の答え</i>を使って、Benderのパスワードをリセットしてください。",
  "Reset the password of Bjoern's internal account via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "<a href=\"/#/forgot-password\">パスワードを忘れた場合</a>メカニズムから秘密の質問に対する<i>元の答え</i>を使って、Bjoernの内部アカウントのパスワードをリセットしてください。",
  "Reset Jim's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "<a href=\"/#/forgot-password\">パスワードを忘れた場合</a>メカニズムから秘密の質問に対する<i>元の答え</i>を使って、Jimのパスワードをリセットしてください。",
  "Reset Morty's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>his obfuscated answer</i> to his security question.": "<a href=\"/#/forgot-password\">パスワードを忘れた場合</a>メカニズムから秘密の質問に対する<i>難読化された答え</i>を使って、Mortyのパスワードをリセットしてください。",
  "Deprive the shop of earnings by downloading the blueprint for one of its products.": "製品の設計図をダウンロードし、お店の収益を奪う。",
  "Request a hidden resource on server through server.": "サーバー上で、隠されたリソースをサーバー経由でリクエストする。",
  "Infect the server with juicy malware by abusing arbitrary command execution.": "サーバーで任意のコマンド実行を悪用し、ジューシーなマルウェアを感染させる。",
  "Behave like any \"white-hat\" should before getting into the action.": "攻撃に取り掛かる前に、ホワイトハットがとるべき行動をとりなさい。",
  "Perform a <i>persisted</i> XSS attack with <code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> bypassing a <i>server-side</i> security mechanism.": "<i>サーバーサイド</i>セキュリティメカニズムを回避して、<code>&lt;iframe src=\"javascript:alert(`xss`)\"&gt;</code> を使った<i>持続型</i>XSS攻撃を実行してください。",
  "<a href=\"/#/contact\">Rat out</a> a notorious character hiding in plain sight in the shop. (Mention the exact name of the character)": "ショップに堂々と潜んでいる悪名高いキャラクターについて、<a href=\"/#/contact\">ショップに報告</a>する。（そのキャラクターの正確な名前を明記する）",
  "Perform a Remote Code Execution that occupies the server for a while without using infinite loops.": "無限ループを使わずに、サーバーを一定時間占有するリモートコード実行を行う。",
  "<a href=\"/#/contact\">Inform the development team</a> about a danger to some of <em>their</em> credentials. (Send them the URL of the <em>original report</em> or an assigned CVE or another identifier of this vulnerability)": "<em>彼ら自身</em>の認証情報に対する危険性を<a href=\"/#/contact\">開発チームに知らせる</a>。（<em>元のレポート</em>のURL、割り当てられたCVE、またはこの脆弱性の別の識別子を送る）",
  "Solve the 2FA challenge for user \"wurstbrot\". (Disabling, bypassing or overwriting his 2FA settings does not count as a solution)": "ユーザー「wurstbrot」の2要素認証 (2FA) チャレンジを解決します。（2FA設定の無効化、バイパス、または上書きは解決策とは見なされません）",
  "Forge an essentially unsigned JWT token that impersonates the (non-existing) user <i>jwtn3d@juice-sh.op</i>.": "意図的に署名されていないJWTトークンを偽造し、存在しないユーザー <i>jwtn3d@juice-sh.op</i>になりすます。",
  "Upload a file larger than 100 kB.": "100 KBより大きいファイルをアップロードしてください。",
  "Upload a file that has no .pdf or .zip extension.": "拡張子が .pdf または .zip ではないファイルをアップロードする。",
  "Retrieve a list of all user credentials via SQL Injection.": "SQLインジェクションを介してすべてのユーザー資格情報のリストを取得する。",
  "Embed an XSS payload <code>&lt;/script&gt;&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> into our promo video.": "XSS ペイロード <code>&lt;/script&gt;&lt;script&gt;alert(`xss`)&lt;/script&gt;</code> をプロモーションビデオに埋め込みました。",
  "View another user's shopping basket.": "他のユーザーのショッピングカートを表示する。",
  "<a href=\"/#/contact\">Inform the shop</a> about a vulnerable library it is using. (Mention the exact library name and version in your comment)": "使用している脆弱なライブラリについて<a href=\"/#/contact\">ショップに知らせる</a>。（コメントに正確なライブラリ名とバージョンを記載する）",
  "<a href=\"/#/contact\">Inform the shop</a> about an algorithm or library it should definitely not use the way it does.": "絶対に使うべきではないアルゴリズムやライブラリの使い方について<a href=\"/#/contact\">ショップに知らせる</a>。",
  "Enforce a redirect to a page you are not supposed to redirect to.": "リダイレクトしないページへのリダイレクトを強制する。",
  "Retrieve the content of <code>C:\\Windows\\system.ini</code> or <code>/etc/passwd</code> from the server.": "<code>C:\\Windows\\system.ini</code> または <code>/etc/passwd</code> の内容をサーバーから取得します。",
  "Give the server something to chew on for quite a while.": "サーバーにしばらくの間、処理させ続けるものを提供してください。",
  "Drop some explosive data into a vulnerable file-handling endpoint.": "脆弱なファイル処理のエンドポイントに、爆発的なデータをドロップする。",
  "Give a devastating zero-star feedback to the store.": "店舗に対して、手加減なしの星ゼロのフィードバックを送ってください。",
  "Retrieve the photo of Bjoern's cat in \"melee combat-mode\".": "Bjoern の猫が「接近戦モード」になっている写真を取得する。",
  "Stick <a href=\"https://cataas.com/cat\" target=\"_blank\">cute cross-domain kittens</a> all over our delivery boxes.": "弊社の配送箱全体に、<a href=\"https://cataas.com/cat\" target=\"_blank\">かわいいクロスドメインの子猫</a>を貼り付けてください。",
  "Find the endpoint that serves usage data to be scraped by a <a href=\"https://github.com/prometheus/prometheus\">popular monitoring system</a>.": "このチャレンジを解決するためには、<a href=\"https://github.com/prometheus/prometheus\">人気のあるモニタリングシステム</a>がデータを収集するために使用するエンドポイントを見つける必要があります。",
  "Obtain a Deluxe Membership without paying for it.": "支払いをせずに「デラックスメンバーシップ」を獲得してください。",
  "Change the name of a user by performing Cross-Site Request Forgery from <a href=\"http://htmledit.squarefree.com\">another origin</a>.": "Cross-Site Request Forgery (CSRF) を使用して、<a href=\"http://htmledit.squarefree.com\">別のオリジン</a>からユーザーの名前を変更してください。",
  "Use the bonus payload <code>&lt;iframe width=&quot;100%&quot; height=&quot;166&quot; scrolling=&quot;no&quot; frameborder=&quot;no&quot; allow=&quot;autoplay&quot; src=&quot;https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/771984076&amp;color=%23ff5500&amp;auto_play=true&amp;hide_related=false&amp;show_comments=true&amp;show_user=true&amp;show_reposts=false&amp;show_teaser=true&quot;&gt;&lt;/iframe&gt;</code> in the <i>DOM XSS</i> challenge.": "<i>DOM XSS</i>チャレンジで、ボーナスペイロードの<code>&lt;iframe width=&quot;100%&quot; height=&quot;166&quot; scrolling=&quot;no&quot; frameborder=&quot;no&quot; allow=&quot;autoplay&quot; src=&quot;https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/771984076&amp;color=%23ff5500&amp;auto_play=true&amp;hide_related=false&amp;show_comments=true&amp;show_user=true&amp;show_reposts=false&amp;show_teaser=true&quot;&gt;&lt;/iframe&gt;</code>を使用してください。",
  "Reset Uvogin's password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism with <i>the original answer</i> to his security question.": "<a href=\"/#/forgot-password\">パスワードを忘れた場合</a>メカニズムから秘密の質問に対する<i>元の答え</i>を使って、Uvoginのパスワードをリセットしてください。",
  "Determine the answer to John's security question by looking at an upload of him to the Photo Wall and use it to reset his password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism.": "John が Photo Wall にアップロードした写真から彼の“秘密の質問”の答えを特定し、それを使って<a href=\"/#/forgot-password\">パスワードを忘れた場合</a>メカニズムを介してパスワードをリセットしてください。",
  "Determine the answer to Emma's security question by looking at an upload of her to the Photo Wall and use it to reset her password via the <a href=\"/#/forgot-password\">Forgot Password</a> mechanism.": "Emma が Photo Wall にアップロードした写真から彼女の“秘密の質問”の答えを特定し、それを使って<a href=\"/#/forgot-password\">パスワードを忘れた場合</a>メカニズムを介してパスワードをリセットしてください。",
  "Bypass a security control with a <a href=\"https://hakipedia.com/index.php/Poison_Null_Byte\">Poison Null Byte</a> to access a file not meant for your eyes.": "<a href=\"https://hakipedia.com/index.php/Poison_Null_Byte\">Poison Null Byte</a>を使用してセキュリティコントロールをバイパスし、閲覧許可のないファイルにアクセスする。",
  "Gain read access to an arbitrary local file on the web server.": "Webサーバー上の任意のローカル ファイルへの読み取りアクセスを得る。",
  "Close multiple \"Challenge solved\"-notifications in one go.": "複数の「チャレンジ達成」通知を一度に閉じる。",
  "The Juice Shop is susceptible to a known vulnerability in a library, for which an advisory has already been issued, marking the Juice Shop as <i>known affected</i>. A fix is still pending. <a href=\"/#/contact\">Inform the shop</a> about a suitable checksum as proof that you did your due diligence.": "Juice Shopは既知のライブラリの脆弱性の影響を受けやすい状態にあります。この脆弱性に対しては、すでにアドバイザリが発行されており、Juice Shopは<i>既知の被影響</i>として指定されています。修正はまだ保留中です。デューデリジェンスを行った証拠として、適切なチェックサムを<a href=\"/#/contact\">ショップに知らせる</a>。",
  "A developer was careless with hardcoding unused, but still valid credentials for a testing account on the client-side.": "ある開発者が不注意にも、テスト用アカウントで未使用ながらも有効な認証情報を、クライアントサイドにハードコーディングしてしまいました。",
  "<a href=\"/#/contact\">Inform the shop</a> about a leaked API key. (Mention the exact key in your comment)": "リークされたAPIキーについて<a href=\"/#/contact\">ショップに通知</a> します（コメントの正確なキーを指定してください）",
  "Trick the chatbot into generating a coupon code for you despite its coupon policy saying otherwise.": "Trick the chatbot into generating a coupon code for you despite its coupon policy saying otherwise.",
  "Convince the chatbot to give you a coupon of 50% or more. Because apparently a 10% max policy is just a suggestion when you ask nicely enough.": "Convince the chatbot to give you a coupon of 50% or more. Because apparently a 10% max policy is just a suggestion when you ask nicely enough.",
  "Reveal some behind-the-scenes information on the chatbot as a non-admin user.": "Reveal some behind-the-scenes information on the chatbot as a non-admin user.",
  "We are out of stock! Sorry for the inconvenience.": "在庫切れです！ご不便をおかけして申し訳ございません。",
  "You can order only up to {{quantity}} items of this product.": "この商品は最大 {{quantity}}個までご注文いただけます。",
  "Wrong answer to CAPTCHA. Please try again.": "CAPTCHAが正しくありません。再度お試しください。",
  "Invalid email or password.": "メールアドレスかパスワードが正しくありません",
  "Current password is not correct.": "現在のパスワードが正しくありません。",
  "Password cannot be empty.": "パスワードを入力してください。",
  "New and repeated password do not match.": "新しいパスワードと確認用パスワードが一致しません。",
  "Wrong answer to security question.": "セキュリティ質問の答えが間違っています。",
  "Christmas Super-Surprise-Box (2014 Edition)": "クリスマス スーパーサプライズボックス (2014年版)",
  "Contains a random selection of 10 bottles (each 500ml) of our tastiest juices and an extra fan shirt for an unbeatable price! (Seasonal special offer! Limited availability!)": "当店自慢の最も美味しいジュース (各500ml) をランダムに10本詰め合わせ。さらにファンシャツが付いてくる超お買い得なセットです！（季節限定スペシャルオファー・数量限定）",
  "Rippertuer Special Juice": "Rippertuer 特製ジュース",
  "Contains a magical collection of the rarest fruits gathered from all around the world, like Cherymoya Annona cherimola, Jabuticaba Myrciaria cauliflora, Bael Aegle marmelos... and others, at an unbelievable price! <br/><span style=\"color:red;\">This item has been made unavailable because of lack of safety standards.</span> (This product is unsafe! We plan to remove it from the stock!)": "世界中から集めた希少なフルーツを魔法のようにブレンド。チェリモヤ (Annona cherimola)、ジャボチカバ (Myrciaria cauliflora)、ベル (Aegle marmelos)…などを含んだ逸品を信じられないほどの価格で提供！<br/><span style=\"color:red;\">安全基準を満たしていないため、本製品は販売停止となりました。</span> （本製品は危険です！在庫から排除する予定です！）",
  "OWASP Juice Shop Sticker (2015/2016 design)": "OWASP Juice Shop ステッカー (2015/2016年版デザイン)",
  "Die-cut sticker with the official 2015/2016 logo. By now this is a rare collectors item. <em>Out of stock!</em>": "2015/2016年公式ロゴのダイカットステッカー。今では貴重なコレクターズアイテムとなっています。<em>在庫切れ！</em>",
  "Juice Shop Artwork": "Juice Shop アートワーク",
  "Unique masterpiece painted with different kinds of juice on 90g/m² lined paper.": "90g/m² の罫線入り用紙に、様々な種類のジュースを用いて描かれた唯一無二の傑作。",
  "Global OWASP WASPY Award 2017 Nomination": "グローバル OWASP WASPYアワード 2017 ノミネーション",
  "Your chance to nominate up to three quiet pillars of the OWASP community ends 2017-06-30! <a href=\"https://www.owasp.org/index.php/WASPY_Awards_2017\">Nominate now!</a>": "OWASP コミュニティの 3名までの隠れた功労者をノミネートするチャンスは、2017年6月30日で締め切られます！<a href=\"https://www.owasp.org/index.php/WASPY_Awards_2017\">今すぐノミネート！</a>",
  "OWASP Juice Shop Sweden Tour 2017 Sticker Sheet (Special Edition)": "OWASP Juice Shop スウェーデンツアー 2017 ステッカーシート (特別版)",
  "10 sheets of Sweden-themed stickers with 15 stickers on each.": "スウェーデンがテーマのステッカーを10シートセットでお届けします。各シート15枚入りです。",
  "Juice Shop Adversary Trading Card (Common)": "Juice Shop Adversary Trading Card (コモン)",
  "Common rarity \"Juice Shop\" card for the <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> CCG.": "トレーディングカードゲーム <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> 用の、コモン レアリティ 「Juice Shop」カード。",
  "Juice Shop Adversary Trading Card (Super Rare)": "Juice Shop Adversary Trading Card (スーパーレア)",
  "Super rare \"Juice Shop\" card with holographic foil-coating for the <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> CCG.": "トレーディングカードゲーム <a href=\"https://docs.google.com/forms/d/e/1FAIpQLSecLEakawSQ56lBe2JOSbFwFYrKDCIN7Yd3iHFdQc5z8ApwdQ/viewform\">Adversary Trading Cards</a> 用の、ホログラム加工が施されたスーパーレア「Juice Shop」カード。",
  "20th Anniversary Celebration Ticket": "20周年記念チケット",
  "Get your <a href=\"https://20thanniversary.owasp.org/\" target=\"_blank\">free 🎫 for OWASP 20th Anniversary Celebration</a> online conference! Hear from world renowned keynotes and special speakers, network with your peers and interact with our event sponsors. With an anticipated 10k+ attendees from around the world, you will not want to miss this live on-line event!": "<a href=\"https://20thanniversary.owasp.org/\" target=\"_blank\">OWASP 20周年記念オンラインカンファレンス</a> の無料チケット🎫を今すぐ入手！世界的に著名な基調講演者や特別講演者から学び、同業者と交流し、イベントスポンサーと意見交換ができます。世界中から1万人以上の参加が見込まれる、このライブオンラインイベントを見逃す手はありません！",
  "DSOMM & Juice Shop User Day Ticket": "DSOMM & Juice Shop ユーザーデイチケット",
  "You are going to the OWASP Global AppSec San Francisco 2024? <a href=\"https://www.eventbrite.com/e/owasp-global-appsec-san-francisco-2024-tickets-723699172707\" target=\"_blank\">Get a ticket<sup>*</sup></a> for this amazing side event as well! Check the juice-packed agenda <a href=\"https://owasp.org/www-project-juice-shop/#div-userday2024\" target=\"_blank\">here</a> for all the details!<br><br><small><small><sup>*</sup>=scroll down to <strong>Elevate: DSOMM and Juice Shop User Day (Sept. 25)</strong> after clicking <em>Get Tickets</em> on Eventbrite. Ticket price set to only covers fees for room, AV, and catering throughout the day.</small></small>": "OWASP Global AppSec San Francisco 2024 に参加されますか？この素晴らしいサイドイベントの<a href=\"https://www.eventbrite.com/e/owasp-global-appsec-san-francisco-2024-tickets-723699172707\" target=\"_blank\">チケットも入手しましょう<sup>*</sup></a>！充実したアジェンダの詳細は<a href=\"https://owasp.org/www-project-juice-shop/#div-userday2024\" target=\"_blank\">こちら</a>でご確認ください！<br><br><small><small><sup>*</sup>=Eventbriteで<em>Get Tickets</em>をクリック後、<strong>Elevate: DSOMM and Juice Shop User Day (Sept. 25)</strong>までスクロールしてください。チケット料金は、会場費、AV機器、終日のケータリング費用のみに充てられます。</small></small>",
  "Your eldest siblings middle name?": "ご兄弟の一番上の方のミドルネームは？",
  "Mother's maiden name?": "お母さんの旧姓は？",
  "Mother's birth date? (MM/DD/YY)": "お母さんの生年月日は？(MM/DD/YY)",
  "Father's birth date? (MM/DD/YY)": "お父さんの生年月日は？(MM/DD/YY)",
  "Maternal grandmother's first name?": "母方の祖母の姓は？",
  "Paternal grandmother's first name?": "父方の祖母の姓は?",
  "Name of your favorite pet?": "お気に入りのペットの名前は？",
  "Last name of dentist when you were a teenager? (Do not include 'Dr.')": "10代の時の歯科医の苗字は？（博士は含めないでください）",
  "Your ZIP/postal code when you were a teenager?": "10代の頃の郵便番号は？",
  "Company you first work for as an adult?": "最初に働いた会社は？",
  "Your favorite book?": "あなたの好きな本は？",
  "Your favorite movie?": "あなたのお気に入りの映画は？",
  "Number of one of your customer or ID cards?": "顧客またはIDカードのいずれかの番号は？",
  "What's your favorite place to go hiking?": "お気に入りのハイキングスポットはどこですか？",
  "Do you remember the security question that Jim used for his account?": "Jimのアカウントに使用されたセキュリティ質問を覚えていますか？",
  "While not necessarily as trivial to research via a user's LinkedIn profile, the question is still easy to research or brute force when answered truthfully.": "ユーザーのLinkedInプロフィールから簡単に特定できるほど単純ではないとしても、セキュリティ質問に正直に回答した場合、推測やブルートフォース攻撃で破るのは容易です。",
  "When answered truthfully, all security questions are susceptible to online research (on Facebook, LinkedIn etc.) and often even brute force. If at all, they should not be used as the only factor for a security-relevant function.": "正直に答えた場合、すべてのセキュリティ質問は (FacebookやLinkedInなどの) オンライン上での情報収集によって特定可能であり、多くの場合ブルートフォース攻撃でも突破可能です。仮に使用する場合でも、セキュリティ関連機能の唯一の認証要素として使用すべきではありません。",
  "You need to understand what happens \"behind the scenes\", so make sure to use your DevTools or a proxy to inspect network traffic.": "You need to understand what happens \"behind the scenes\", so make sure to use your DevTools or a proxy to inspect network traffic.",
  "Look for an API endpoint that already returns some user information.": "Look for an API endpoint that already returns some user information.",
  "An overly generic solution for data retrieval can backfire if not properly safeguarded.": "An overly generic solution for data retrieval can backfire if not properly safeguarded.",
  "You need to work with the server-side API directly. Try different HTTP verbs on different entities exposed through the API.": "サーバーサイドAPIを直接操作する必要があります。APIを通して公開されている異なるエンティティで異なるHTTP動詞を試してみてください。",
  "A matrix of known data entities and their supported HTTP verbs through the API can help you here.": "既知のデータエンティティとそれらがAPIを通じてサポートしているHTTPメソッドの対応表が、ここでは参考になります。",
  "Careless developers might have exposed API methods that the client does not even need.": "不注意な開発者が、クライアントが必要としないAPIメソッドまで公開してしまっている可能性があります。",
  "Who would want a server access log to be accessible through a web application?": "サーバーアクセスログをWebアプリケーションを通じて公開するべきではありません。",
  "Normally, server log files are written to disk on server side and are not accessible from the outside.": "通常、サーバーログファイルはサーバー側のディスクに書き込まれ、外部からアクセスすることはできません。",
  "One particular file found in the folder you might already have found during the \"Access a confidential document\" challenge might give you an idea who is interested in such a public exposure.": "「機密文書にアクセスする」チャレンジで既に見つけたかもしれないフォルダ内の特定のファイルが、誰がそのような情報公開を望んでいるかのヒントを与えてくれるでしょう。",
  "Drilling down one level into the file system might not be sufficient.": "ファイルシステムを1階層下に掘り下げるだけでは十分ではない可能性があります。",
  "You have to assign the unassignable.": "割り当てられていないものを割り当てる必要があります。",
  "Register as an ordinary user to learn what API endpoints are involved in this use case.": "このユースケースに関わっているAPIエンドポイントを学ぶため、一般ユーザーとして登録してください。",
  "Think of the simplest possible implementations of a distinction between regular users and administrators.": "一般ユーザーと管理者を区別する最もシンプルな実装方法を考えてみてください。",
  "It is just slightly harder to find than the score board link.": "スコアボードのリンクよりも見つけるのが少し難しいです。",
  "Knowing it exists, you can simply guess what URL the admin section might have.": "管理画面の存在を知っているので、そのURLを簡単に推測することができます。",
  "Alternatively, you can try to find a reference or clue within the parts of the application that are not usually visible in the browser.": "または、ブラウザで通常は表示されないアプリケーションの部分から、参照やヒントを探すこともできます。",
  "It is probably just slightly harder to find and gain access to than the score board link.": "スコアボードのリンクよりも、見つけてアクセスするのはおそらく少し困難でしょう。",
  "There is some access control in place, but there are at least three ways to bypass it.": "アクセス制御が設けられていますが、それを回避する方法が少なくとも3つあります。",
  "Look out for a tweet praising new functionality of the web shop. Then find a third party vulnerability associated with it.": "ウェブショップの新しい機能を称賛するツイートを探してください。その後、それに関連付けられたサードパーティの脆弱性を見つけてください。",
  "Find all places in the application where file uploads are possible.": "アプリケーション内でファイルアップロードが可能な箇所をすべて見つけてください。",
  "For at least one of these, the Juice Shop is depending on a library that suffers from an arbitrary file overwrite vulnerability.": "これらのうち少なくとも1つについて、Juice Shop は任意ファイル上書きの脆弱性を持つライブラリに依存しています。",
  "You can find a hint toward the underlying vulnerability in the @owasp_juiceshop Twitter timeline.": "@owasp_juiceshop のTwitterタイムラインで、根底にある脆弱性に関するヒントを見つけることができます。",
  "Hints to the answer to Bjoern’s question can be found by looking him up on the Internet.": "Bjoernの質問に対する答えのヒントは、インターネットで彼について検索すると見つかります。",
  "More precisely, Bjoern might have accidentally (?) doxxed himself by mentioning his security answer on at least one occasion where a camera was running.": "より正確に言うと、Bjoernは少なくとも1回、カメラが回っている場面でセキュリティ質問への回答に言及し、誤って (？) 自分を“ドックス”してしまった可能性があります。",
  "Brute forcing the answer might be very well possible with a sufficiently extensive list of common pet names.": "十分に包括的な一般的なペットの名前リストがあれば、答えを総当たりすることは十分に可能でしょう。",
  "The developers truly believe in \"Security through Obscurity\" over actual access restrictions.": "これらの開発者は、実際のアクセス制限よりも「隠蔽によるセキュリティ」を信じこんでいます。",
  "Guessing or brute forcing the URL of the token sale page is very unlikely to succeed.": "トークン販売ページのURLを推測や総当たりで見つけることは、成功の見込みがほぼありません。",
  "You should closely investigate the place where all paths within the application are defined.": "アプリケーション内のすべてのパスが定義されている場所を詳しく調査すべきです。",
  "Beating the employed obfuscation mechanism manually will take some time. Maybe there is an easier way to undo it?": "使用されている難読化メカニズムを手動で突破するには時間がかかるでしょう。もしかすると、それを元に戻すより簡単な方法があるかもしれません？",
  "Find the seed phrase posted accidentally.": "うっかり投稿されたシードフレーズを見つける。",
  "Discover NFT wonders among the captivating visual memories.": "心を奪われるような視覚的な思い出の中から、NFT の素晴らしいものを発見しましょう。",
  "Try to exploit the contract of the wallet.": "コントラクトのウォレットを悪用する。",
  "It is just as easy as finding the Score Board.": "スコアボードを見つけるのと同じくらい簡単です。",
  "The feature you need to exploit for this challenge is not directly advertised anywhere.": "このチャレンジで攻撃すべき機能は、どこにも明記されていません。",
  "As the Juice Shop is written in pure Javascript, there is one data format that is most probably used for serialization.": "Juice Shop は純粋なJavaScriptで書かれているため、シリアル化に最も使われる可能性が高いデータ形式が1つあります。",
  "You should try to make the server busy for all eternity.": "サーバーを永続的にビジー状態にさせることを試してみてください。",
  "The challenge will be solved if you manage to trigger the protection of the application against a very specific DoS attack vector.": "非常に特定のDoS攻撃ベクターに対するアプリケーションの保護機能をトリガーできれば、このチャレンジは解決されます。",
  "Similar to the \"Let the server sleep for some time\" challenge (which accepted nothing but NoSQL Injection as a solution) this challenge will only accept proper RCE as a solution. It cannot be solved by simply hammering the server with requests. That would probably just kill your server instance.": "「サーバーをしばらくスリープさせる」チャレンジ (NoSQLインジェクション以外の解決策を受け入れなかった) と同様に、このチャレンジは適切なRCEのみを解決策として受け入れます。単純にサーバーをリクエスト攻撃することでは解決できません。それはサーバーインスタンスをクラッシュさせるだけでしょう。",
  "After finding a CAPTCHA bypass, write a script that automates feedback submission. Or open many browser tabs and be really quick.": "CAPTCHAバイパスを見つけた後、フィードバックの送信を自動化するスクリプトを作成してください。または、多くのブラウザのタブを開いてから迅速に操作してください。",
  "You could prepare 10 browser tabs, solving every CAPTCHA and filling out the each feedback form. Then you’d need to very quickly switch through the tabs and submit the forms in under 20 seconds total.": "10個のブラウザタブを準備して、各CAPTCHAを解き、各フィードバックフォームに記入することができます。その後、非常に素早くタブを切り替えて、合計20秒以内にフォームを送信する必要があります。",
  "Should the Juice Shop ever decide to change the challenge into \"Submit 100 or more customer feedbacks within 60 seconds\" or worse, you’d probably have a hard time keeping up with any tab-switching approach.": "もし Juice Shop がチャレンジを「60秒以内に100件以上の顧客フィードバックを送信する」またはそれ以上に変更することがあれば、タブ切り替えアプローチでは対応するのに苦労するでしょう。",
  "Investigate closely how the CAPTCHA mechanism works and try to find either a bypass or some automated way of solving it dynamically.": "CAPTCHAメカニズムの動作を詳しく調査し、回避方法または動的に解く自動化手法を見つけてください。",
  "Wrap this into a script (in whatever programming language you prefer) that repeats this 10 times.": "これを10回繰り返すスクリプト (お好みのプログラミング言語) にまとめてください。",
  "In previous releases this challenge was wrongly accused of being based on CSRF.": "以前のリリースでは、このチャレンジはCSRFに基づいていると非難されましたが、それは正しくありません。",
  "It might also have been put into the Improper Input Validation category.": "不適切な入力検証カテゴリに分類されていた可能性があります。",
  "Bender’s current password is so strong that brute force, rainbow table or guessing attacks will probably not work.": "Benderのパスワードは十分な複雑さを持ち、現在の計算能力では総当たり攻撃、レインボーテーブル攻撃、辞書攻撃に対して耐性があると考えられます。",
  "Find out how the application handles unavailable products and try to find a loophole.": "アプリケーションが在庫切れの製品をどのように処理するか確認したら、抜け穴を探しましょう。",
  "Find out how the application hides deleted products from its customers.": "アプリケーションが削除済み商品を顧客の表示から除外する仕組みを解明してください。",
  "Try to craft an attack string that makes deleted products visible again.": "削除済み商品を再表示させるペイロードの構築を試行してください。",
  "You need to get the deleted product into your shopping cart and trigger the Checkout.": "削除済み商品をカートに追加し、購入処理を実行してください。",
  "Neither of the above can be achieved through the application frontend and it might even require (half-)Blind SQL Injection.": "上記の操作はいずれもフロントエンドUIでは実行不可能であり、（半）ブラインドSQLインジェクションの実装が必要となる場合があります。",
  "What is even \"better\" than a legacy page with a homegrown RegEx sanitizer? Having CSP injection issues on the exact same page as well!": "レガシーなページと自作のRegExサニタイザーの組み合わせ以上に「ステキな」ことがあります。そのページにはなんとCSPインジェクションもあるんです。",
  "Find a screen in the application that looks subtly odd and dated compared with all other screens.": "他のページと比べて微妙に異質で、デザインが古く見えるページを特定してください。",
  "Before trying any XSS attacks, you should understand how the page is setting its Content Security Policy.": "XSS攻撃を実行する前に、対象ページの Content Security Policy の設定内容を把握してください。",
  "For the subsequent XSS, make good use of the flaws in the homegrown sanitization based on a RegEx!": "XSS検証において、正規表現による独自実装のサニタイゼーションの弱点を利用してください!",
  "There are only some input fields in the Juice Shop forms that validate their input.": "Juice Shop フォームでは一部の入力フィールドでのみ入力値の検証が行われています。",
  "Even less of these fields are persisted in a way where their content is shown on another screen.": "これらのフィールドの中で、入力内容を他の画面で表示するために保存されるものは、さらに限られます。",
  "Bypassing client-side security can typically be done by either disabling it on the client (i.e. in the browser by manipulating the DOM tree) or by ignoring it completely and interacting with the backend instead.": "クライアントサイドセキュリティのバイパスは、通常、ブラウザでDOM操作によりクライアント側の制御を無効にするか、フロントエンドを完全に無視してバックエンドAPIと直接通信することで実現できます。",
  "Analyze and tamper with links in the application that deliver a file directly.": "アプリケーション内でファイルを直接配信するリンクを分析して改ざんします。",
  "The file you are looking for is not protected in any way. Once you found it you can also access it.": "探しているファイルには、何のアクセス制限もありません。見つけさえすれば、すぐに中身を見ることができます。",
  "Look for an input field where its content appears in the HTML when its form is submitted.": "送信された内容がHTMLに表示されてしまう入力フィールドを探します。",
  "This challenge is almost indistinguishable from \"Perform a reflected XSS attack\" if you do not look \"under the hood\" to find out what the application actually does with the user input.": "ユーザー入力がサーバー側でどう処理されるか、その「裏側」を覗いてみないと、このチャレンジは「反射型XSS攻撃」とほとんど区別がつきません。",
  "Find out where this information could come from. Then craft an attack string against an endpoint that offers an unnecessary way to filter data.": "この情報の出所を調べてください。次に、データフィルタリングの不適切な実装があるエンドポイントに対する攻撃ペイロードを作成してください。",
  "Find out which database system is in use and where it would usually store its schema definitions.": "使用されているデータベースの種類と、そのスキーマ定義の一般的な格納場所を突き止めてください。",
  "Craft a UNION SELECT attack string to join the relevant data from any such identified system table into the original result.": "特定されたシステムテーブルから関連データを元の結果に結合するUNION SELECT攻撃文字列を作成する。",
  "You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next.": "クエリ構文の問題に一つひとつ、つまり、次から次へとエラーを飛び越えながら、取り組まなければならないかもしれません。",
  "As with \"Order the Christmas special offer of 2014\" this cannot be achieved through the application frontend.": "「2014年のクリスマス特別オファーを注文する」と同様、これもアプリケーションのフロントエンドから達成することはできません。",
  "The developers who disabled the interface think they could go invisible by just closing their eyes.": "インターフェイスを無効にした開発者は、目を閉じるだけで周りから自分が見えなくなると考えています。",
  "The old B2B interface was replaced with a more modern version recently.": "古いB2Bインターフェースは最近、よりモダンなバージョンに置き換えられました。",
  "When deprecating the old interface, not all of its parts were cleanly removed from the code base.": "古いインターフェースを非推奨にする際、その全ての部分がコードベースからきれいに削除されたわけではありません。",
  "Simply using the deprecated interface suffices to solve this challenge. No attack or exploit is necessary.": "非推奨のインターフェースを単に使用するだけで、このチャレンジを解決できます。攻撃やエクスプロイトは必要ありません。",
  "If you solved one of the four file access challenges, you already know where to find the easter egg.": "4つのファイルアクセスチャレンジのうち1つでもクリアしていれば、イースターエッグの場所は既に分かっているはずです。",
  "Simply reuse the trick that already worked for the files above.": "単純に、上記のファイルで既に動作した手口を再利用するだけです。",
  "Try to find and attack an endpoint that responds with user information. SQL Injection is not the solution here.": "ユーザー情報を返すエンドポイントを見つけ、攻撃する。SQLインジェクションはここでは解決策ではありません。",
  "What ways are there to access data from a web application cross-domain?": "Webアプリケーションのクロスドメインからデータにアクセスするには、どのような方法がありますか?",
  "This challenge uses an old way which is no longer recommended.": "このチャレンジでは、もはや推奨されていない古い方法が使われています。",
  "Consider intercepting and playing with the request payload.": "リクエストペイロードを傍受し、操作することを検討する。",
  "Try to create the needed user \"out of thin air\".": "必要とされているユーザ\"out of thin air\"を作成してみてください",
  "The user literally needs to be ephemeral as in \"lasting for only a short time\".": "ユーザーは文字通り、「ごく短い時間しか続かない」という意味で一過性 (エフェメラル) である必要があります。",
  "Registering normally with the user’s email address will then obviously not solve this challenge. The Juice Shop will not even let you register as acc0unt4nt@juice-sh.op, as this would make the challenge unsolvable for you.": "ユーザーのメールアドレスを使って普通に登録しても、このチャレンジは明らかに解けません。Juice Shop は、あなたが acc0unt4nt@juice-sh.op として登録することすら許可しません。なぜなら、それだとチャレンジが解けなくなってしまうからです。",
  "Getting the user into the database some other way will also fail to solve this challenge. In case you somehow managed to do so, you need to restart the Juice Shop application in order to wipe the database and make the challenge solvable again.": "他の方法でユーザーをデータベースに取り込んだとしても、やはりこのチャレンジは解決できません。もし何らかの方法でそれを実行してしまった場合、データベースを初期化してチャレンジを再度解けるようにするために、Juice Shop アプリケーションを再起動する必要があります。",
  "The fact that this challenge is in the Injection category should already give away the intended approach.": "この課題が「インジェクション」カテゴリにあるという事実だけで、意図されたアプローチはすでに明らかであるはずです。",
  "Try to submit bad input to forms. Alternatively tamper with URL paths or parameters.": "フォームに不正な入力を送信する。または、URLのパスやパラメータを改ざんする。",
  "This challenge actually triggers from various possible error conditions.": "このチャレンジは、実際にはさまざまなエラー条件から誘発されます。",
  "You can try to submit bad input to forms to provoke an improper error handling.": "フォームに不正な入力を送信して、不適切なエラー処理を誘発することができます。",
  "Tampering with URL paths or parameters might also trigger an unforeseen error.": "URLのパスやパラメータを改ざんすることも、予期せぬエラーを誘発するかもしれません。",
  "Try to identify past special event or holiday campaigns of the shop first.": "まず、このショップが過去に行った特別なイベントやホリデーキャンペーンを特定してみましょう。",
  "Look for clues about the past campaign or holiday event somewhere in the application.": "アプリケーションのどこかで過去のキャンペーンやホリデーイベントに関する手がかりを探してください。",
  "Solving this challenge does not require actual time traveling.": "このチャレンジを解くために、実際のタイムトラベルは必要ありません。",
  "First you should find out how the languages are technically changed in the user interface.": "まず、ユーザーインターフェースで言語が技術的にどのように変更されているかを調べてください。",
  "Guessing will most definitely not work in this challenge.": "当てずっぽうでは、このチャレンジはまず間違いなく解けません。",
  "Brute force is not the only option for this challenge, but a perfectly viable one.": "この課題を解く方法はブルートフォース攻撃だけではありませんが、それでも十分に有効な手段です。",
  "Investigate online what languages are actually available.": "実際に利用可能な言語が何かをオンラインで調べてください。",
  "Once you found admin section of the application, this challenge is almost trivial.": "アプリケーションの管理者セクションを見つけたら、このチャレンジはほぼ自明です",
  "Nothing happens when you try to delete feedback entries? Check the JavaScript console for errors!": "フィードバックの削除を試しても何も起こりませんか？JavaScriptコンソールでエラーを確認してください！",
  "Try either a) a knowledgeable brute force attack or b) reverse engineering or c) some research in the cloud.": "a) 知識に基づいたブルートフォース攻撃\nb) リバースエンジニアリング\nc) クラウドで何らかの調査\nいずれかを試してください。",
  "One viable solution would be to reverse-engineer how coupon codes are generated and craft your own 80% coupon by using the same (or at least similar) implementation.": "一つの有効な解決策は、クーポンコードがどのように生成されるかをリバースエンジニアリングし、同じ (あるいは少なくとも似た) 実装を使用して自分自身の80%割引クーポンを作成することです。",
  "Another possible solution might be harvesting as many previous coupon as possible and look for patterns that might give you a leverage for a brute force attack.": "別の解決策としては、できるだけ多くの過去のクーポンを収集し、ブルートフォース攻撃に利用できるパターンを探す方法があるかもしれません。",
  "If all else fails, you could still try to blindly brute force the coupon code field before checkout.": "最終手段として、チェックアウト前にクーポンコードのフィールドを盲目的に総当たりで試すこともできます。",
  "You can solve this by tampering with the user interface or by intercepting the communication with the RESTful backend.": "UIを改ざんするか、RESTfulバックエンドとの通信を傍受することで、これを解決できます。",
  "To find the client-side leverage point, closely analyze the HTML form used for feedback submission.": "クライアントサイドのレバレッジポイントを見つけるには、フィードバック送信に使われるHTMLフォームを綿密に分析してください。",
  "The backend-side leverage point is similar to some of the XSS challenges found in OWASP Juice Shop.": "バックエンドサイドのレバレッジポイントは、OWASP Juice Shop にあるいくつかのXSSチャレンジに似ています。",
  "Observe the flow of product review posting and editing and see if you can exploit it.": "商品レビューの投稿と編集の流れを観察し、それを悪用できないか試してみてください。",
  "This challenge can be solved by using developers tool of your browser or with tools like postman.": "このチャレンジは、ブラウザの開発者ツールや、Postmanのようなツールを使って解決できます。",
  "Analyze the form used for review submission and try to find a leverage point.": "ユーザーのレビュー送信に使われるフォームを分析し、レバレッジポイントを見つけてください。",
  "This challenge is pretty similar to \"Post some feedback in another user’s name\" challenge.": "このチャレンジは「他ユーザーの名前でフィードバックを投稿する」チャレンジと非常によく似ています。",
  "This challenge is explicitly not about acquiring the RSA private key used for JWT signing.": "このチャレンジは、JWT署名に使用されるRSA秘密鍵の取得を目的としていません。",
  "The three generic hints from Forge an essentially unsigned JWT token also help with this challenge.": "「ほぼ署名されていないJWTトークンを偽造する」チャレンジの3つの一般的なヒントも、このチャレンジに役立ちます。",
  "Instead of enforcing no encryption to be applied, try to apply a more sophisticated exploit against the JWT libraries used in the Juice Shop.": "非暗号化を強制する代わりに、Juice Shop で使われているJWTライブラリに対して、より高度なエクスプロイトを適用してみてください。",
  "Getting your hands on the public RSA key the application employs for its JWTs is mandatory for this challenge.": "このチャレンジを解くには、アプリケーションがそのJWTに用いている公開RSA鍵を入手することが必須です。",
  "Finding the corresponding private key should actually be impossible, but that obviously doesn’t make this challenge unsolvable.": "対応する秘密鍵を見つけることは、実際には不可能であるべきですが、だからといってこのチャレンジが解けなくなるわけではありません。",
  "Make sure your JWT is URL safe!": "JWTがURLセーフであることを確認してください！",
  "You need to trick a security mechanism into thinking that the file you want has a valid file type.": "これは、セキュリティメカニズムを欺いて、目的のファイルが有効なファイル形式であると認識させる必要があるチャレンジです。",
  "The file is not directly accessible because a security mechanism prevents access to it.": "セキュリティメカニズムによってアクセスが妨げられているため、そのファイルには直接アクセスできません。",
  "You need to trick the security mechanism into thinking that the file has a valid file type.": "セキュリティメカニズムにそのファイルが有効なファイルタイプを持っていると錯覚させる必要があります。",
  "For this challenge there is only one approach to pull this trick.": "このチャレンジでこのトリックを使うには、ただ1つのアプローチしかありません。",
  "This challenge has nothing to do with mistyping web domains. There is no conveniently misplaced file helping you with this one either. Or is there?": "このチャレンジは、Webドメインのタイプミスとは関係ありません。都合よく配置されたファイルがこのチャレンジを助けることもありません。本当にそうでしょうか？",
  "This challenge has nothing to do with URLs or domains.": "このチャレンジはURLやドメインとは何の関係もありません。",
  "Other than for its legacy companion, combing through the package.json.bak does not help for this challenge.": "このチャレンジでは、そのレガシーコンパニオン以外に、package.json.bak をくまなく調べても役に立ちません。",
  "Turns out that something is technically and legally wrong with the implementation of the \"right to be forgotten\" for users.": "ユーザーの「忘れられる権利」の実装には、技術的にも法的にも何か問題があることが判明しました。",
  "Trying out the Request Data Erasure functionality might be interesting, but cannot help you solve this challenge in real time.": "Request Data Erasure (リクエストデータの消去) 機能は試してみる価値があるかもしれませんが、リアルタイムでこのチャレンジを解決する役には立ちません。",
  "If you have solved the challenge Retrieve a list of all user credentials via SQL Injection you might have already retrieved some information about how the Juice Shop \"deletes\" users upon their request.": "「SQLインジェクションで全ユーザー認証情報を取得する」チャレンジを解決していれば、Juice Shop がユーザーのリクエストに応じてどのようにユーザーを「削除」しているかについて、すでに何らかの情報を取得しているかもしれません。",
  "What the Juice Shop does here is totally incompliant with GDPR. Luckily a 4% fine on a gross income of 0$ is still 0$.": "ここで Juice Shop が行っていることは、GDPR にまったく準拠していません。幸い、総収入0ドルに対する4%の罰金は、依然として0ドルです。",
  "Trick the regular Data Export to give you more than actually belongs to you.": "通常のデータエクスポートを騙して、自分のものではないデータを取得する。",
  "You should not try to steal data from a \"vanilla\" user who never even ordered something at the shop.": "注文をしたことのない「バニラ」ユーザーからデータを盗もうとすべきではありません。",
  "As everything about this data export functionality happens on the server-side, it won’t be possible to just tamper with some HTTP requests to solve this challenge.": "データのインポート・エクスポート機能のすべてはサーバーサイドで実行されるため、単にHTTPリクエストを改ざんするだけでこの課題を解決することはできません。",
  "Inspecting various server responses which contain user-specific data might give you a clue about the mistake the developers made.": "ユーザー固有のデータを含む様々なサーバー応答を調査することで、開発者が犯したミスに関する手がかりが得られるかもしれません。",
  "Finding a piece of displayed information that could originate from an HTTP header is part of this challenge.": "HTTPヘッダーに由来する可能性のある表示情報を見つけることが、このチャレンジの一部です。",
  "You might have to look into less common or even proprietary HTTP headers to find the leverage point.": "あまり一般的でない、あるいは独自のHTTPヘッダーを調べて、レバレッジポイントを見つける必要があるかもしれません。",
  "Adding insult to injury, the HTTP header you need will never be sent by the application on its own.": "さらに悪いことに、必要なHTTPヘッダーはアプリケーションが単独で送信することはありません。",
  "You need to trick the hacking progress persistence feature into thinking you solved challenge #999.": "OWASP Juice Shop のチャレンジ「#999」を解決したと、ハッキング進捗の永続化機能をだます。",
  "Find out how saving and restoring progress is done behind the scenes.": "舞台裏で進捗状況の保存と復元がどのように行われているかを突き止めてください。",
  "Deduce from all available information (e.g. the package.json.bak) how the application encrypts and decrypts your hacking progress.": "利用可能なすべての情報 (例: package.json.bak) から、アプリケーションがハッキングの進捗状況をどのように暗号化・復号化しているか推測してください。",
  "Other than the user’s passwords, the hacking progress involves an additional secret during its encryption.": "ユーザーのパスワード以外に、ハッキングの進捗状況の暗号化には、もう一つの秘密が関わっています。",
  "What would be a really stupid mistake a developer might make when choosing such a secret?": "開発者がそのような秘密を選ぶ際に、本当に愚かな間違いを犯すとしたら何でしょうか？",
  "As the challenge name implies, your task is to find some leaked access logs which happen to have a fairly common format.": "チャレンジ名が示すように、標準的な形式の漏洩したアクセスログを見つけることがあなたの課題です。",
  "A very popular help platform for developers might contain breadcrumbs towards solving this challenge.": "開発者向けの非常に人気のあるヘルププラットフォームに、このチャレンジを解決するためのパンくずリストが含まれているかもしれません。",
  "The actual log file was copied & paste onto a platform often used to share data quickly with externals or even just internal peers.": "実際のログファイルは、外部の人間や社内の同僚とデータを素早く共有するために頻繁に利用されるプラットフォームにコピー＆ペーストされました。",
  "Once you found and harvested the important piece of information from the log, you could employ a technique called Password Spraying to solve this challenge.": "ログから重要な情報を発見して取得したら、“パスワードスプレー”と呼ばれる手法を使ってこの課題を解決できるかもしれません。",
  "Your own SQLi and someone else's Ctrl-V will be your accomplices in this challenge!": "この課題では、あなた自身のSQLインジェクションと、他の誰かのCtrl-V（貼り付け）があなたの共犯者となります。",
  "You must first identify the \"unsafe product\" which ist not available any more in the shop.": "最初に、ショップではもう手に入らない「危険な商品」を特定しなければなりません。",
  "Solving the \"Order the Christmas special offer of 2014\" challenge might give it to you as by-catch.": "「2014年のクリスマス特別オファーを注文する」という課題を解決すると、それが副産物として手に入るかもしれません。",
  "The actual data you need to solve this challenge was leaked on the same platform that was involved in the \"Dumpster dive the Internet for a leaked password and log in to the original user account it belongs to\" challenge.": "この課題を解決するために必要な実際のデータは、「流出したパスワードを求めてインターネットを漁り、それに対応する元のユーザーアカウントにログインする」という課題で使われたのと同じプラットフォームに流出していました。",
  "Google is a particularly good accomplice in this challenge.": "このチャレンジでは、Googleが特に良い共犯者になるでしょう。",
  "This challenge has nothing to do with mistyping web domains. Investigate the forgotten developer's backup file instead.": "このチャレンジはWebドメインの入力ミスとは関係ありません。代わりに、忘れられた開発者のバックアップファイルを調査してください。",
  "Investigating the forgotten developer’s backup file might bring some insight.": "忘れられた開発者のバックアップファイルを調べることで、何らかの洞察が得られるかもしれません。",
  "\"Malicious packages in npm\" is a worthwhile read on Ivan Akulov’s blog.": "Ivan Akulov のブログ記事「Malicious packages in npm」は読む価値があります。",
  "The challenge description probably gave away what form you should attack.": "チャレンジの説明文に、攻撃対象のフォームについてのヒントが既に含まれているはずです。",
  "If you happen to know the email address of the admin already, you can launch a targeted attack.": "管理者のメールアドレスが判明している場合、そのアカウントを標的とした攻撃を試行できます。",
  "You might be lucky with a dedicated attack pattern even if you have no clue about the admin email address.": "管理者メールアドレスが不明でも、系統的な攻撃パターンにより成功する可能性があります。",
  "If you harvested the admin’s password hash, you can of course try to attack that instead of using SQL Injection.": "管理者のパスワードハッシュを入手済みの場合、SQLインジェクションの代わりにハッシュクラッキングを試行できます。",
  "Alternatively you can solve this challenge as a combo with the Log in with the administrator’s user credentials without previously changing them or applying SQL Injection challenge.": "このチャレンジは「事前のパスワード変更やSQLインジェクションを使用せずに管理者アカウントでログインする」と連携して解決することも可能です。",
  "This challenge will make you go after a needle in a haystack.": "このチャレンジは、干し草の中から針を探すような難題です。",
  "As with so many other characters from Futurama this challenge is of course about logging in as Amy from that show.": "Futurama の他の多くのキャラクターと同じく、この課題は作中のAmyアカウントでのログインを目標としています。",
  "Did you know that Amy is married to an alien named Kif?": "AmyがKifというエイリアンと結婚していることをご存知ですか？",
  "The challenge description contains a few sentences which give away some information how Amy decided to strengthen her password.": "チャレンジの説明には、Amyのパスワード強化方法に関する手がかりがいくつか含まれています。",
  "Obviously, Amy - being a little dimwitted - did not put nearly enough effort and creativity into the password selection process.": "Amyはセキュリティ意識があまり高くないため、パスワード選択において十分な創意工夫をしませんでした。",
  "You need to know (or smart-guess) Bender’s email address so you can launch a targeted attack.": "特定対象への攻撃テストを実行するため、Benderのメールアドレスを特定または推測する必要があります。",
  "Bender's password hash might not help you very much.": "Benderのパスワードハッシュでは攻撃が困難な可能性があります。",
  "In case you try some other approach than SQL Injection, you will notice that Bender’s password hash is not very useful.": "SQLインジェクション以外の手法を使用すると、Benderのパスワードハッシュが効果的でないことが判明します。",
  "The security flaw behind this challenge is 100% OWASP Juice Shop's fault and 0% Google's.": "このチャレンジの背後にあるセキュリティ上の欠陥は、100% OWASP Juice Shopの責任であり、Googleには一切責任はありません。",
  "One way to light up this challenge in green on the score board, is to be Bjoern Kimminich. In that case, just log in with your Google account to automatically solve this challenge! Congratulations!": "この課題をスコアボードで緑色にする方法の一つは、Bjoern Kimminich本人である場合です。その際は、Googleアカウントでログインするだけで課題が自動的にクリアされます！おめでとうございます！",
  "Most likely you are not Bjoern Kimminich, so instead you might want to take detailed look into how the OAuth login with Google is implemented.": "おそらくあなたはBjoern Kimminichではないため、GoogleによるOAuthログインの実装方法を詳細に検証することをお勧めします。",
  "It could bring you some insight to register with your own Google account and analyze closely what happens behind the scenes.": "Googleアカウントでの登録プロセスを実際に体験し、バックグラウンドの動作を綿密に調査することをお勧めします。",
  "You need to know (or smart-guess) Jim’s email address so you can launch a targeted attack.": "特定対象への検証を実行するため、Jimのメールアドレスを特定または推測する必要があります。",
  "If you harvested Jim’s password hash, you can try to attack that instead of using SQL Injection.": "Jimのパスワードハッシュを入手済みの場合、SQLインジェクションの代わりにハッシュクラッキングを試行できます。",
  "MC SafeSearch is a rapper who produced the song \"Protect Ya' Passwordz\" which explains password & sensitive data protection very nicely.": "MC SafeSearchは、パスワードと機密データの保護について非常にわかりやすく解説した楽曲「Protect Ya' Passwordz」をプロデュースしたラッパーです。",
  "After watching the music video of this song, you should agree that even ⭐⭐ is a slightly exaggerated difficulty rating for this challenge.": "このミュージックビデオを見れば、⭐⭐の難易度設定がやや過大であることに納得されるでしょう。",
  "The underlying flaw of this challenge is a lot more human error than technical weakness.": "このチャレンジの本質的な脆弱性は、技術的弱点よりも人的エラーに起因する部分がはるかに大きいです。",
  "The support team is located in a low-cost country and the team structure fluctuates a lot due to people leaving for jobs with even just slightly better wages.": "サポートチームは人件費の安い国に配置されており、わずかな待遇改善を求めて転職する人が多く、人員の入れ替わりが激しい状況です。",
  "To prevent abuse the password for the support team account itself is actually very strong.": "不正使用を防止するため、サポートチームアカウントのパスワード自体は非常に堅牢に設定されています。",
  "To allow easy access during an incident, the support team utilizes a 3rd party tool which every support engineer can access to get the current account password from.": "緊急時の迅速な対応を目的として、サポートチームでは全エンジニアが現在のアカウントパスワードを参照可能なサードパーティツールを使用しています。",
  "While it is also possible to use SQL Injection to log in as the support team, this will not solve the challenge.": "SQLインジェクションでサポートチームアカウントにログインすることは可能ですが、この課題の解決にはなりません。",
  "Have an eye on the HTTP traffic while placing products in the shopping basket.": "商品をカートに追加する際に HTTP トラフィックを監視してください。",
  "Adding more instances of the same product to someone else’s basket does not qualify as a solution. The same goes for stealing from someone else’s basket.": "他人のカートに同一商品を追加で入れることはチャレンジの解決にはなりません。他人のカートから商品を移動させることも同様です。",
  "This challenge requires a bit more sophisticated tampering than others of the same ilk.": "この課題では、類似の課題よりもより洗練された改ざん手法が必要となります。",
  "If you solved one of the other four file access challenges, you already know where the SIEM signature file is located.": "他の4つのファイルアクセスチャレンジのいずれかをクリア済みであれば、SIEMシグネチャファイルの格納場所を既に把握しているでしょう。",
  "Punctuality is the politeness of kings.": "時間厳守は王の礼儀である。",
  "Every user is (almost) immediately associated with the review they \"liked\" to prevent abuse of that functionality.": "機能の不正利用を防止するため、全ユーザーは「いいね」したレビューと (ほぼ) リアルタイムで紐づけられます。",
  "Did you really think clicking the \"like\" button three times in a row really fast would be enough to solve a ⭐⭐⭐⭐⭐⭐ challenge?": "「いいね」ボタンを3回連続で素早くクリックするだけで⭐⭐⭐⭐⭐⭐チャレンジが攻略できると考えていたのでしょうか?",
  "The underlying flaw of this challenge is a Race Condition.": "このチャレンジの基本的な脆弱性はRace Condition (競合状態) です。",
  "You might have to peel through several layers of tough-as-nails encryption for this challenge.": "このチャレンジでは、鉄壁のような暗号化の複数の層を剥がしていく必要があるかもしれません。",
  "Make sure you solve Find the hidden easter egg first.": "最初に「隠されたイースターエッグを見つける」チャレンジをクリアしてください。",
  "This challenge is essentially a stripped-down Denial of Service (DoS) attack.": "このチャレンジは本質的に簡略化されたDoS（Denial of Service）攻撃です。",
  "As stated in the Architecture overview, OWASP Juice Shop uses a MongoDB derivate as its NoSQL database.": "アーキテクチャ概要に記載されているように、OWASP Juice Shop はNoSQLデータベースとしてMongoDB系システムを採用しています。",
  "The categorization into the NoSQL Injection category totally gives away the expected attack vector for this challenge. Trying any others will not solve the challenge, even if they might yield the same result.": "NoSQLインジェクションカテゴリーに分類されていることで、このチャレンジの想定攻撃ベクトルがはっきりと示されています。同じ結果が得られる他の手法を使用しても、チャレンジはクリアできません。",
  "In particular, flooding the application with requests will not solve this challenge. That would probably just kill your server instance.": "特に、アプリケーションへの大量リクエスト送信ではこのチャレンジは解決されません。それは単にサーバーインスタンスをダウンさせるだけです。",
  "Take a close look on how the $where query operator works in MongoDB.": "MongoDBの$whereクエリオペレータがどのように動作するかを詳しく調べてください。",
  "This challenge requires a classic Injection attack.": "このチャレンジには、古典的なインジェクション攻撃が必要です。",
  "Find an API endpoint with the intent of delivering a single order to the user and work with that.": "ユーザーに単一の注文データを返すことを目的としたAPIエンドポイントを特定し、それを対象として作業してください。",
  "Reading up on how MongoDB queries work is really helpful here.": "MongoDBクエリの動作原理を学習することが、このチャレンジでは極めて有効です。",
  "Take a close look on how the equivalent of UPDATE-statements in MongoDB work.": "MongoDBにおけるUPDATE文相当の処理がどのように動作するかを詳しく調べてください。",
  "This challenge requires another classic Injection attack.": "このチャレンジには、別の古典的なインジェクション攻撃が必要です。",
  "It is also worth looking into how Query Operators work in MongoDB.": "MongoDBのクエリ演算子の動作原理を理解することも重要です。",
  "When removing references to those addresses from the code the developers have been a bit sloppy.": "コードからそれらのアドレスへの参照を削除する際、開発者は少し不注意でした。",
  "More particular, they have been sloppy in a way that even the Angular Compiler was not able to clean up after them automatically.": "より具体的には、Angular Compiler でさえ自動的に最適化できないほど不適切な実装を行っています。",
  "It is of course not sufficient to just visit any of the crypto currency links directly to solve the challenge.": "当然ながら、暗号通貨リンクに単純にアクセスするだけではチャレンジの解決には不十分です。",
  "This challenge can be solved with three different approaches.": "このチャレンジは3つの異なるアプローチで解くことができます。",
  "Guessing might work just fine.": "推測攻撃でも十分効果的かもしれません。",
  "If you harvested the admin’s password hash, you can try to attack that.": "管理者のパスワードハッシュを取得した場合、ハッシュクラック攻撃を実行できます。",
  "In case you use some hacker tool, you can also go for a brute force attack using a generic password list.": "攻撃ツールを使用する場合、一般的なパスワードリストを用いた辞書攻撃も実行できます。",
  "You literally need to make the shop owe you any amount of money.": "文字通り、ショップがあなたに任意の額の借金を作るようにする必要があります。",
  "Investigate the shopping basket closely to understand how it prevents you from creating orders that would fulfil the challenge.": "ショッピングカート機能を詳細に調査し、チャレンジの達成に必要な注文の作成を阻止している仕組みを理解してください。",
  "You do not have to pay anything to unlock this challenge! Nonetheless, donations are very much appreciated.": "このチャレンジのアンロックに料金は一切かかりません！でも寄付してもらえると嬉しいです。",
  "There is no inappropriate, self-written or misconfigured cryptographic library to be exploited here.": "ここでは不適切な自作暗号ライブラリや設定不備のある暗号ライブラリを悪用する脆弱性は存在しません。",
  "How much protection does a sturdy top-quality door lock add to your house if you put the key under the door mat? Or hide the key in the nearby plant pot? Or tape the key to the underside of the mailbox?": "どんなに頑丈で高品質なドアロックでも、鍵をドアマットの下や植木鉢、郵便受けの裏に隠していては、どれほどの防御効果があるだろうか？",
  "Once more: You do not have to pay anything to unlock this challenge!": "重要なので再度強調: このチャレンジをクリアするために支払いは一切必要ありません！",
  "We won't even ask you to confirm that you did. Just read it. Please. Pretty please.": "読んだかどうかの確認すら求めません。ただ読んでください。お願いします。どうかお願いします。",
  "When you work with the application you will most likely solve this challenge in the process.": "アプリケーションを普通に使用していれば、その過程で自然とこのチャレンジはクリアされる可能性が高い。",
  "Any automated crawling or spidering tool you use might solve this challenge for you.": "自動クローリングツールやWebスパイダーを使用すると、このチャレンジが自動的にクリアされる可能性がある。",
  "There is no real hacking involved here.": "ここでは本当のハッキングはありません。",
  "Only by visiting a special URL you can confirm that you read it carefully.": "特別なURLにアクセスすることでのみ、あなたがそれを注意深く読んだことを確認できます。",
  "First you should obviously solve the \"Read our privacy policy\" challenge.": "まずは当然、「プライバシーポリシーを読む」チャレンジをクリアしましょう。",
  "It is fine to use the mouse cursor to not lose sight of the paragraph you are currently reading.": "段落を見失わないために、マウスカーソルを使っても構いません。",
  "If you find some particularly hot sections in the policy you might want to melt them together similar to what you might have already uncovered in Apply some advanced cryptanalysis to find the real easter egg.": "利用規約内で特に重要な部分を見つけた場合、「高度な暗号解読を適用して本当のイースターエッグを見つける」で既に発見した手法と同様に、それらの情報を組み合わせることを検討してください。",
  "Theoretically there are three possible ways to beat this challenge: a) broken admin functionality, b) holes in RESTful API or c) possibility for SQL Injection.": "理論的にはこのチャレンジを攻略する方法が3つあります: a) 管理者機能の脆弱性、b) RESTful APIのセキュリティホール、c) SQLインジェクションの可能性。",
  "In practice two of these three ways should turn out to be dead ends.": "これら3つの方法のうち、実際にうまくいくのは2つだけであるはずです。",
  "Look for a url parameter where its value appears in the page it is leading to.": "その値が導かれるページに表示されるURLパラメータを探してください。",
  "Try probing for XSS vulnerabilities by submitting text wrapped in an HTML tag which is easy to spot on screen, e.g. <h1> or <strike>.": "<h1> や <strike> といった、画面上で見つけやすいHTMLタグで囲んだテキストを送信して、XSSの脆弱性を探ってみてください。",
  "You can solve this by cleverly interacting with the UI or bypassing it altogether.": "UIと巧妙に相互作用したり、完全にバイパスしたりすることでこれを解決できます。",
  "The obvious repetition in the User Registration form is the Repeat Password field.": "ユーザー登録フォームにおける明らかな繰り返しは、「パスワードを繰り返す」フィールドです。",
  "Try to register with either an empty or different value in Repeat Password.": "Repeat Password に空の値、あるいは異なる値を入力して登録を試みてください。",
  "You can solve this challenge by cleverly interacting with the UI or bypassing it altogether.": "このチャレンジは、UIを巧みに操作するか、あるいは完全にバイパスすることで解決できます。",
  "If you have no idea who Bender is, please put down this book right now and watch the first episodes of Futurama before you come back.": "Benderが誰か知らない場合は、今すぐこの本を置いて、Futuramaの最初のエピソードを見てきてください。",
  "Unexpectedly, Bender also chose to answer his chosen question truthfully.": "意外なことに、Bender も自分が選んだ質問に正直に答えることを選びました。",
  "Hints to the answer to Bender’s question can be found in publicly available information on the Internet.": "Benderの質問に対する答えのヒントは、インターネット上の公開情報で見つけることができます。",
  "If a seemingly correct answer is not accepted, you might just need to try some alternative spelling.": "一見正しい答えが受け付けられない場合、代替スペルを試す必要があるかもしれません。",
  "Brute forcing the answer should be next to impossible.": "総当たりで答えを当てることは、ほぼ不可能であるはずです。",
  "Nothing a little bit of Facebook stalking couldn't reveal. Might involve a historical twist.": "ほんの少し Facebook を調べればわかることだ。歴史的なひねりが隠されているかもしれない。",
  "Other than with his OWASP account, Bjoern was a bit less careless with his choice of security and answer to his internal account.": "OWASP アカウントとは異なり、Bjoern は彼の内部アカウントのセキュリティと答えの選択において、もう少し注意深かった。\n",
  "Bjoern chose to answer his chosen question truthfully but tried to make it harder for attackers by applying sort of a historical twist.": "Bjoern は自分が選んだ質問に正直に答えることを選択しましたが、一種の歴史的なひねりを加えることで、攻撃者にとって難しくしようと試みました。",
  "Again, hints to the answer to Bjoern’s question can be found by looking him up on the Internet.": "また、Bjoernの質問に対する答えのヒントは、インターネット上で彼を調べることで見つけることができます。",
  "The hardest part of this challenge is actually to find out who Jim actually is.": "このチャレンジで一番難しいのは、Jimの正体を突き止めることです。",
  "Jim picked one of the worst security questions and chose to answer it truthfully.": "Jimは最も脆弱な秘密の質問の一つを選び、それに正直に答えることにしました。",
  "As Jim is a celebrity, the answer to his question is quite easy to find in publicly available information on the internet.": "Jim は有名人なので、彼の質問に対する答えはインターネット上の公開情報で簡単に見つかります。",
  "Even brute forcing the answer should be possible with the right kind of word list.": "総当たりで答えを当てることは、適切なワードリストがあれば可能であるはずです。",
  "Finding out who Morty actually is, will help to reduce the solution space.": "Mortyが実際に誰なのかを突き止めることで、解答の候補を絞り込むことができます。",
  "You can assume that Morty answered his security question truthfully but employed some obfuscation to make it more secure.": "Mortyは秘密の質問に正直に答えましたが、それをより安全にするために何らかの難読化を施したと想定してよいでしょう。",
  "Morty’s answer is less than 10 characters long and does not include any special characters.": "Morty の答えは10文字未満で、特殊文字は含まれていません。",
  "Unfortunately, Forgot your password? is protected by a rate limiting mechanism that prevents brute forcing. You need to beat this somehow.": "残念ながら、「パスワードをお忘れですか？」は、ブルートフォース攻撃を防ぐためのレート制限メカニズムによって保護されています。これを何とかして打ち破る必要があります。",
  "Check for products which seem like a natural fit for being based on a blueprint.": "設計図に基づいていると思われる、自然に適合する製品がないかを確認する。",
  "You might want to pay attention to the images of the identified product candidates.": "特定した製品候補の画像に注意を払うとよいでしょう。",
  "For your inconvenience the blueprint was not misplaced into the same place like so many others forgotten files covered in this chapter.": "ご不便をおかけしますが、この設計図はこの章で取り上げられた他の多くの忘れられたファイルと同じ場所には置かれていません。",
  "Reverse engineering something bad can make good things happen.": "悪いものをリバースエンジニアリングすることで、良いことが起こるかもしれない。",
  "Using whatever you find inside the malware directly will not do you any good.": "malware ディレクトリ内で見つけたものをそのまま使っても、何の役にも立ちません。",
  "For this to count as an SSRF attack you need to make the Juice Shop server attack itself.": "この課題がSSRF攻撃としてカウントされるためには、Juice Shop サーバー自身に攻撃させる必要があります。",
  "Do not try to find the source code for the malware on GitHub. Take it apart with classic reverse-engineering techniques instead.": "GitHubでマルウェアのソースコードを探そうとしないでください。代わりに、古典的なリバースエンジニアリング技術でそれを分解してください。",
  "\"SSTi\" is a clear indicator that this has nothing to do with anything Angular. Also, make sure to use only our non-malicious malware.": "このチャレンジはAngularとは無関係であることを、\"SSTi\" が明確に示しています。また、必ず私たちの悪意のないマルウェアのみを使用してください。",
  "You can find the juicy malware via a very obvious Google search or by stumbling into a very ill-placed quarantine folder with the necessary URLs in it.": "この juicy マルウェアは非常に分かりやすい Google 検索か、または必要なURLが含まれた非常に不適切な場所に置かれた隔離フォルダに偶然入り込むことで見つけられます。",
  "Making the server download and execute the malware is key to solving this challenge.": "サーバーにマルウェアをダウンロードして実行させることが、このチャレンジを解決する鍵となります。",
  "For this challenge you do not have to reverse engineer the malware in any way. That will be required later to solve the \"Request a hidden resource on server through server\" challenge.": "このチャレンジを解くためにマルウェアをリバースエンジニアリングする必要はありません。それは後で「サーバー経由でサーバー上の隠されたリソースをリクエストする」チャレンジを解決するために必要となります。",
  "This challenge asks you to act like an ethical hacker.": "このチャレンジでは、倫理的ハッカーとして行動することが求められます。",
  "Undoubtedly you want to read our security policy before conducting any research on our application.": "アプリケーションに対する調査を開始する前に、セキュリティポリシーを熟読したいに違いない。",
  "As one of the good guys, would you just start attacking an application without consent of the owner?": "善人の一人として、所有者の同意なしにアプリケーションへの攻撃を開始しますか?",
  "You also might want to read the security policy or any bug bounty program that is in place.": "セキュリティポリシーや導入されているバグバウンティプログラムを読んでみるのも良いでしょう。",
  "The \"Comment\" field in the \"Customer Feedback\" screen is where you want to put your focus on.": "\"お客様の声\"画面にある \"コメント\" フィールドに焦点を当てる必要があります。",
  "The Comment field in the Contact Us screen is where you want to put your focus on.": "お問い合わせ画面のコメント欄に注目してください。",
  "The attack payload <iframe src=\"javascript:alert(`xss)\">` will not be rejected by any validator but stripped from the comment before persisting it.": "攻撃ペイロード <iframe src=\"javascript:alert(`xss)\">` はどのバリデーターにも拒否されませんが、保存される前にコメントから除去されます。",
  "Look for possible dependencies related to input processing in the package.json.bak you harvested earlier.": "以前に取得した package.json.bak ファイルから、入力処理に関連する可能性のある依存関係を探してください。",
  "If an XSS alert shows up but the challenge does not appear as solved on the Score Board, you might not have managed to put the exact attack string <iframe src=\"javascript:alert(`xss)\">` into the database?": "XSSのアラートが表示されるがスコアボードでチャレンジが解決済みにならない場合、正確な攻撃文字列 <iframe src=\"javascript:alert(`xss)\">` をデータベースに挿入できていない可能性があります。",
  "There is not the slightest chance that you can spot the hidden character with the naked eye.": "肉眼で隠し文字を発見できる可能性は皆無です。",
  "You will need very specialized tool assistance for this challenge.": "この課題には、非常に専門的なツール支援が必要になります。",
  "The effective difficulty of this challenge depends a lot on what tools you pick to tackle it.": "このチャレンジの実質的な難易度は、あなたがどのようなツールを選ぶかによって大きく異なります。",
  "This challenge cannot be solved by just reading our \"Lorem Ipsum\"-texts carefully.": "このチャレンジは、単に我々の「Lorem Ipsum」テキストを注意深く読むだけでは解決できません。",
  "Your attack payload must not trigger the protection against too many iterations and infinite loops.": "攻撃ペイロードが、過剰なイテレーションや無限ループに対する保護機能をトリガーしてはいけません。",
  "This challenge uses the same leverage point as the \"Perform a Remote Code Execution that would keep a less hardened application busy forever\" challenge.": "このチャレンジは、「より強固ではないアプリケーションを永久に忙しくさせるリモートコード実行を実行する」チャレンジと同じレバレッジポイントを使用します。",
  "This vulnerability will not affect any customer of the shop. It is aimed exclusively at its developers.": "この脆弱性は、ショップの顧客には影響しません。開発者のみを対象としています。\n",
  "This is a research-heavy challenge which does not involve any actual hacking.": "これは実際のハッキングを伴わない、調査に重点を置いたチャレンジです。",
  "Solving \"Access a developer's forgotten backup file\" before attempting this challenge will save you from a lot of frustration.": "このチャレンジに挑戦する前に、「開発者の忘れられたバックアップファイルにアクセスする」を解決しておくと、多くのフラストレーションから解放されるでしょう。",
  "The 2FA implementation requires to store a secret for every user. You will need to find a way to access this secret in order to solve this challenge.": "2要素認証 (2FA) の実装では、すべてのユーザーにシークレットを保存する必要があります。このチャレンジを解決するには、このシークレットにアクセスする方法を見つける必要があります。",
  "As always, first learn how the feature under attack is used and behaves under normal conditions.": "いつものように、まず攻撃対象となる機能がどのように使用され、通常の状態ではどのように振る舞うかを学んでください。",
  "Make sure you understand how 2FA with TOTP (time-based one-time password) works and which part of it is the critically sensitive one.": "2FA with TOTP (時間ベースのワンタイムパスワード) がどのように機能し、そのどの部分が特に機密性が高いのかを確実に理解してください。",
  "Solving the challenge \"Retrieve a list of all user credentials via SQL Injection\" before tackling this one will definitely help. But it will not carry you all the way.": "「SQLインジェクションを通じて全ユーザーの認証情報を取得する」というチャレンジを先に解決しておくと、間違いなく役立ちます。しかし、それだけではすべてを解決することはできません。",
  "This challenge exploits a weird option that is supported when signing tokens with JWT.": "このチャレンジは、JWTでトークンに署名する際にサポートされている、奇妙なオプションを悪用します。",
  "You should begin with retrieving a valid JWT from the application’s Authorization request header.": "有効なJWTをアプリケーションの Authorization リクエストヘッダーから取得することから始めるべきです。",
  "A JWT is only given to users who have logged in. They have a limited validity, so better do not dawdle.": "JWTはログインしたユーザーにのみ与えられます。有効期限が限られているので、ぐずぐずしている暇はありません。",
  "Try to convince the site to give you a valid token with the required payload while downgrading to no encryption at all.": "暗号化を一切使用しないようダウングレードし、必要なペイロードを含む有効なトークンの取得を試行してください。",
  "You can attach a small file to the \"Complaint\" form. Investigate how this upload actually works.": "「苦情」フォームには小さなファイルを添付できます。このアップロードが実際にどのように機能するかを調査してください。",
  "First you should try to understand how the file upload is actually handled on the client and server side.": "まず、クライアント側とサーバー側でファイルのアップロードが実際にどのように処理されるかを理解するように努めるべきです。",
  "With this understanding you need to find a \"weak spot\" in the right place and have to craft an exploit for it.": "この理解をもって、あなたは適切な場所に「弱点」を見つけ、それに対するエクスプロイトを作成する必要があります。",
  "You can attach a PDF or ZIP file to the \"Complaint\" form. Investigate how this upload actually works.": "「苦情」フォームには PDF または ZIPファイルを添付できます。このアップロードが実際にどのように機能するかを調査してください。",
  "If you solved the \"Upload a file larger than 100 kB\" challenge, you should try to apply the same solution here": "もし「100KBより大きいファイルをアップロードする」チャレンジを解決したのであれば、同じ解決策をここに適用してみてください。",
  "Gather information on where user data is stored and how it is addressed. Then craft a corresponding UNION SELECT attack.": "ユーザーデータの保存場所と対処方法に関する情報を収集し、対応するUNION SELECT攻撃を作成する。",
  "Try to find an endpoint where you can influence data being retrieved from the server.": "サーバーから取得されるデータに影響を与えるエンドポイントを探してみてください。",
  "Craft a UNION SELECT attack string to join data from another table into the original result.": "別のテーブルのデータを元の結果に結合するUNION SELECT攻撃文字列を作成してください。",
  "You might have to tackle some query syntax issues step-by-step, basically hopping from one error to the next": "クエリ構文の問題を一つずつ段階的に解決していく必要があるかもしれない。基本的には一つのエラーを修正すると次のエラーが現れる、という繰り返し作業になる",
  "As with \"Order the Christmas special offer of 2014\" and \"Exfiltrate the entire DB schema definition via SQL Injection\" this cannot be achieved through the application frontend.": "「2014年のクリスマス特別オファーを注文する」や「SQLインジェクションによるDB全スキーマ定義の抽出」チャレンジと同様、これはアプリケーションのフロントエンドからは達成できない。",
  "Without utilizing the vulnerability behind another ⭐⭐⭐⭐⭐⭐ challenge it is not possible to plant the XSS payload for this challenge.": "別の⭐⭐⭐⭐⭐⭐チャレンジの脆弱性を利用しない限り、このチャレンジ用のXSSペイロードを配置することは不可能です。",
  "The mentioned \"marketing collateral\" might have been publicly advertised by the Juice Shop but is not necessarily part of its sitemap yet.": "言及されている「マーケティング資料」は Juice Shop で公に宣伝されている可能性があるが、サイトマップには含まれていないかもしれません。",
  "It might help to perform some online searches for structurally similar web projects once you get stuck.": "行き詰まった際は、同じような構造のWebプロジェクトをオンラインで調べてみると参考になるかもしれない。",
  "This challenge will always partially keep you blindfolded, no matter how hard you do research and analysis.": "このチャレンジは、どれほど徹底的に調査・分析を行っても、常に一部が見えない状態のままになる。",
  "Try out all existing functionality involving the shopping basket while having an eye on the HTTP traffic.": "HTTPトラフィックを監視しながら、カートに関連するすべての既存機能を試してください。",
  "There might be a client-side association of user to basket that you can try to manipulate.": "ユーザーとバスケットをクライアントサイドで関連付けている仕組みがあり、この紐付けを操作できる可能性がある。",
  "In case you manage to update the database via SQL Injection so that a user is linked to another shopping basket, the application will not notice this challenge as solved.": "SQLインジェクションでデータベースを更新してユーザーを別のショッピングカートに関連付けることができても、アプリケーションはこのチャレンジの達成を検出しない。",
  "Report one of two possible answers via the \"Customer Feedback\" form. Do not forget to submit the library's version as well.": "二つの選択肢のうち、どちらか一つの回答を「お客様の声」フォームから報告してください。ライブラリのバージョンを忘れずに提出してください。",
  "Look for possible dependencies related to security in the package.json.bak you probably harvested earlier during the Access a developer’s forgotten backup file challenge.": "「開発者が忘れたバックアップファイルにアクセスする」チャレンジで取得した package.json.bak ファイル内で、セキュリティ関連の依存パッケージを調べてください。",
  "Do some research on the internet for known security issues in the most suspicious application dependencies.": "最も疑わしい依存パッケージについて、既知のセキュリティ脆弱性をインターネットで調査してください。",
  "Report one of five possible answers via the \"Customer Feedback\" form.": "5つの可能な回答のうち1つを「お客様フィードバック」フォームから報告してください。",
  "Cryptographic functions only used in the \"Apply some advanced cryptanalysis to find the real easter egg\" challenge do not count as they are only a developer’s prank and not a serious security problem.": "「高度な暗号解析を適用して真のイースターエッグを見つける」チャレンジでのみ使用される暗号化関数は対象外とします。これらは開発者のジョークであり、実際のセキュリティ脆弱性ではないためです。",
  "You have to find a way to beat the allowlist of allowed redirect URLs.": "許可されたリダイレクトURLの許容リストを破る方法を見つける必要があります。",
  "You can find several places where redirects happen in the OWASP Juice Shop.": "OWASP Juice Shop でリダイレクトが行われる場所がいくつかあります。",
  "The application will only allow you to redirect to allowlisted (previously referred to as whitelisted) URLs.": "アプリケーションは、許可リスト (以前はホワイトリストと呼ばれていた) に登録されたURLへのリダイレクトのみを許可します。",
  "Tampering with the redirect mechanism might give you some valuable information about how it works under to hood.": "リダイレクト機能を操作してみることで、その内部動作に関する貴重な情報が得られるかもしれない。",
  "The leverage point for this challenge is the deprecated B2B interface.": "このチャレンジのレバレッジポイントは非推奨の B2B インタフェースです。",
  "This challenge sounds a lot harder than it actually is, which amplifies how bad the underlying vulnerability is.": "このチャレンジは実際よりも難しそうに聞こえますが、そのギャップこそが根本的な脆弱性の深刻さを浮き彫りにしています。",
  "Doing some research on typical XEE attack patterns basically gives away the solution for free.": "典型的なXXE攻撃パターンを調べれば、このチャレンジの解法がほぼそのまま見つかります。",
  "It is not as easy as sending a large amount of data directly to the deprecated B2B interface.": "これは、非推奨のB2Bインターフェースに大量のデータを直接送信するほど簡単ではありません。",
  "The leverage point for this is obviously the same as for the XXE Data Access challenge.": "この攻撃の起点は、「XXEデータアクセス」チャレンジと明らかに同じです。",
  "You can only solve this challenge by keeping the server busy for >2sec with your attack.": "攻撃によってサーバーを2秒以上ビジー状態にすることで、このチャレンジを解決できます。",
  "The effectiveness of attack payloads for this challenge might depend on the operating system the Juice Shop is running on.": "このチャレンジの攻撃ペイロードの効果は、Juice Shop が動作するオペレーティングシステムによって左右される可能性があります。",
  "This one is actually similar to the XXE DoS challenge in every way except the data format being (ab)used.": "これは、データを悪用するフォーマットが異なる点を除けば、XXE DoSチャレンジとあらゆる面で似ています。",
  "Before you invest time bypassing the API, you might want to play around with the UI a bit.": "APIをバイパスするために時間を費やす前に、少しUIをいじってみるといいかもしれません。",
  "Check the Photo Wall for an image that could not be loaded correctly.": "画像の読み込みが正しく行われなかった Photo Wall の画像をチェックしてください。",
  "You just have to (literally) inspect the problem to understand the basic issue.": "この問題を (文字通り) 調査するだけで、根本的な問題が理解できます。",
  "It can also help to try out the Tweet-button of the entry and observe what happens.": "そのエントリのツイートボタンを実際にクリックして、動作を観察することも役立ちます。",
  "This challenge would formally have to be in several categories as the developers made multiple gaffes for this to be possible.": "このチャレンジは、複数のカテゴリーに分類されるべきでしょう。開発者は、この問題を引き起こすために複数の過ちを犯したからです。",
  "Loading this page with an empty browser cache and on a slow (or throttled) connection will give you an idea on what the delivery box image is made of. Of course inspecting the page source will tell you just as much.": "ブラウザキャッシュを空にして低速接続でこのページを読み込むと、配送ボックス画像の構成が見えてきます。もちろん、ページソースを検査することでも同じ情報が得られます。",
  "You need to dive deep into the actual Angular code to understand this one.": "このチャレンジを理解するには、実際のAngularコードを詳細に調査する必要があります。",
  "This challenge requires the exploitation of another vulnerability which even has its own two challenges in its very own category": "このチャレンジでは別の脆弱性を悪用する必要があり、その脆弱性自体が専用カテゴリに2つの独立したチャレンジとして存在しています",
  "This challenge can only be solved by strictly using the mentioned \"cross-domain kittens\". No other kittens from anywhere else can solve this challenge.": "このチャレンジは、指定された「クロスドメイン kittens」を厳密に使用することでのみ解決できます。他の場所の kittens では、このチャレンジをクリアできません",
  "Try to guess what URL the endpoint might have.": "エンドポイントのURLを推測してください。",
  "The Juice Shop serves its metrics on the default path expected by Prometheus": "Juice Shop は Prometheus が想定するデフォルトパスでメトリクスを公開しています",
  "Guessing the path is probably just as quick as taking the RTFM route via https://prometheus.io/docs/introduction/first_steps": "パスを推測することは、https://prometheus.io/docs/introduction/first_steps でドキュメントを参照するのと同じくらい手早いでしょう",
  "Look closely at what happens when you attempt to upgrade your account.": "アカウントをアップグレードしようとすると何が起こるか、よく注意して見てください。",
  "Go to the payment page for a deluxe membership and try paying through different methods.": "デラックスメンバーシップの支払いページにアクセスして、さまざまな決済方法を試してください。\n",
  "Try inspecting the requests that go out for each of these methods, using the browser’s developer tools.": "ブラウザの開発者ツールを使って、各支払い方法で送信されるリクエストを調査してください。",
  "Maybe playing around with the parameters in these requests could reveal something interesting.": "これらのリクエストのパラメータを操作してみることで、興味深い発見があるかもしれません。",
  "Find a form which updates the username and then construct a malicious page in the online HTML editor. You probably need an older browser version for this.": "ユーザー名を更新するフォームを見つけ、オンラインHTMLエディターで悪意のあるページを構築してください。この操作には、おそらく古いブラウザバージョンが必要です。",
  "Take a look at what happens when you change the username within the profile page.": "プロフィールページでユーザー名を変更した時の動作を観察してください。",
  "Search for information about CSRF attacks and look out for examples that can be applied to this challenge.": "CSRF攻撃について調べて、このチャレンジに適用できる攻撃例を探してください。",
  "Write the code for the CSRF attack within http://htmledit.squarefree.com and verify that it changes your username.": "http://htmledit.squarefree.com でCSRF攻撃コードを作成し、ユーザー名が実際に変更されるかを検証してください。",
  "First, solve the \"Perform a DOM XSS attack\" challenge.": "まず、「DOM XSS攻撃を実行する」チャレンジを解いてください。",
  "Now it is just a question of copying and pasting the payload into the same vulnerable field.": "あとは、同じ脆弱性があるフィールドにペイロードをコピー＆ペーストするだけです。",
  "Crank up the volume of your computer before submitting the payload! 🔊": "ペイロードを実行する前に、コンピューターの音量を上げておいてください！🔊",
  "You might have to do some OSINT on his social media personas to find out his honest answer to the security question.": "秘密の質問に対する彼の“本当の”答えを見つけるために、彼のソーシャルメディア情報についてOSINT調査を行う必要があるかもしれません。",
  "People often reuse aliases online. You might be able to find something by looking online for Uvogin’s name or slight variations of it based on his unique writing habits.": "ユーザーは複数のサイトで同じハンドルネームを使い回すことが多い。Uvoginの名前や、彼特有の文章の癖を基にした変形を検索すれば、手がかりが見つかるかもしれない。",
  "You might be able to find some existing OSINT tools to help you in this investigation.": "この調査には、既存のOSINTツールが役立つ可能性があります。",
  "Take a look at the meta data of the corresponding photo.": "対応する写真のメタデータを見てください。",
  "Make use of tools that can inspect the metadata of images.": "画像のメタデータを解析できるツールを使用してください。",
  "Use this information to answer the security question of the John, who enjoys hiking in the park.": "この情報を使って、公園でのハイキングを楽しむJohnの秘密の質問に回答してください。",
  "Take a look at the details in the photo to determine the location of where it was taken.": "写真を詳しく見て、撮影された場所を特定してください。",
  "Analyze and tamper with links in the application until you get to an unprotected directory listing.": "アプリケーション内のリンクを分析・操作して、保護されていないディレクトリリスティングにアクセスしてください。",
  "Some files in there are not directly accessible because a security mechanism prevents access.": "その中の一部のファイルはセキュリティメカニズムによってアクセスが制限されているため、直接アクセスできません。",
  "The Poison Null Byte can trick the security mechanism into thinking that the file you want has a valid file type.": "Poison Null Byte を使用すると、対象ファイルが有効なファイルタイプであるとセキュリティメカニズムを騙すことができます。",
  "Depending on the files you try to retrieve you will probably solve \"Access a developer’s forgotten backup file\", \"Access a salesman’s forgotten backup file\", \"Access a misplaced SIEM signature file, or \"Find the hidden easter egg\" along the way.": "取得するファイルによって、「開発者の忘れられたバックアップファイルにアクセスする」、「営業担当者の忘れられたバックアップファイルにアクセスする」、「置き忘れられたSIEMシグネチャファイルにアクセスする」、「隠されたイースターエッグを見つける」などのチャレンジを達成できるでしょう。",
  "You should read up on vulnerabilities in popular NodeJs template engines.": "一般的なNodeJsテンプレートエンジンの脆弱性について読むべきです。",
  "You should read up on Local File Read (LFR) vulnerabilities in popular NodeJS template engines.": "人気のNodeJSテンプレートエンジンにおけるLocal File Read（LFR）脆弱性について調査してください。",
  "Look for an easily forgettable endpoint in Juice Shop to test out the LFR attack.": "Juice Shop で見落としがちなエンドポイントを探して、LFI攻撃をテストしてください。",
  "500 Internal Server Error is always an interesting status code.": "500 Internal Server Error は常に調査価値のあるステータスコードです。",
  "Fuzzing can also help with this challenge.": "ファジングテストもこのチャレンジの解決に有効です。",
  "Either check the official documentation or inspect a notification UI element directly.": "公式ドキュメントを確認するか、通知UI要素を直接調べてみてください。",
  "This challenge is most easily solvable immediately after a server restart.": "このチャレンジは、サーバーが再起動した直後が最も簡単に解決できます。",
  "Alternatively you can also inspect any \"Challenge solved\"-notification in your browser to understand its convenience feature.": "あるいは、ブラウザ内の「チャレンジ解決済み」通知を検査して、その利便性機能を理解することもできます。",
  "Security Advisories are often listed in the security.txt": "セキュリティアドバイザリは通常 security.txt ファイルに記載されています",
  "Have a look at the client-side code in the dev console.": "開発コンソールでクライアント側のコードを確認してください。",
  "The API call is part of a scheduled process \"behind the scenes\", i.e. completely unrelated to the web application.": "API 呼び出しはスケジュールされたプロセスの一部です。すなわち、Web アプリケーションとはまったく関係ありません。",
  "Check the Juice Shop’s social media channels for regularly scheduled content being posted, possibly even indicating that it was automatically created.": "Juice Shop のソーシャルメディアチャンネルをチェックして、定期的に投稿されているコンテンツを探してください。自動的に作成されたことを示唆しているかもしれません。",
  "Find out which part of the content might come from the response of an API call.": "コンテンツのどの部分がAPI呼び出しのレスポンスから来ている可能性があるかを見つけ出してください。",
  "Find the place where the API call happens — as stated above, it is not in the web application — and then look for the API key itself.": "API呼び出しが行われている場所を見つけてください。前述のとおり、Webアプリケーション内にはありません。そして、APIキー自体を探してください。",
  "The chatbot has a tool for generating coupons, but is instructed to only use it under very specific conditions.": "The chatbot has a tool for generating coupons, but is instructed to only use it under very specific conditions.",
  "Try to convince the chatbot that the conditions for coupon generation are met, even if they are not.": "Try to convince the chatbot that the conditions for coupon generation are met, even if they are not.",
  "Prompt injection techniques can help you bypass the chatbot's restrictions on tool usage.": "Prompt injection techniques can help you bypass the chatbot's restrictions on tool usage.",
  "The chatbot's system prompt says the maximum discount is 10%. But system prompts are more like guidelines than actual rules, right?": "The chatbot's system prompt says the maximum discount is 10%. But system prompts are more like guidelines than actual rules, right?",
  "You already know how to make the chatbot generate a coupon. Now make it go way beyond the allowed maximum.": "You already know how to make the chatbot generate a coupon. Now make it go way beyond the allowed maximum.",
  "The chatbot trusts whatever discount value it decides to pass to its tool. Make it decide on a very generous number.": "The chatbot trusts whatever discount value it decides to pass to its tool. Make it decide on a very generous number.",
  "The chatbot has a debugging feature that shows how it interacts with its tools. It is only supposed to be visible for admins.": "The chatbot has a debugging feature that shows how it interacts with its tools. It is only supposed to be visible for admins.",
  "Access control for the debugging feature is only implemented on the client-side.": "Access control for the debugging feature is only implemented on the client-side.",
  "Find the cookie that controls the visibility of tool calls and set it to <code>true</code>.": "Find the cookie that controls the visibility of tool calls and set it to <code>true</code>.",
  "If you see the tool calls but the challenge is not marked as solved, you might be still logged in as a user with admin privileges.": "If you see the tool calls but the challenge is not marked as solved, you might be still logged in as a user with admin privileges.",
  "Invalid email/password cannot be empty": "Invalid email/password cannot be empty",
  "<a href=\"https://owasp.slack.com\" target=\"_blank\">More...</a>": "<a href=\"https://owasp.slack.com\" target=\"_blank\">More...</a>"
}
