Re: Webgoat help

From: Chris Gates (chris@learnsecurityonline.com)
Date: Fri Aug 04 2006 - 19:02:17 EDT


Open 2 browsers, one will have jeff and one will have dave. Click submit on
both at the same (roughly the same) time. Because of improper thread
handling one of the browsers will show the wrong information either jeff's
or dave's when it should be the other.

Also, there is webgoat forum
https://lists.sourceforge.net/lists/listinfo/owasp-webgoat

Chris

-- 
Chris Gates, CISSP
C|EH, CPTS, MCP 2003, A+, Network+, Security+
Email:      chris@learnsecurityonline.com
Web:        https://www.learnsecurityonline.com
Learn Security Online, Inc.
* Security Games        * Simulators
* Challenge Servers     * Courses
* Hacking Competitions  * Hacklab Access
On 8/4/06 1:50 PM, "3 shool" <3shool@gmail.com> wrote:
> Hi,
> 
> I do not know if this is the right forum to ask for help in Webgoat
> but I couldn't find anywhere else. This list has been helping me since
> long and I hope I once again get the reqd. help.
> 
> I just downloaded and setup Webgoat from owasp.org. While I was trying
> to exploit the vulnerabilities in the application I got stuck at many
> points and do not have a video or tutorial that can help me move
> forward.
> 
> Right now I'm stuck at "How to Exploit Thread Safety Problems"
> chapter... I'm using the latest version 4 and the link on my screen
> shows
> http://localhost/WebGoat/attack?Screen=16&menu=50
> 
> Can someone tell me how to exploit this... yes I read the hints but I
> guess I need more hints...
> 
> DO we have a solution video or tutorial for the same?
> 
> Eagerly await your reply.
> 
> Thanx.
> 
> ------------------------------------------------------------------------------
> This List Sponsored by: Cenzic
> 
> Concerned about Web Application Security?
> Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
> Choice Award from eWeek. As attacks through web applications continue to rise,
> you need to proactively protect your applications from hackers. Cenzic has the
> most comprehensive solutions to meet your application security penetration
> testing and vulnerability management needs. You have an option to go with a
> managed service (Cenzic ClickToSecure) or an enterprise software
> (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
> help you: http://www.cenzic.com/news_events/wpappsec.php
> And, now for a limited time we can do a FREE audit for you to confirm your
> results from other product. Contact us at request@cenzic.com for details.
> ------------------------------------------------------------------------------
> 
------------------------------------------------------------------------------
This List Sponsored by: Cenzic
Concerned about Web Application Security? 
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's 
Choice Award from eWeek. As attacks through web applications continue to rise, 
you need to proactively protect your applications from hackers. Cenzic has the 
most comprehensive solutions to meet your application security penetration 
testing and vulnerability management needs. You have an option to go with a 
managed service (Cenzic ClickToSecure) or an enterprise software 
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can 
help you: http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:56:33 EDT