From 508f1287442c06e65cf17741115a14a20229ca51 Mon Sep 17 00:00:00 2001 From: Nanne Baars Date: Sat, 8 Apr 2017 22:38:03 +0200 Subject: [PATCH] Challenge 4: First setup --- .../webgoat/plugin/challenge3/Challenge3.java | 2 +- .../src/main/resources/html/Challenge.html | 101 ++++++++++++++++++ .../src/main/resources/js/challenge3.js | 2 +- .../resources/lessonPlans/en/Challenge_1.adoc | 2 +- .../resources/lessonPlans/en/Challenge_4.adoc | 1 + 5 files changed, 105 insertions(+), 3 deletions(-) create mode 100644 webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_4.adoc diff --git a/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/challenge3/Challenge3.java b/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/challenge3/Challenge3.java index b1d22364a..d5f94e774 100644 --- a/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/challenge3/Challenge3.java +++ b/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/challenge3/Challenge3.java @@ -29,7 +29,7 @@ import static org.springframework.web.bind.annotation.RequestMethod.POST; * @author nbaars * @since 4/8/17. */ -@AssignmentPath("/challenge3") +@AssignmentPath("/challenge/3") public class Challenge3 extends AssignmentEndpoint { @Autowired diff --git a/webgoat-lessons/challenge/src/main/resources/html/Challenge.html b/webgoat-lessons/challenge/src/main/resources/html/Challenge.html index e1baebd44..c909915bf 100644 --- a/webgoat-lessons/challenge/src/main/resources/html/Challenge.html +++ b/webgoat-lessons/challenge/src/main/resources/html/Challenge.html @@ -250,5 +250,106 @@ +
+
+ + +
+
+
+ + +
+ +
+ +
+
+

Samsung Galaxy S8

+
Samsung ยท + (124421 reviews) +
+ +
+ PRICE +
+

US $899

+ +
+
+ COLOR +
+
+
+
+
+
+
+
+ CAPACITY +
+
+
64 GB
+
128 GB
+
+
+
+
+ QUANTITY +
+
+
+ +
+
+
+ +
+
+ CHECKOUT CODE +
+ + + +
+ +
+ +
+ Like
+
+
+
+ +
+
+
+
+
+
+
+ +
+
+ +
+
+ +
+
+
+
+
\ No newline at end of file diff --git a/webgoat-lessons/challenge/src/main/resources/js/challenge3.js b/webgoat-lessons/challenge/src/main/resources/js/challenge3.js index be9cb11f0..53d4c36a2 100644 --- a/webgoat-lessons/challenge/src/main/resources/js/challenge3.js +++ b/webgoat-lessons/challenge/src/main/resources/js/challenge3.js @@ -9,7 +9,7 @@ $(document).ready(function () { }) }) - $.get("challenge3", function (result, status) { + $.get("challenge/3", function (result, status) { alert("Hello"); }) }) \ No newline at end of file diff --git a/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_1.adoc b/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_1.adoc index 4f77d8158..e5678d52f 100644 --- a/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_1.adoc +++ b/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_1.adoc @@ -1 +1 @@ -==== Admin forgot password can you help? \ No newline at end of file +Admin forgot password can you help? \ No newline at end of file diff --git a/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_4.adoc b/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_4.adoc new file mode 100644 index 000000000..60cb2eb18 --- /dev/null +++ b/webgoat-lessons/challenge/src/main/resources/lessonPlans/en/Challenge_4.adoc @@ -0,0 +1 @@ +No need to pay (fixed after private disclosure), do you need to pay now? \ No newline at end of file