cktricky
|
7acc17aea3
|
everything checks out re: unit tests. Additionally, this closes issue #112 (seriously, are we up to 112 issues already?)
|
2014-05-22 10:56:29 -06:00 |
|
cktricky
|
2ef2209f70
|
resolves issue #121 by saving JSAPI and HTML5 shim locally within Railsgoat
|
2014-05-19 08:54:58 -04:00 |
|
cktricky
|
d2bd77a461
|
the latest sqli tutorial leveraging @forced_request modifications. We really need some more unit-tests for all this new functionality
|
2014-04-17 22:07:58 -04:00 |
|
cktricky
|
77fcf26abd
|
working on a tutorial for the scope injection / sql injection
|
2014-04-17 20:51:16 -04:00 |
|
John Poulin
|
196b732b91
|
Fixed bug in analytics view
|
2014-04-17 20:04:32 -04:00 |
|
John Poulin
|
3f63480022
|
Added Analytics function to track user hits by ip address, referrer and user agent
|
2014-04-17 20:03:50 -04:00 |
|
John Poulin
|
5056f77395
|
Added codefix example for CSS context XSS.
|
2014-04-17 20:03:17 -04:00 |
|
John Poulin
|
e760fc0087
|
merging
|
2014-04-17 20:03:14 -04:00 |
|
cktricky
|
8e4e084dc9
|
Fixes #99. We have added the hogan method for escaping user input and added a tutorial
|
2014-04-17 12:51:02 -04:00 |
|
cktricky
|
d4c882a1c7
|
Fixes #107. Added some verbiage surrounding the SQL Injection tutorial
|
2014-04-17 08:09:02 -04:00 |
|
cktricky
|
59946e056c
|
changed motorcross to motocross everywhere that it used. Closes or resolves issue #104
|
2014-03-26 12:58:48 -04:00 |
|
cktricky
|
7a89ae6f17
|
added the tutorial for the newest logic flaw
|
2014-03-16 22:10:19 -04:00 |
|
cktricky
|
8140cb3a1b
|
added the basic template of a tutorial guide for the newly added logic flaw, now I have to fill it out :-( (j/k)
|
2014-03-16 16:19:07 -04:00 |
|
cktricky
|
7a4efaa950
|
added the basic components to begin working on the pay index view
|
2014-03-15 10:28:52 -04:00 |
|
cktricky
|
2c8781ebc1
|
added a pay controller and model
|
2014-03-14 20:29:14 -04:00 |
|
cktricky
|
e49b43f899
|
added the verbose model attributes finding under the exposure section within the tutorials
|
2014-03-12 20:28:59 -04:00 |
|
cktricky
|
4b0560a250
|
whew, now THAT is a huge tutorial explanation for a relatively simple issue!
|
2014-03-12 18:59:38 -04:00 |
|
cktricky
|
c559bd5602
|
updated tutorial to reflect changes to the correct code listed within the user model
|
2014-03-09 20:16:54 -04:00 |
|
ecneladis
|
84fd9503ca
|
Removed duplicated code from exemplary validations for password
|
2014-03-06 19:40:33 +01:00 |
|
Mike McCabe
|
4801dc518a
|
fixing two A5 typos
|
2013-11-14 11:26:31 -05:00 |
|
Mike McCabe
|
3ec9765ca3
|
small update to A7
|
2013-11-14 11:24:15 -05:00 |
|
cktricky
|
f53ab56e92
|
fixes a bug introduced during the transition from info_disclosure to A6
|
2013-11-14 11:06:27 -05:00 |
|
cktricky
|
b9e2723175
|
closes issue #30
|
2013-11-14 10:59:20 -05:00 |
|
cktricky
|
edfe5b646e
|
fixed category number and this closes issue #35
|
2013-11-14 10:52:04 -05:00 |
|
cktricky
|
419a051da9
|
Merge branch 'top-10-2013' of github.com:OWASP/railsgoat into top-10-2013
|
2013-11-14 10:47:44 -05:00 |
|
cktricky
|
b84c8d4cc7
|
finished write-up for broken auth
|
2013-11-14 10:47:27 -05:00 |
|
Mike McCabe
|
e116d8b096
|
finishing A7
|
2013-11-14 10:34:35 -05:00 |
|
cktricky
|
890717b7ea
|
write-up complete for exposure
|
2013-11-14 10:10:58 -05:00 |
|
cktricky
|
e764efe1d4
|
working on A6 tutorial write-up now that the code is working
|
2013-11-14 09:39:57 -05:00 |
|
Mike McCabe
|
aeabbcf8c6
|
A7 - switching the var used in the view so that non-admins can view the admin panel
|
2013-11-13 19:14:12 -05:00 |
|
Mike McCabe
|
af8776a3ea
|
halfway done A7
|
2013-11-13 18:23:38 -05:00 |
|
cktricky
|
8c672fd2fc
|
fixed the route
|
2013-11-13 12:16:48 -05:00 |
|
Mike McCabe
|
f0ca17df79
|
updating the information for A9 fixes #27
|
2013-11-13 11:47:29 -05:00 |
|
Mike McCabe
|
fe9d8b266f
|
adding security misconfig text
|
2013-11-12 18:55:14 -05:00 |
|
cktricky
|
6950accce4
|
a6 exposure, working on the wording for SSNs being stored in the clear
|
2013-11-12 17:44:27 -05:00 |
|
cktricky
|
655b636c38
|
Merge branch 'top-10-2013' of github.com:OWASP/railsgoat into top-10-2013
|
2013-11-12 16:12:49 -05:00 |
|
Mike McCabe
|
c06140659c
|
updated description with owasp one
|
2013-11-12 16:10:38 -05:00 |
|
cktricky
|
14bff998dd
|
Merge branch 'master' of github.com:OWASP/railsgoat into top-10-2013
|
2013-11-12 16:07:23 -05:00 |
|
Michael McCabe
|
7833b85837
|
updating description with owasp 2013 description
|
2013-11-12 15:24:07 -05:00 |
|
Michael McCabe
|
cf1b5dc124
|
updating description with owasp 2013 description
|
2013-11-12 13:55:24 -05:00 |
|
GSMcNamara
|
09c0f07d8b
|
Lowercased a letter.
|
2013-11-07 15:06:05 -05:00 |
|
GSMcNamara
|
7ddec28bcc
|
Removed apostrophe
|
2013-11-07 15:02:31 -05:00 |
|
GSMcNamara
|
813711d79e
|
Grammar fix.
|
2013-11-07 14:56:18 -05:00 |
|
cktricky
|
a65a20a647
|
Merge branch 'master' of github.com:OWASP/railsgoat into top-10-2013
|
2013-10-14 08:29:39 -04:00 |
|
Mike McCabe
|
8686f6b9d3
|
adding messages mvc to allow users to send messages.
|
2013-10-11 16:03:37 -04:00 |
|
cktricky
|
17e082a63e
|
I believe the secure_compare tutorial is complete
|
2013-08-18 20:46:40 -04:00 |
|
cktricky
|
5b6b88a4ba
|
fixed broken auth numbering and also the incorrect accordion labels within insecure_compare
|
2013-08-18 20:18:33 -04:00 |
|
cktricky
|
bc74edf28d
|
lastest work towards the secure_compare tutorial
|
2013-08-18 20:10:36 -04:00 |
|
cktricky
|
979b6a229a
|
working on avoiding timing attacks piece
|
2013-08-17 21:27:33 -04:00 |
|
cktricky
|
d909f55ab9
|
initial write-up for gauntlt
|
2013-08-08 21:25:52 -04:00 |
|