This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Section 3: ModSecurity protecting WebGoat

From OWASP
Revision as of 06:30, 24 July 2008 by Stephen Evans (talk | contribs)

Jump to: navigation, search

This section details the strategy and work done in order to reach the 50% milestone of the project. When the term 'mitigated' is used throughout this document, it is used in the sense that the WebGoat vulnerability in a lesson has been prevented from being exploited by using ModSecurity.

Project Setup and Environment

Doing the WebGoat lessons - tips and tricks

Project organization

ModSecurity rules

SecDirData directory

Error pages

Informational and debug messages