Refactored files to Maven standard Layout
Added plugin to produce executable jar. Now it is easy to run webgoat on all platforms.
This commit is contained in:
9
src/main/webapp/lesson_plans/English/WeakSessionID.html
Normal file
9
src/main/webapp/lesson_plans/English/WeakSessionID.html
Normal file
@ -0,0 +1,9 @@
|
||||
<div align="Center">
|
||||
<p><b>Lesson Plan Title:</b> How to Hijack a Session</p>
|
||||
</div>
|
||||
<p><b>Concept / Topic To Teach:</b> </p>
|
||||
<!-- Start Instructions -->
|
||||
Application developers who develop their own session IDs frequently forget to incorporate the complexity and randomness necessary for security. If the user specific session ID is not complex and random, then the application is highly susceptible to session-based brute force attacks.
|
||||
<p><b>General Goal(s):</b> </p>
|
||||
Try to access an authenticated session belonging to someone else.
|
||||
<!-- Stop Instructions -->
|
Reference in New Issue
Block a user