From 990bf079d3139196cd31281e85fdabe188b544ed Mon Sep 17 00:00:00 2001 From: Benedikt - Desktop Date: Sun, 18 Nov 2018 13:19:26 +0100 Subject: [PATCH] Added hints for dom-based xss assignment (part 2) --- .../owasp/webgoat/plugin/DOMCrossSiteScriptingVerifier.java | 2 ++ .../src/main/resources/i18n/WebGoatLabels.properties | 6 ++++++ 2 files changed, 8 insertions(+) diff --git a/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/plugin/DOMCrossSiteScriptingVerifier.java b/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/plugin/DOMCrossSiteScriptingVerifier.java index 7f1444a3f..6ee699bef 100644 --- a/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/plugin/DOMCrossSiteScriptingVerifier.java +++ b/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/plugin/DOMCrossSiteScriptingVerifier.java @@ -32,6 +32,7 @@ package org.owasp.webgoat.plugin; import org.owasp.webgoat.assignments.AssignmentEndpoint; +import org.owasp.webgoat.assignments.AssignmentHints; import org.owasp.webgoat.assignments.AssignmentPath; import org.owasp.webgoat.assignments.AttackResult; import org.owasp.webgoat.session.UserSessionData; @@ -47,6 +48,7 @@ import java.io.IOException; * Created by jason on 11/23/16. */ @AssignmentPath("/CrossSiteScripting/dom-follow-up") +@AssignmentHints(value = {"xss-dom-message-hint-1", "xss-dom-message-hint-2", "xss-dom-message-hint-3", "xss-dom-message-hint-4", "xss-dom-message-hint-5", "xss-dom-message-hint-6"}) public class DOMCrossSiteScriptingVerifier extends AssignmentEndpoint { @RequestMapping(method = RequestMethod.POST) public @ResponseBody diff --git a/webgoat-lessons/cross-site-scripting/src/main/resources/i18n/WebGoatLabels.properties b/webgoat-lessons/cross-site-scripting/src/main/resources/i18n/WebGoatLabels.properties index 66cb0a4cc..940c79523 100644 --- a/webgoat-lessons/cross-site-scripting/src/main/resources/i18n/WebGoatLabels.properties +++ b/webgoat-lessons/cross-site-scripting/src/main/resources/i18n/WebGoatLabels.properties @@ -19,6 +19,12 @@ xss-reflected-6a-hint-4=Still didn't find it? Check the