Penetration Testing mailing list archives

Re: Webgoat help


From: Chris Gates <chris () learnsecurityonline com>
Date: Fri, 04 Aug 2006 17:02:17 -0600

Open 2 browsers, one will have jeff and one will have dave.  Click submit on
both at the same (roughly the same) time.  Because of improper thread
handling one of the browsers will show the wrong information either jeff's
or dave's when it should be the other.

Also, there is webgoat forum
https://lists.sourceforge.net/lists/listinfo/owasp-webgoat

Chris


-- 

Chris Gates, CISSP
C|EH, CPTS, MCP 2003, A+, Network+, Security+

Email:      chris () learnsecurityonline com
Web:        https://www.learnsecurityonline.com

Learn Security Online, Inc.

* Security Games        * Simulators
* Challenge Servers     * Courses
* Hacking Competitions  * Hacklab Access



On 8/4/06 1:50 PM, "3 shool" <3shool () gmail com> wrote:

Hi,

I do not know if this is the right forum to ask for help in Webgoat
but I couldn't find anywhere else. This list has been helping me since
long and I hope I once again get the reqd. help.

I just downloaded and setup Webgoat from owasp.org. While I was trying
to exploit the vulnerabilities in the application I got stuck at many
points and do not have a video or tutorial that can help me move
forward.

Right now I'm stuck at "How to Exploit Thread Safety Problems"
chapter... I'm using the latest version 4 and the link on my screen
shows
http://localhost/WebGoat/attack?Screen=16&menu=50

Can someone tell me how to exploit this... yes I read the hints but I
guess I need more hints...

DO we have a solution video or tutorial for the same?

Eagerly await your reply.

Thanx.

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------




------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? 
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's 
Choice Award from eWeek. As attacks through web applications continue to rise, 
you need to proactively protect your applications from hackers. Cenzic has the 
most comprehensive solutions to meet your application security penetration 
testing and vulnerability management needs. You have an option to go with a 
managed service (Cenzic ClickToSecure) or an enterprise software 
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can 
help you: http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------


Current thread: