85 Commits

Author SHA1 Message Date
mayhew64
976671949e Changed the credit card user to be the user that was logged in as. Also base64 encoded the user cookie to make finding sql injection slightly harder.
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@376 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-02-03 18:16:51 +00:00
mayhew64
b63d0a6886 Changed the class build.
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@375 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-02-03 17:56:48 +00:00
mayhew64
3cf801f58f Removed errors introduced in previous checkin. String and integer conflicts in JSP
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@374 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-02-03 17:55:27 +00:00
soylentmean
b8c1d13e50 Lots of wording changes and HTML fixes.
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@373 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-01-06 21:06:42 +00:00
soylentmean
8a372baa01 Fixing wording a smidge.
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@372 4033779f-a91e-0410-96ef-6bf7bf53c507
2009-01-06 20:19:22 +00:00
mayhew64
01b845beb9 Changes by Chris Roe to fix lesson issues with FireFox.
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@371 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-12-17 13:06:29 +00:00
soylentmean
7a55b7e02f fixed a typo
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@370 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-12-11 21:15:20 +00:00
soylentmean
711097a340 Standardized all the HTML, clarified things, and fixed a whole bunch of grammar issues.
I also changed the explanation for Browser Cache Poisoning; the old explanation was incorrect.  If I'm mistaken on that, feel free to revert that part of the explanation.


git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@369 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-12-11 20:04:15 +00:00
mayhew64
696550ccb0 Minor syntax issue with the word prename in the instructions - reported by April King
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@368 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-12-10 23:52:04 +00:00
mayhew64
7998e60f29 Removed hardcoded webgoat path for URLs
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@367 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-11-21 16:57:23 +00:00
mayhew64
c0d2d13e5a Reported by dwpoon, Yesterday (17 hours ago)
I would like to submit the attached patch to avoid hard-coding
"/WebGoat" as the webapp's context path, at least for the HTTP splitting
lesson.  This issue has also been reported in July 2007; see
https://lists.owasp.org/pipermail/owasp-webgoat/2007-July/000432.html

Also see Issue 15 http://code.google.com/p/webgoat/issues/detail?id=15


git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@366 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-11-21 12:57:14 +00:00
mayhew64
3412f1e984 Contribution by Kristian Erik Hermansen. Fixed to work with 1.6
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@365 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-09-09 15:32:23 +00:00
brandon.devries
5854b66614 minor bug fixes and enhancements, including proper dollar value formatting
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@364 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-14 14:31:17 +00:00
brandon.devries
71e53c1ffb removing unused folder
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@363 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-14 12:56:14 +00:00
brandon.devries
a185de3fa0 minor changes and improving display issues
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@362 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-12 17:36:30 +00:00
brandon.devries
775fdad7c4 some cleanup, and removing unneeded ClassNotFoundExceptions
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@361 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-12 14:33:22 +00:00
brandon.devries
9c84df3d6c corrected spelling and some formatting
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@360 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-11 14:39:09 +00:00
brandon.devries
17af39e428 Formatting according to OWASP WebGoat Java Style
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@359 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-08-05 17:32:17 +00:00
mayhew64
7918037066 Removed build.xml
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@358 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 16:14:06 +00:00
mayhew64
95c57ea521 Removed windows and changed to developer
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@357 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 16:05:17 +00:00
mayhew64
7c8dcc37fb Logos that slipped through
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@356 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 16:04:22 +00:00
mayhew64
8f06b0197b Smaller eclipse workspace
Changed workspace name to reflect WebGoat 
Added the video solutions link
Update readmen to reflect contributions and new stuff

git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@355 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 15:40:13 +00:00
sherif.fathy
581151f166 Actually, I think the problem was happening because the lesson was returning the lesson HTML again incase of incorrect key to eval was throwing an error trying to evaluate a whole bunch of HTML. Fixed this by catching the exception and showing an appropriate message.
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@354 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-12 05:56:41 +00:00
mayhew64
084c43381b Added bug report
Added message for missing solutions
Minor edits to lesson plans

git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@353 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-11 00:05:05 +00:00
mayhew64
536d29e78a Minor wording changes
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@352 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-09 00:25:02 +00:00
mayhew64
d590f7deb2 Minor wording edits
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@351 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-09 00:21:32 +00:00
mayhew64
71460125b6 Separated DB usage for messages in CSRF and Stored XSS
Many cosmetic english changes
Fixed IE rendering for Challenge
 

git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@350 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-07-09 00:17:20 +00:00
mayhew64
29f0222258 Minor 5.2 changes.
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@349 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-05-13 03:44:40 +00:00
mayhew64
6598829155 Added doc directory back into main project root. Build script moves doc to webcontent.
Changed how to work with WebGoat picture to have original buttons 

git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@348 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-05-12 14:22:33 +00:00
mayhew64
40ee15bcaa Alphabetized categories
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@347 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-05-12 13:10:17 +00:00
mayhew64
ba26dd3a84 Reorder categories to be alphabetized
Changed unvalidated input to parameter tampering

git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@346 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-22 16:45:29 +00:00
mayhew64
cabc905d4b 5.2 Credits
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@345 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-22 15:38:21 +00:00
mayhew64
2dd882a9a8 Minor fixes
removed many System.out.printlns
delete extra solutions directory - wrong location
added 5.2 credits

git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@344 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-22 15:34:54 +00:00
mayhew64
7f034fa3f9 No Changes - SVN Test
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@343 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-22 12:01:21 +00:00
wirth.marcel
3e1d124434 Text edited
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@342 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-18 08:41:02 +00:00
wirth.marcel
decc426267 Minor changes... Tan gets now only updatet after it was correct
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@341 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-18 08:38:51 +00:00
wirth.marcel
1493631f02 Session Fixation instructions altered
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@340 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-15 09:43:34 +00:00
wirth.marcel
5a0e7a5d7a Session Fixation lesson plan and solution edited
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@339 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-15 09:43:01 +00:00
wirth.marcel
c001a67b95 Minor Bugfixes
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@338 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 13:28:25 +00:00
wirth.marcel
15d80a3006 Minor fixes
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@337 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 12:03:55 +00:00
wirth.marcel
c4b5bb0758 Wireshark to useful tools added
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@336 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 09:24:12 +00:00
wirth.marcel
42d4fd322d InsecureLogin Credits added. Instructions changed
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@335 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 08:35:33 +00:00
wirth.marcel
d7b43ba72c InsecureLogin solution edited
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@334 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 08:33:30 +00:00
wirth.marcel
5b8d96453b SessionFixation and TomcatSetup edited
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@333 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 07:50:12 +00:00
wirth.marcel
1143d00103 git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@332 4033779f-a91e-0410-96ef-6bf7bf53c507 2008-04-14 07:46:25 +00:00
wirth.marcel
6d0d122ee6 Lesson Instruction altered
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@331 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 07:44:57 +00:00
wirth.marcel
8f89989223 Introduction Sectin altered
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@330 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-14 07:42:28 +00:00
wirth.marcel
2105f62f39 Solution changed. Figure added
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@329 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-13 22:18:33 +00:00
wirth.marcel
c99dd85aab Insecure Login lesson plan and solution
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@328 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-13 22:17:49 +00:00
wirth.marcel
5bcf14ba75 InsecureLogin finished
git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@327 4033779f-a91e-0410-96ef-6bf7bf53c507
2008-04-13 22:17:07 +00:00