Restructured the baseline to remove extra src/main directory structure. Added eclipes project file
git-svn-id: http://webgoat.googlecode.com/svn/branches/webgoat-6.0@485 4033779f-a91e-0410-96ef-6bf7bf53c507
This commit is contained in:
20
webapp/lesson_plans/en/MultiLevelLogin2.html
Normal file
20
webapp/lesson_plans/en/MultiLevelLogin2.html
Normal file
@ -0,0 +1,20 @@
|
||||
<div align="Center">
|
||||
<p><b>Lesson Plan Title:</b> Multi Level Login 2</p>
|
||||
</div>
|
||||
<p><b>Concept / Topic To Teach:</b> </p>
|
||||
<!-- Start Instructions -->
|
||||
A Multi Level Login should provide a strong authentication.
|
||||
This is archived by adding a second layer. After having
|
||||
logged in with your user name and password you are asked
|
||||
for a 'Transaction Authentication Number' (TAN). This is
|
||||
often used by online banking. You get a list with a lots
|
||||
of TANs generated only for you by the bank. Each TAN is used only once.
|
||||
Another method is to provide the TAN by SMS. This has
|
||||
the advantage that an attacker can not get TANs provided
|
||||
by the user.
|
||||
<p><b>General Goal(s):</b> </p>
|
||||
In this lesson you have to try to break into another account.
|
||||
You have an own account for WebGoat Financial but you want to
|
||||
log into another account only knowing the user name of the victim
|
||||
to attack.
|
||||
<!-- Stop Instructions -->
|
Reference in New Issue
Block a user