Category Archives: Access Control Flaws

Hacme Books Week 5

This is the last in a series five posts for the vulnerable web application Hacme Books. Broken Access Control Access control is one of the major security concerns in any application.  Elevated access to a system may result in disaster … Continue reading

Posted in Access Control Flaws | Tagged | Leave a comment

WebGoat Week 2

This is the second in a series of ten posts for the OWSAP WebGoat vulnerable web application. New posts for WebGoat will post every Monday. LAB: Role Based Access Control Scheme Bypass Business Layer Access Control For this lab you … Continue reading

Posted in Access Control Flaws, Cross Site Scripting, Data Layer Access Control, DOM Based XSS, Remote Admin Attacks | Tagged , | Leave a comment

WebGoat Week 1

This is the first in a series of ten posts for the OWSAP WebGoat vulnerable web application. New posts for WebGoat will post every Monday. General HTTP Splitting and Cache Poisoning For the HTTP splitting portions of this lesson you … Continue reading

Posted in Access Control Flaws, Cache Poisoning, HTTP Splitting | Leave a comment