This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Section 3: ModSecurity protecting WebGoat

From OWASP
Revision as of 06:24, 24 July 2008 by Stephen Evans (talk | contribs) (add intro)

Jump to: navigation, search

This section details the strategy and work done in order to reach the 50% milestone of the project. When the term 'mitigated' is used throughout this document, it is used in the sense that the WebGoat vulnerability in a lesson has been prevented from being exploited by using ModSecurity.


Project Setup and Environment

Doing the WebGoat lessons - tips and tricks

Project organization

ModSecurity rules

SecDirData directory

Error pages

Informational and debug messages