Commit Graph

  • 63a50df7a1 Add hint to lesson users no longer have guess the complete ip address Nanne Baars 2018-07-06 18:22:29 +02:00
  • f9e552f1cd Add instructions how to run WebGoat on Java 9 or higher Nanne Baars 2018-07-04 19:15:54 +02:00
  • 2233550fe1 Adding more solutions for SQL order by lesson Nanne Baars 2018-06-22 14:12:37 +02:00
  • cb18295f9f Update hint Nanne Baars 2018-06-21 07:53:21 +02:00
  • 651698d96c Add different solution for XXE attack Nanne Baars 2018-06-21 07:17:27 +02:00
  • 4d7d0058c3 Update how to create a release document Nanne Baars 2018-06-20 18:38:16 +02:00
  • e3fba396de Merge tag 'v8.0.0.M21' into develop Nanne Baars 2018-06-20 18:24:06 +02:00
  • 3536fd0b6d Merge branch 'release/v8.0.0.M21' v8.0.0.M21 Nanne Baars 2018-06-20 18:23:59 +02:00
  • bc84e8f207 Build release when tag is set Nanne Baars 2018-06-20 18:22:35 +02:00
  • 14dbd47675 Merge tag 'v8.0.0.M20' into develop Nanne Baars 2018-06-20 18:06:26 +02:00
  • 898dd90c6f Merge branch 'release/v8.0.0.M20' v8.0.0.M20 Nanne Baars 2018-06-20 18:06:17 +02:00
  • ac12a009e4 New release v8.0.0.M20 Nanne Baars 2018-06-20 18:05:59 +02:00
  • 699b1bfd89 Only do releases and Docker updates when building master Nanne Baars 2018-06-20 18:05:06 +02:00
  • ad77a7ab24 Merge tag 'v8.0.0.M19' into develop Nanne Baars 2018-06-20 16:40:44 +02:00
  • b7278590f5 Merge branch 'release/v8.0.0.M19' v8.0.0.M19 Nanne Baars 2018-06-20 16:40:33 +02:00
  • 9dd93d88d9 New release v8.0.0.M19 Nanne Baars 2018-06-20 16:40:28 +02:00
  • 4c767cb977 Merge tag 'v8.0.0.M18' into develop Nanne Baars 2018-06-20 16:32:44 +02:00
  • 12123ef13b Merge branch 'release/v8.0.0.M18' v8.0.0.M18 Nanne Baars 2018-06-20 16:32:31 +02:00
  • c7da546249 Improve text for lesson about CSRF login Matthias Grundmann 2018-06-14 11:00:43 +02:00
  • a41ff0083c
    Merge pull request #479 from misfir3/develop misfir3 2018-06-13 18:44:09 -06:00
  • 701a99cf8f
    Merge pull request #487 from matthias-g/xssFixes misfir3 2018-06-13 18:42:14 -06:00
  • 844808bfa7
    Merge pull request #485 from matthias-g/fixSQLInjection misfir3 2018-06-13 18:41:05 -06:00
  • 81aac93dfe
    Usage base64 encoded password as expected by JJWT Matthias Grundmann 2018-06-13 17:58:52 +02:00
  • e5ec2c1ee0
    Fix html attribute Matthias Grundmann 2018-06-13 17:56:57 +02:00
  • b0fbeaff2c
    This improves the text of the lesson about XSS Matthias Grundmann 2018-06-13 17:56:23 +02:00
  • b47bb96534
    Update changed password in tests Matthias Grundmann 2018-06-13 16:11:28 +02:00
  • 3b9b695ef1 Check host header instead of origin which might not be present #475 Matthias Grundmann 2018-06-12 17:35:00 +02:00
  • 1d2575a211 Allow - in usernames because CSRF lesson requires username starting with prefix crsf- #476 Matthias Grundmann 2018-06-12 10:49:24 +02:00
  • 56fc983414
    Update database layout so that proposed solution works Matthias Grundmann 2018-06-12 17:36:44 +02:00
  • 268adbcf7e
    Move assignments to correct package so that hints are shown Matthias Grundmann 2018-06-12 17:35:57 +02:00
  • f383454440 Fix spelling in JWT lesson Matthias Grundmann 2018-06-11 16:53:32 +02:00
  • bae3e75ae2 Fix minor issues in hint view Matthias Grundmann 2018-06-11 16:43:16 +02:00
  • a7b82985d4 Fix usage of JJWT API which expects base64 encoded strings as key Matthias Grundmann 2018-06-08 19:31:32 +02:00
  • 3d282e163c Show newest comments first Matthias Grundmann 2018-06-08 16:45:27 +02:00
  • 7068c84c6a Fix parameter in url and some spelling Matthias Grundmann 2018-06-08 15:43:53 +02:00
  • 0030c7bdfb
    Merge pull request #480 from matthias-g/fixPageNum misfir3 2018-06-07 11:27:29 -06:00
  • 89f6a73275
    Fix next page button when url doesn't end with page number Matthias Grundmann 2018-06-07 19:07:58 +02:00
  • cf0e4e40cf clean up Jason White 2018-06-05 14:36:40 -06:00
  • dfd51f8b54 Merge branch 'develop' of github.com:misfir3/WebGoat into develop Jason White 2018-06-05 14:10:51 -06:00
  • 5e8c610fbf gke-deploy.sh Jason White 2018-06-05 14:10:29 -06:00
  • 71514fc39b GKE deploy script Jason White 2018-06-05 09:45:47 -06:00
  • 1734170e9e updates to missing function ac lesson Jason 2018-06-04 16:53:13 -06:00
  • c89afe6334 Merge remote-tracking branch 'upstream/develop' into develop Jason 2018-06-01 09:54:03 -06:00
  • 9af0054b5b Merge branch 'release/v8.0.0.M17' v8.0.0.M17 Nanne Baars 2018-05-30 20:54:18 +02:00
  • 26aa72e721 New release Nanne Baars 2018-05-30 20:54:13 +02:00
  • c510bd9bf1 New develop version Nanne Baars 2018-05-30 20:37:25 +02:00
  • 6bf853d953 Merge tag 'v8.0.0.M16' into develop Nanne Baars 2018-05-30 20:35:56 +02:00
  • b298440985 Merge branch 'release/v8.0.0.M16' v8.0.0.M16 Nanne Baars 2018-05-30 20:35:22 +02:00
  • c7a714a590 Move to next release Nanne Baars 2018-05-30 17:05:50 +02:00
  • 93620f148b Remove challenges which are also incorporated in the lessons themselves Nanne Baars 2018-05-30 16:46:50 +02:00
  • ecb7688e08 Update to new version for develop Move WebWolf to port 9090 easier since most of the time something is running on 8081 Add scripts for easy building Docker files etc Nanne Baars 2018-05-30 13:17:05 +02:00
  • 0de784eb32 Update README and simply the java command to one with optional arguments Nanne Baars 2018-05-29 22:16:29 +02:00
  • 4691bc5fd5 Extended proxy lesson with Edit and Resend and explained how to exclude WebGoat internal calls from proxying Nanne Baars 2018-05-29 21:30:13 +02:00
  • fc2c99bcb4 Limit the username to letters and digits only Nanne Baars 2018-05-29 16:16:52 +02:00
  • 7292a577e3 Only do a release when we build master and have a tagged the release Nanne Baars 2018-05-29 15:20:07 +02:00
  • 396c1c1d47 Update order of starting WebGoat Nanne Baars 2018-05-29 15:16:29 +02:00
  • 2911788679 Merge tag 'v8.0.0' into develop Nanne Baars 2018-05-29 14:59:32 +02:00
  • 985148ede3 Merge branch 'release/v8.0.0' v8.0.0 Nanne Baars 2018-05-29 14:59:07 +02:00
  • 9587550bc5 Fixed column name on sql injection lesson 7 MaDuck 2018-05-28 16:54:44 +02:00
  • 9a0995dae5 Fixed column name on sql injection lesson 6 MaDuck 2018-05-28 16:53:23 +02:00
  • 4e07e0ebfa Fix links to open new browser tab Nanne Baars 2018-05-29 14:04:33 +02:00
  • 6e95fdfe56 Adjusted documentation Nanne Baars 2018-05-29 13:33:52 +02:00
  • e045bc692d Buying page also calculates the prices Product image added Nanne Baars 2018-05-29 12:47:27 +02:00
  • 589872ad47 Fix for JWT assignment 1 log in now works again. Reset button only triggers reset when admin is set to true in the token Nanne Baars 2018-05-29 11:20:40 +02:00
  • 5f4889cefe Clicking link in first password reset link only switched back and forward Nanne Baars 2018-05-29 09:29:50 +02:00
  • 55793dd153 New release v8.0.0.M15 v8.0.0.M15 Nanne Baars 2018-05-27 20:54:50 +02:00
  • 1edceb0aa8 Extended and fixed some lessons Nanne Baars 2018-05-27 20:37:44 +02:00
  • d2b6725f3b Moved challenge2 to client-side-filtering as final assignment Nanne Baars 2018-05-27 12:41:52 +02:00
  • 6e003bc088 Working last password assignment Nanne Baars 2018-05-26 18:48:48 +02:00
  • f8a7a61e85 New lesson working Nanne Baars 2018-05-26 15:09:18 +02:00
  • eaf68d38c5 Initial commit for password reset lesson Nanne Baars 2018-05-25 14:27:45 +02:00
  • 8d7ecb19d7 Added testcases for all JWT endpoints Nanne Baars 2018-05-23 12:51:57 +02:00
  • e0cf5b4a84 Removed under construction from JWT lesson Nanne Baars 2018-05-22 20:31:08 +02:00
  • 5b524d3a94 Added more unit tests Nanne Baars 2018-05-22 20:30:09 +02:00
  • dda6f674a3 Last assignment for JWT tokens finished Nanne Baars 2018-05-22 17:06:03 +02:00
  • e06d4642eb Fix error in testcase Nanne Baars 2018-05-21 20:50:28 +02:00
  • 4a8fdcf887 Fix content-type for login (gives error in console of browser) Nanne Baars 2018-05-21 19:04:53 +02:00
  • fd96ba18f1 Added test cases for solving the lesson Nanne Baars 2018-05-21 18:42:50 +02:00
  • 60ef35e241 Working lesson Nanne Baars 2018-05-21 13:19:26 +02:00
  • 9d7886d572 More JWT work Nanne Baars 2018-05-21 12:41:37 +02:00
  • 7a0820bf89 WIP Nanne Baars 2018-05-16 12:39:23 +02:00
  • ea9c1a453d Initial version for JWT Nanne Baars 2018-04-23 11:09:30 +02:00
  • 63ca11a1bb Change WebWolf to WebGoat Ryan Thomas 2018-05-22 17:36:59 -07:00
  • 5378d72600 Change version in pom.xml Nanne Baars 2018-05-23 14:04:21 +02:00
  • 93d6d0e6b7 Added lesson texts Jose Selvi 2018-05-22 10:24:34 +02:00
  • 84860e65f6 Insecure Deserialization exercise Jose Selvi 2018-05-16 17:35:03 +02:00
  • a73bf58d36 more hintview patching Jason 2018-05-03 10:49:58 -06:00
  • 0ff6000511 wiring jqueryui to vuln jquery #368 Jason 2018-05-03 10:49:31 -06:00
  • 91d9db5f80 work-arounds, fixes for page initialization and some clean-up Jason 2018-05-03 10:25:34 -06:00
  • ac1b9e8311 cleanup that was missed in prev. commit Jason 2018-05-02 16:36:34 -06:00
  • 9d49373486 fix for periodic fail on StoredXssCommentsTest Jason 2018-05-02 16:35:57 -06:00
  • ead78d40e6 Chore - fix spelling issues Nick Smith 2018-02-09 17:29:42 -05:00
  • 7b5bb6d6f1 Fixed typos xanderhades 2018-01-29 17:25:19 -05:00
  • 408a637649 Update HttpBasics_ProxyIntro0.adoc Nitish 2018-01-22 15:56:10 +05:30
  • e96ab488ff Merge branch 'develop' of github.com:misfir2/WebGoat into develop Jason White 2018-05-14 12:17:32 -06:00
  • 31f7ea6985 script to automate WebGoat deployment on GKE jason 2018-05-14 12:15:48 -06:00
  • 6cf96f971d Fix typo Nanne Baars 2018-05-11 15:14:11 +02:00
  • 0b9a027c19 Fix some minor grammatical issues. TimDG 2018-05-08 11:27:13 +02:00
  • 186f24f1df more hintview patching Jason 2018-05-03 10:49:58 -06:00
  • 089dd56a15 wiring jqueryui to vuln jquery #368 Jason 2018-05-03 10:49:31 -06:00