Monthly Archives: July 2012

WebGoat Week 2

This is the second in a series of ten posts for the OWSAP WebGoat vulnerable web application. New posts for WebGoat will post every Monday. LAB: Role Based Access Control Scheme Bypass Business Layer Access Control For this lab you … Continue reading

Posted in Access Control Flaws, Cross Site Scripting, Data Layer Access Control, DOM Based XSS, Remote Admin Attacks | Tagged , | Leave a comment

WebGoat Week 1

This is the first in a series of ten posts for the OWSAP WebGoat vulnerable web application. New posts for WebGoat will post every Monday. General HTTP Splitting and Cache Poisoning For the HTTP splitting portions of this lesson you … Continue reading

Posted in Access Control Flaws, Cache Poisoning, HTTP Splitting | Leave a comment