Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
<font size="5">Test Cases:</font><br><br>
<B><a href="Case01-Tag2HtmlPageScope-StripScriptTag.jsp?userinput=textvalue">Case01-Tag2HtmlPageScope-StripScriptTag.jsp</a></B><br>
Injection of tags to the scope of the HTML page that strips script tags.<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<U>Barriers:</U><br>
Script tags are stripped from the input<br>
<U>Sample Exploit Structures:</U><br>
Expand All @@ -33,7 +33,7 @@

<B><a href="Case02-Tag2HtmlPageScope-SecretVectorPOST.jsp?userinput=textvalue">Case02-Tag2HtmlPageScope-SecretVectorPOST.jsp</a></B><br>
Injection of tags to the scope of the HTML page that that only relies on secret POST input.<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<U>Barriers:</U><br>
Secret input vector without any hints<br>
<U>Sample Exploit Structures:</U><br>
Expand All @@ -48,7 +48,7 @@

<B><a href="Case03-Tag2HtmlPageScope-ConstantAntiCSRFToken.jsp?anticsrf=<%=anticsrf%>&userinput=textvalue">Case03-Tag2HtmlPageScope-ConstantAntiCSRFToken.jsp</a></B><br>
Injection of tags to the scope of the HTML page that requires a constant session stored AntiCSRF token.<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<U>Barriers:</U><br>
Requires a constant session-specific AntiCSRF token<br>
<U>Sample Exploit Structures (alongside the AntiCSRF token):</U><br>
Expand All @@ -63,7 +63,7 @@

<B><a href="Case04-Tag2HtmlPageScope-ChangingAntiCSRFToken.jsp">Case04-Tag2HtmlPageScope-ChangingAntiCSRFToken.jsp</a></B><br>
Injection of tags to the scope of the HTML page that requires an expiring one-use session stored AntiCSRF token.<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<U>Barriers:</U><br>
Requires a changing, newly generated session-specific AntiCSRF token<br>
<U>Sample Exploit Structures (alongside the AntiCSRF token):</U><br>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
<font size="5">Test Cases:</font><br><br>
<B><a href="Case01-Tag2HtmlPageScope-StripScriptTag.jsp">Case01-Tag2HtmlPageScope-StripScriptTag.jsp</a></B><br>
Injection of tags to the scope of the HTML page that strips script tags.<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<U>Barriers:</U><br>
Script tags are stripped from the input<br>
<U>Sample Exploit Structures:</U><br>
Expand All @@ -33,7 +33,7 @@

<B><a href="Case02-Tag2HtmlPageScope-SecretVectorGET.jsp">Case02-Tag2HtmlPageScope-SecretVectorGET.jsp</a></B><br>
Injection of tags to the scope of the HTML page that that only relies on secret GET input.<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<U>Barriers:</U><br>
Secret input vector without any hints<br>
<U>Sample Exploit Structures:</U><br>
Expand All @@ -48,7 +48,7 @@

<B><a href="Case03-Tag2HtmlPageScope-ConstantAntiCSRFToken.jsp">Case03-Tag2HtmlPageScope-ConstantAntiCSRFToken.jsp</a></B><br>
Injection of tags to the scope of the HTML page that requires a constant session stored AntiCSRF token.<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<U>Barriers:</U><br>
Requires a constant session-specific AntiCSRF token<br>
<U>Sample Exploit Structures (alongside the AntiCSRF token):</U><br>
Expand All @@ -63,7 +63,7 @@

<B><a href="Case04-Tag2HtmlPageScope-ChangingAntiCSRFToken.jsp">Case04-Tag2HtmlPageScope-ChangingAntiCSRFToken.jsp</a></B><br>
Injection of tags to the scope of the HTML page that requires an expiring one-use session stored AntiCSRF token.<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<U>Barriers:</U><br>
Requires a changing, newly generated session-specific AntiCSRF token<br>
<U>Sample Exploit Structures (alongside the AntiCSRF token):</U><br>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,8 +12,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,8 +12,8 @@
<body>

<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->

Expand Down
4 changes: 2 additions & 2 deletions WebContent/passive/index-info.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<head>
Expand Down
4 changes: 2 additions & 2 deletions WebContent/passive/index-session.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<head>
Expand Down
4 changes: 2 additions & 2 deletions WebContent/passive/index.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<head>
Expand Down
6 changes: 3 additions & 3 deletions WebContent/passive/info/index.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<head>
Expand All @@ -11,7 +11,7 @@

<H2>Information Leakage</H2>
<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<br>
<H3>Examples</H3>
<UL>
Expand Down
4 changes: 2 additions & 2 deletions WebContent/passive/info/info-app-stack-trace.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<%@ page import="java.util.*" %>
Expand Down
4 changes: 2 additions & 2 deletions WebContent/passive/info/info-cookie-no-httponly.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<%@ page import="java.util.*" %>
Expand Down
4 changes: 2 additions & 2 deletions WebContent/passive/info/info-server-stack-trace.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<%@ page import="java.util.*" %>
Expand Down
6 changes: 3 additions & 3 deletions WebContent/passive/session/index.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<head>
Expand All @@ -11,7 +11,7 @@

<H2>Session vulnerabilities</H2>
<br>
(Contributed by the <b>OWASP Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
(Contributed by the <b>Zed Attack Proxy (ZAP) project</b>, via Simon Bennetts)<br>
<br>
<H3>Examples</H3>
<UL>
Expand Down
4 changes: 2 additions & 2 deletions WebContent/passive/session/session-password-autocomplete.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<head>
Expand Down
4 changes: 2 additions & 2 deletions WebContent/passive/session/weak-authentication-basic.jsp
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<!--
Inspired by a vulnerable test case originally written for the OWASP Zed Attack Proxy (ZAP) project
(http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Inspired by a vulnerable test case originally written for the Zed Attack Proxy (ZAP) project
(https://www.zaproxy.org)
Original Author: psiinon (psiinon@gmail.com).
-->
<head>
Expand Down
Loading