OWASP Juice Shop: Hacking a Modern Web Application
blog.javascripttoday.com
blog.javascripttoday.com
It's bad... isn't it? :O It's one of the first articles I wrote, and I posted it here thinking nothing of it, but alas, it hit the first page.
Although it was primarily written to introduce the JuiceShop project to people, so I guess that's good.
That verbal style works because verbal communication is real-time and you can provide correction and feedback when something doesn't work as expected. In other words: because you're able to babysit the process and answer questions. Unfortunately, you don't have that luxury in a written medium.
I find that what works better in a written context is to have a concise list of instructions at the top with zero explanation. Below that, you can write a step-by-step explanation of the motivation and intent of each step.
This allows a reader to skip what's obvious and jump to the explanation they need to fill in a gap in their understanding.
I would also suggest you choose a specific target audience that can be expected to understand some things without explanation and who needs only a little explanation to understand a single new idea (e.g. XSS vulnerabilities, but not how to set up a project).
Another minor tip:
Make fewer value judgments and use fewer superlatives—don't write 'X is the best' or 'Y is a great'. Unless X or Y is the subject at hand, it's fine to simply say 'X is a {concise, matter-of-fact description}'.
My impression is that you have a lot in your head and that you're very excited to share that knowledge, which is awesome, but you need to share your knowledge patiently and methodically. That's a good thing though: it means you have a deep well to draw from if you enjoy writing technical articles :)
You've submitted this article before and it was marked dead, and with the questionable "Modern" in the title I was thrown off. AI articles have a certain tone with lots of superlatives and "we" usage.
I think it is awesome to help share this stuff with the world, but focus on being direct. There is some meat in the article, but the signal to noise ratio makes it hard to extract the value from the article.
If you enjoy writing, get doing it. Don't let me get you down. We are all learning as we go <3
Although... I don't know, I've been writing articles like that for awhile. Last night I was writing one and recalled your comment on the "we" usage, making me second guess... haha. Is it really that bad?
Thanks, though. No worries. I assume most articles are AI these days as well.
I didn't understand the term "Modern" in the title. This exploit is as old as they get on the web, so I was expecting maybe some tool-chain attack or something on the React stack.
And then in the conclusion: > In this article, we explored an incredible project
I didn't feel the was explored the project.
> We’ve also explored XSS attacks and discussed how they work.
This is the only thing the article did so the "also" through me off.
These are just little things that set off my AI spidey-sense.