Re: [SC-L] Web Application Exploits and Defenses

2010-05-05 Thread Rob Floodeen
On the same subject, I'm looking for something along this line (and that of hacme). However I need it to be able to: 1. Work on current MS Products 2. Store it's data to a remote database 3. Be accessible from Remote systems 4. Clean target space Why? I need an external corporate webserver t

[SC-L] Web Application Exploits and Defenses

2010-05-05 Thread Kenneth Van Wyk
The folks at Google have released some web app training, along with a vulnerable web app sandbox to play in. The tool is called Jarlsberg. Anyone here take a look at it yet, and have an opinion about it? The description (see below) sounds kinda sorta like OWASP's WebGoat, except that the vuln