Minor fixes
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@337 4033779f-a91e-0410-96ef-6bf7bf53c507
This commit is contained in:
@ -28,7 +28,7 @@ accept the TAN even it is already used.
|
||||
|
||||
<b>Solution:</b><br/>
|
||||
This Lesson has two stages. The first stage is only to show how a multi level login
|
||||
works. In the second you have to breake the strong authentication.
|
||||
works. In the second you have to break the strong authentication.
|
||||
<p>
|
||||
<b>Stage 1</b><br>
|
||||
This stage should be rather straight forward. Give in as name Jane
|
||||
@ -49,7 +49,7 @@ list provided, click on the submit button and you are done.
|
||||
|
||||
<p>
|
||||
<b>Stage 2</b><br>
|
||||
The first step in this stage is equal to Stage 1. Log in as Jane with tarzan.
|
||||
The first step in this stage is equal to Stage 1. Log in as Jane with tarzan as password.
|
||||
Now you will be asked for a TAN. Unfortunately you have only a already
|
||||
used TAN from the victim. Fill in the TAN you have and make sure that WebScarab
|
||||
will intercept the next request. Hit the submit button and change the hidden_tan
|
||||
|
Reference in New Issue
Block a user