2266361186
Modified the default ranking such that CSRF can have its correct spot in the lesson ranking scheme.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@82 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-24 19:10:19 +00:00
e121871396
Modified the ranking of the lessons. CSRF has been moved to "Broken Access Control"
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@81 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-24 19:09:24 +00:00
38e9a8967b
Added the AoC logo
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@80 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-24 05:10:43 +00:00
265c56b302
Fixed a bug which caused the RoleBasedAccessControl_i class to be instantiated and inserted into the navigation menu.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@78 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-23 19:11:32 +00:00
1ad2fd45d3
Fixed bug preventing the source from being displayed. Basic code clean-up as well.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@77 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-23 18:56:42 +00:00
16e1bfb9c5
changed from "WebGoat WSDL" to "WebGoat WSDL File"
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@75 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-23 15:37:00 +00:00
7cd01d8656
The old Course object used some insane recursion, causing my JVM to spike at 100%. Furthermore, it increased the WebGoat initial startup time to roughly 1:30-2:00 minutes (for me). In order to address the disk access overhead (the current greatest impacter of performance), we now cache the file names before parsing the lessons and their resources.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@72 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-22 22:25:50 +00:00
88553e25f2
Minor spelling issue in hint.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@71 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-22 20:14:43 +00:00
edbd6446b6
Very minor spacing issue. Commented out a nbsp and modified the contact information to utilize two columns.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@66 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-22 18:45:32 +00:00
f6d5fbfc50
I was getting an empty string and a ".svn" file in the "Help File" drop-down box. Modified parseResults() to ensure that the file is not an empty string and the file ends with ".help"
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@65 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-22 18:33:50 +00:00
8b51818508
Changed remaining contact information to reference an email address I receive (webgoat@g2-inc.com)
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@61 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-16 18:29:06 +00:00
fd9b60f98e
Added some files required to build OWASP release.
...
Modified License text and format to reflect GPL license.
Reformatted most of the code.
git-svn-id: http://webgoat.googlecode.com/svn/trunk@60 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-16 14:56:40 +00:00
036964495b
Fixed comments by Bruce
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@59 4033779f-a91e-0410-96ef-6bf7bf53c507
2007-01-11 05:14:09 +00:00
2fdf823259
Changed BackDoors lessons to be a little bit clearer, added more hints.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@58 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-31 07:35:58 +00:00
c469a8b0a1
Fixed HttpSplitting and CSRF per Bruce's requests
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@57 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-31 06:32:32 +00:00
ae225126ae
Changed CSRF per Bruce's comments
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@56 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-30 17:30:30 +00:00
63043b0f34
Modified Silent Transactions and XML Injection lesson per Bruce's comments
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@55 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-30 08:07:48 +00:00
ba38b57a44
Modified DOMInjection per Bruce's comments
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@54 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-29 16:43:59 +00:00
f19330db4b
Changed help text
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@52 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-29 05:11:40 +00:00
cd4e6a3b95
Minor nits
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@51 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-29 04:51:37 +00:00
37c56c748d
modified CSRF to add an actual attack
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@49 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-28 16:59:02 +00:00
5e061d5bad
Added JSONInjection, SilentTransactions
...
Modified The install guide
git-svn-id: http://webgoat.googlecode.com/svn/trunk@48 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-28 15:35:10 +00:00
af2df52e91
Added Backdoors lesson
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@47 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-25 17:20:01 +00:00
857799f855
Minor syntax cleanup
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@44 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-24 13:38:45 +00:00
7acbacbe61
Added Cache Poisining lesson as a staged lesson to HTTP Splitting lesson.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@40 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-23 00:24:47 +00:00
1d67443b22
Removed some commented code and added more description to the HTTP Splitting lesson
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@38 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-22 00:20:31 +00:00
575d040c24
Added XMLInjection lesson
...
Modified DOM Injection lesson
Added gratification to http splitting
git-svn-id: http://webgoat.googlecode.com/svn/trunk@37 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-21 04:39:32 +00:00
60d65681ff
Renamed XMLInjection to XPATHInjection
...
Made some changes to the lesson according to Jeff's comments
git-svn-id: http://webgoat.googlecode.com/svn/trunk@36 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-16 23:38:02 +00:00
296254e279
This patch contains the HTTP connector that intercepts the requests to the application and tries to communicate with OSG.
...
It also contains the DOM Injection lesson
git-svn-id: http://webgoat.googlecode.com/svn/trunk@35 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-16 22:39:14 +00:00
80a2add2d7
- This patch fixes Forced Browsing lesson by removing any custom coding for WebSession and HammerHead.java
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@34 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-04 04:35:04 +00:00
51d40b7b22
- Contains the XMLInjection lesson.
...
- New files added:
XMLInjection.html, XMLInjection.java and XMLInjection/EmployeesData.xml
git-svn-id: http://webgoat.googlecode.com/svn/trunk@33 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-12-02 19:45:59 +00:00
99779ea2e9
Add a new lesson "How to add a new lesson" under new category "New Lessons"
...
Modified the existing lessons to present the solution in the last hint
git-svn-id: http://webgoat.googlecode.com/svn/trunk@31 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-11-11 22:41:42 +00:00
e5b3b00b0f
General cleanup of warnings, fixed a few method scope issues and incorrect use of static references to categories
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@30 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-11-03 23:55:08 +00:00
fae3c3f047
patch to fix a last minute typo and an unwanted import statement
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@29 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-11-03 02:50:12 +00:00
6a59cd6e6e
git-svn-id: http://webgoat.googlecode.com/svn/trunk@28 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-11-03 01:14:36 +00:00
ca2dfa27d1
* Log spoofing lesson this includes the following file:
...
- LogSpoofing.html
- LogSpoofing.java
git-svn-id: http://webgoat.googlecode.com/svn/trunk@27 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-11-01 02:26:51 +00:00
1a9d859507
- Updated a comment and removed some unused imports in HttpSplitting.java
...
- Added CSRF.html and CSRF.java
git-svn-id: http://webgoat.googlecode.com/svn/trunk@26 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-10-23 01:15:03 +00:00
b6256a17f1
Fixed 'Restart Lesson' bug in SoapRequest.java. Successful completion of a lesson resets the function invocation counters. Added HttpOnly lesson with improved browser identification support.
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@25 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-10-09 14:28:09 +00:00
6916632841
- Added some documentations.
...
- Changed some variable names for clarification
git-svn-id: http://webgoat.googlecode.com/svn/trunk@24 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-10-09 00:49:53 +00:00
6cc8bed0c7
- Added HTTP lesson together with its lesson plan and goals.
...
- Files added:
HttpSplitting.html
HttpSplitting.java
redirect.jsp
- Files Changed:
webgoat-class.properties
webgoat-lmc.properties
git-svn-id: http://webgoat.googlecode.com/svn/trunk@23 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-10-08 23:46:34 +00:00
98949c00d8
Moved remotely
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@15 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:41:26 +00:00
0465a6d6aa
git-svn-id: http://webgoat.googlecode.com/svn/trunk@14 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:40:10 +00:00
d3ad0b6040
Moved remotely
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@12 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:34:48 +00:00
275fe04bfe
git-svn-id: http://webgoat.googlecode.com/svn/trunk@11 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:30:52 +00:00
94b5751542
Removed file/folder
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@10 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:30:07 +00:00
3e581f0119
git-svn-id: http://webgoat.googlecode.com/svn/trunk@9 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:29:19 +00:00
a8ce18c72e
Moved remotely
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@8 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:25:59 +00:00
58c4d16530
Removed file/folder
...
git-svn-id: http://webgoat.googlecode.com/svn/trunk@7 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:25:36 +00:00
8455a33200
git-svn-id: http://webgoat.googlecode.com/svn/trunk@5 4033779f-a91e-0410-96ef-6bf7bf53c507
2006-09-30 13:04:08 +00:00