Section 4: Mitigating the WebGoat lessons