git-svn-id: http://webgoat.googlecode.com/svn/trunk@64 4033779f-a91e-0410-96ef-6bf7bf53c507
		
			
				
	
	
		
			11 lines
		
	
	
		
			908 B
		
	
	
	
		
			HTML
		
	
	
	
	
	
			
		
		
	
	
			11 lines
		
	
	
		
			908 B
		
	
	
	
		
			HTML
		
	
	
	
	
	
| <div align="Center">
 | |
| <p><b>Lesson Plan Title:</b> How to Bypass Client Side JavaScript Validation </p>
 | |
| </div>
 | |
| <p><b>Concept / Topic To Teach:</b> </p>
 | |
| <!-- Start Instructions -->
 | |
| Client-side validation should not be considered a secure means of validating parameters. These validations only help reduce the amount of server processing time for normal users who do not know the format of required input. Attackers can bypass these mechanisms easily in various ways. Any client-side validation should be duplicated on the server side. This will greatly reduce the likelihood of insecure parameter values being used in the application.
 | |
| <!-- Stop Instructions -->
 | |
| <br>
 | |
| <p><b>General Goal(s):</b> </p>
 | |
| For this exercise, the web site requires that you follow certain rules when you fill out a form. The user should be able to break those rules, and send the website input that it wasn't expecting. <br>
 |