351 Commits

Author SHA1 Message Date
mayhew64
0032ffdbfc Changed the credit card user to be the user that was logged in as. Also base64 encoded the user cookie to make finding sql injection slightly harder.
git-svn-id: http://webgoat.googlecode.com/svn/trunk@376 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-02-03 18:16:51 +00:00
mayhew64
cafcea2ae9 Changed the class build.
git-svn-id: http://webgoat.googlecode.com/svn/trunk@375 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-02-03 17:56:48 +00:00
mayhew64
88a730f225 Removed errors introduced in previous checkin. String and integer conflicts in JSP
git-svn-id: http://webgoat.googlecode.com/svn/trunk@374 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-02-03 17:55:27 +00:00
soylentmean
97571dbe90 Lots of wording changes and HTML fixes.
git-svn-id: http://webgoat.googlecode.com/svn/trunk@373 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-01-06 21:06:42 +00:00
soylentmean
5506f1c279 Fixing wording a smidge.
git-svn-id: http://webgoat.googlecode.com/svn/trunk@372 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-01-06 20:19:22 +00:00
mayhew64
9331ef0d9a Changes by Chris Roe to fix lesson issues with FireFox.
git-svn-id: http://webgoat.googlecode.com/svn/trunk@371 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-12-17 13:06:29 +00:00
soylentmean
6d1158c40c fixed a typo
git-svn-id: http://webgoat.googlecode.com/svn/trunk@370 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-12-11 21:15:20 +00:00
soylentmean
64899b3ee3 Standardized all the HTML, clarified things, and fixed a whole bunch of grammar issues.
I also changed the explanation for Browser Cache Poisoning; the old explanation was incorrect.  If I'm mistaken on that, feel free to revert that part of the explanation.


git-svn-id: http://webgoat.googlecode.com/svn/trunk@369 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-12-11 20:04:15 +00:00
mayhew64
f6e994b14e Minor syntax issue with the word prename in the instructions - reported by April King
git-svn-id: http://webgoat.googlecode.com/svn/trunk@368 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-12-10 23:52:04 +00:00
mayhew64
9d8c58bef3 Removed hardcoded webgoat path for URLs
git-svn-id: http://webgoat.googlecode.com/svn/trunk@367 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-11-21 16:57:23 +00:00
mayhew64
bab1f6aeb7 Reported by dwpoon, Yesterday (17 hours ago)
I would like to submit the attached patch to avoid hard-coding
"/WebGoat" as the webapp's context path, at least for the HTTP splitting
lesson.  This issue has also been reported in July 2007; see
https://lists.owasp.org/pipermail/owasp-webgoat/2007-July/000432.html

Also see Issue 15 http://code.google.com/p/webgoat/issues/detail?id=15


git-svn-id: http://webgoat.googlecode.com/svn/trunk@366 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-11-21 12:57:14 +00:00
mayhew64
58aa49317a Contribution by Kristian Erik Hermansen. Fixed to work with 1.6
git-svn-id: http://webgoat.googlecode.com/svn/trunk@365 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-09-09 15:32:23 +00:00
brandon.devries
5337ef31ff minor bug fixes and enhancements, including proper dollar value formatting
git-svn-id: http://webgoat.googlecode.com/svn/trunk@364 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-14 14:31:17 +00:00
brandon.devries
68357637bc removing unused folder
git-svn-id: http://webgoat.googlecode.com/svn/trunk@363 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-14 12:56:14 +00:00
brandon.devries
4c242f52dc minor changes and improving display issues
git-svn-id: http://webgoat.googlecode.com/svn/trunk@362 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-12 17:36:30 +00:00
brandon.devries
a3990f549e some cleanup, and removing unneeded ClassNotFoundExceptions
git-svn-id: http://webgoat.googlecode.com/svn/trunk@361 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-12 14:33:22 +00:00
brandon.devries
2203a1ebd2 corrected spelling and some formatting
git-svn-id: http://webgoat.googlecode.com/svn/trunk@360 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-11 14:39:09 +00:00
brandon.devries
ba6560b24a Formatting according to OWASP WebGoat Java Style
git-svn-id: http://webgoat.googlecode.com/svn/trunk@359 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-05 17:32:17 +00:00
mayhew64
acab6e9274 Removed build.xml
git-svn-id: http://webgoat.googlecode.com/svn/trunk@358 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 16:14:06 +00:00
mayhew64
8751d7579a Removed windows and changed to developer
git-svn-id: http://webgoat.googlecode.com/svn/trunk@357 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 16:05:17 +00:00
mayhew64
ae79118f55 Logos that slipped through
git-svn-id: http://webgoat.googlecode.com/svn/trunk@356 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 16:04:22 +00:00
mayhew64
d849168ce1 Smaller eclipse workspace
Changed workspace name to reflect WebGoat 
Added the video solutions link
Update readmen to reflect contributions and new stuff

git-svn-id: http://webgoat.googlecode.com/svn/trunk@355 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 15:40:13 +00:00
sherif.fathy
c8908f6911 Actually, I think the problem was happening because the lesson was returning the lesson HTML again incase of incorrect key to eval was throwing an error trying to evaluate a whole bunch of HTML. Fixed this by catching the exception and showing an appropriate message.
git-svn-id: http://webgoat.googlecode.com/svn/trunk@354 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 05:56:41 +00:00
mayhew64
fbf2a079c8 Added bug report
Added message for missing solutions
Minor edits to lesson plans

git-svn-id: http://webgoat.googlecode.com/svn/trunk@353 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-11 00:05:05 +00:00
mayhew64
2a0d5b62a4 Minor wording changes
git-svn-id: http://webgoat.googlecode.com/svn/trunk@352 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-09 00:25:02 +00:00
mayhew64
5d75ed4cae Minor wording edits
git-svn-id: http://webgoat.googlecode.com/svn/trunk@351 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-09 00:21:32 +00:00
mayhew64
ec95ba4089 Separated DB usage for messages in CSRF and Stored XSS
Many cosmetic english changes
Fixed IE rendering for Challenge
 

git-svn-id: http://webgoat.googlecode.com/svn/trunk@350 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-09 00:17:20 +00:00
mayhew64
b0ade9782e Minor 5.2 changes.
git-svn-id: http://webgoat.googlecode.com/svn/trunk@349 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-05-13 03:44:40 +00:00
mayhew64
ad0b90bd24 Added doc directory back into main project root. Build script moves doc to webcontent.
Changed how to work with WebGoat picture to have original buttons 

git-svn-id: http://webgoat.googlecode.com/svn/trunk@348 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-05-12 14:22:33 +00:00
mayhew64
429fd7b0a9 Alphabetized categories
git-svn-id: http://webgoat.googlecode.com/svn/trunk@347 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-05-12 13:10:17 +00:00
mayhew64
9071b86a59 Reorder categories to be alphabetized
Changed unvalidated input to parameter tampering

git-svn-id: http://webgoat.googlecode.com/svn/trunk@346 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-22 16:45:29 +00:00
mayhew64
bbcd546137 5.2 Credits
git-svn-id: http://webgoat.googlecode.com/svn/trunk@345 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-22 15:38:21 +00:00
mayhew64
243f8ca360 Minor fixes
removed many System.out.printlns
delete extra solutions directory - wrong location
added 5.2 credits

git-svn-id: http://webgoat.googlecode.com/svn/trunk@344 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-22 15:34:54 +00:00
mayhew64
14fa88396e No Changes - SVN Test
git-svn-id: http://webgoat.googlecode.com/svn/trunk@343 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-22 12:01:21 +00:00
wirth.marcel
c7776ece65 Text edited
git-svn-id: http://webgoat.googlecode.com/svn/trunk@342 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-18 08:41:02 +00:00
wirth.marcel
314c350079 Minor changes... Tan gets now only updatet after it was correct
git-svn-id: http://webgoat.googlecode.com/svn/trunk@341 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-18 08:38:51 +00:00
wirth.marcel
2649bcb086 Session Fixation instructions altered
git-svn-id: http://webgoat.googlecode.com/svn/trunk@340 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-15 09:43:34 +00:00
wirth.marcel
3a1397f178 Session Fixation lesson plan and solution edited
git-svn-id: http://webgoat.googlecode.com/svn/trunk@339 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-15 09:43:01 +00:00
wirth.marcel
e2ca7f9a33 Minor Bugfixes
git-svn-id: http://webgoat.googlecode.com/svn/trunk@338 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 13:28:25 +00:00
wirth.marcel
80d07fb62c Minor fixes
git-svn-id: http://webgoat.googlecode.com/svn/trunk@337 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 12:03:55 +00:00
wirth.marcel
7ecf14530b Wireshark to useful tools added
git-svn-id: http://webgoat.googlecode.com/svn/trunk@336 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 09:24:12 +00:00
wirth.marcel
8182db6dc4 InsecureLogin Credits added. Instructions changed
git-svn-id: http://webgoat.googlecode.com/svn/trunk@335 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 08:35:33 +00:00
wirth.marcel
efd77a001e InsecureLogin solution edited
git-svn-id: http://webgoat.googlecode.com/svn/trunk@334 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 08:33:30 +00:00
wirth.marcel
40a997f6be SessionFixation and TomcatSetup edited
git-svn-id: http://webgoat.googlecode.com/svn/trunk@333 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 07:50:12 +00:00
wirth.marcel
11fa11ec87 git-svn-id: http://webgoat.googlecode.com/svn/trunk@332 4033779f-a91e-0410-96ef-6bf7bf53c507 2008-04-14 07:46:25 +00:00
wirth.marcel
b11b0903c7 Lesson Instruction altered
git-svn-id: http://webgoat.googlecode.com/svn/trunk@331 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 07:44:57 +00:00
wirth.marcel
ff64cf84c0 Introduction Sectin altered
git-svn-id: http://webgoat.googlecode.com/svn/trunk@330 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 07:42:28 +00:00
wirth.marcel
bb327cc3c8 Solution changed. Figure added
git-svn-id: http://webgoat.googlecode.com/svn/trunk@329 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-13 22:18:33 +00:00
wirth.marcel
691af307c5 Insecure Login lesson plan and solution
git-svn-id: http://webgoat.googlecode.com/svn/trunk@328 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-13 22:17:49 +00:00
wirth.marcel
55b36e911b InsecureLogin finished
git-svn-id: http://webgoat.googlecode.com/svn/trunk@327 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-13 22:17:07 +00:00