Category Archives: Data Layer Access Control

WebGoat Week 2

This is the second in a series of ten posts for the OWSAP WebGoat vulnerable web application. New posts for WebGoat will post every Monday. LAB: Role Based Access Control Scheme Bypass Business Layer Access Control For this lab you … Continue reading

Posted in Access Control Flaws, Cross Site Scripting, Data Layer Access Control, DOM Based XSS, Remote Admin Attacks | Tagged , | Leave a comment