diff --git a/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/Challenge2.java b/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/Challenge2.java index 8bc916874..87ece4df9 100644 --- a/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/Challenge2.java +++ b/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/Challenge2.java @@ -22,8 +22,8 @@ public class Challenge2 extends AssignmentEndpoint { @RequestMapping(method = RequestMethod.POST) public @ResponseBody - AttackResult completed(@RequestParam String couponCode) throws IOException { - if (SUPER_COUPON_CODE.equals(couponCode)) { + AttackResult completed(@RequestParam String checkoutCode) throws IOException { + if (SUPER_COUPON_CODE.equals(checkoutCode)) { return success().feedback("challenge.solved").feedbackArgs(Flag.FLAGS.get(2)).build(); } return failed().build(); diff --git a/webgoat-lessons/challenge/src/main/resources/html/Challenge.html b/webgoat-lessons/challenge/src/main/resources/html/Challenge.html index 8c9bbc78d..b937495a8 100644 --- a/webgoat-lessons/challenge/src/main/resources/html/Challenge.html +++ b/webgoat-lessons/challenge/src/main/resources/html/Challenge.html @@ -61,74 +61,82 @@
-
-
-
- -
-
-

Samsung Galaxy S8 Plus Android Phone

-
Samsung · - (124421 reviews) -
+
+
-
- PRICE -
-

US $899

+
+
+ +
+
+

Samsung Galaxy S8 Plus Android Phone

+
Samsung · + (124421 reviews) +
-
-
- COLOR +
+ PRICE
-
-
-
+

US $899

+ +
+
+ COLOR +
+
+
+
+
-
-
-
- CAPACITY -
-
-
64 GB
-
128 GB
+
+
+ CAPACITY +
+
+
64 GB
+
128 GB
+
-
-
-
- QUANTITY -
-
-
- -
+
+
+ QUANTITY +
+
+
+ +
+
-
-
-
- CHECKOUT CODE -
+
+
+ CHECKOUT CODE +
- - + + -
+
-
- -
- Like
+
+ +
+ Like
+
+
-
+
diff --git a/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_2.adoc b/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_2.adoc index a9177c5b2..6849340ea 100644 --- a/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_2.adoc +++ b/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_2.adoc @@ -1 +1 @@ -=== No need to pay... (WIP!!) \ No newline at end of file +=== No need to pay... \ No newline at end of file