WebGoat Lessons
WebGoat Lessons
Http Basics
- Lesson is present: Yes
- Time to complete: About ten seconds, unless you start playing around with the
request in WebGoat.
- Notes: None. Dead simple.
-------
-------
-------
-------
-------
-------
Remote Admin Access
- Lesson is present: Yes
- Time to complete: ?????
- Notes: The hints for this still suck, and I still cannot figure out how to do
this lesson. I'm sure I'll kick myself once I figure out how to do it, but until
then...
-------
-------
-------
-------
Forgot Password
- Lesson is present: Yes
- Time to complete: 3 minutes
- Notes: This lesson is guess-and-check. Kind of surprising, but that's brute
force for you.
-------
-------
-------
Basic Authentication
- Lesson is present: yes
- Time to complete: ???
- Notes: I understood what it wanted me to do, but no matter how many times I
base64-encoded 'basic:basic' and stuck it in the authorization header, WebGoat
ignored me.
-------
-------
-------
-------
-------
Buffer Overflow
- Lesson is present: no
-------
-------
-------
-------
-------
-------
-------
-------
Encoding Basics
- Lesson is present: yes
- Time to complete: <1 minute
- Notes: What is the point of this? There's no real way to 'complete' it, or so it
seems.
-------
-------
Forced Browsing
- Lesson is present: no