Difference between revisions of "AltoroMutual"

From OWASP
Jump to: navigation, search
(Created page with 'AltoroMutual is an vulnerable-by-design web application created by WatchFire (now AppScan Standard) as a demo test application for their BlackBox Scanner. ===URL=== The AltoroMu…')
 
Line 17: Line 17:
 
* http://parsonsisconsulting.wordpress.com/2010/11/25/sql-injection-with-02-and-google-database-plugin/
 
* http://parsonsisconsulting.wordpress.com/2010/11/25/sql-injection-with-02-and-google-database-plugin/
 
* http://parsonsisconsulting.wordpress.com/2010/11/24/the-power-of-02-scripting/
 
* http://parsonsisconsulting.wordpress.com/2010/11/24/the-power-of-02-scripting/
 +
 +
[[:Category:O2 Platform]]

Revision as of 08:21, 25 November 2010

AltoroMutual is an vulnerable-by-design web application created by WatchFire (now AppScan Standard) as a demo test application for their BlackBox Scanner.

Contents

URL

The AltoroMutual web application can be reach on http://demo.testfire.net/ and it is commonly used to test BlackBox Scanners (IBM's AppScan Standard Evaluation version is hard-coded to only allow this website)

Source Code

The C# source code for AltoroMutual is currently not publicly avaialble

Vulnerabilties

There are number of vulnerabilities (as described in the OWASP Top 10) in this application.

The objective on this WIKI page is to provide detailed explantion of its exploit vector and how it could be protected (WAF or code changes)

External resources

Here are a number of resources that map the current vulnerabilities in AltoroMutual:

Category:O2 Platform