Tag Archives: dom-based xss

WebGoat Week 2

This is the second in a series of ten posts for the OWSAP WebGoat vulnerable web application. New posts for WebGoat will post every Monday. LAB: Role Based Access Control Scheme Bypass Business Layer Access Control For this lab you … Continue reading

Posted in Access Control Flaws, Cross Site Scripting, Data Layer Access Control, DOM Based XSS, Remote Admin Attacks | Tagged , | Leave a comment

Cross Site Scripting – So what?

Ok – so I decided to put in a few things about Cross Site Scripting. I wanted to give you enough information to be able to both understand XSS, and more importantly do it against a modern application protected by … Continue reading

Posted in Cross Site Scripting | Tagged , , , | Leave a comment