{"platform":{"name":"Heimdall Tools","release":"1.3.0"},"version":"1.3.0","statistics":{"duration":null},"profiles":[{"name":"OWASP ZAP Scan","version":"2.7.0","title":"OWASP ZAP Scan of Host: mymac.com","maintainer":null,"summary":"OWASP ZAP Scan of Host: mymac.com","license":null,"copyright":null,"copyright_email":null,"supports":[],"attributes":[],"depends":[],"groups":[],"status":"loaded","controls":[{"id":"90028.1","title":"Insecure HTTP Method - MKCOL","desc":"This HTTP method is a WEBDAV method: MKCOL. If this server is not offering any WEBDAV services, these methods should not be available.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Informational (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/SqlInjection/servers?column=id\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/lesson_js/bypass.js?_=1544107787924\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/service/hint.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544108073698\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/service/lessoninfo.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/lesson_js/bootstrap.min.js?_=1544107787922\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/service/debug/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/SqlInjectionMitigations.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/lesson_js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/WebGoatIntroduction.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/lesson_js/assignment12.js?_=1544107787919\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/challenge/8/votes\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/service/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/HttpProxies.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/lesson_js/password-reset-simple.js?_=1544107787923\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/service/lessonoverview.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MKCOL\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting/stored-xss\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10010","title":"Cookie No HttpOnly Flag","desc":"A cookie has been set without the HttpOnly flag, which means that the cookie can be accessed by JavaScript. If a malicious script can be run on this page then the cookie will be accessible and can be transmitted to another site. If this is a session cookie then session hijacking may be possible.","impact":0.3,"tags":{"nist":["unmapped"],"cweid":"16","wascid":"13","sourceid":"3","confidence":"2","riskdesc":"Low (Medium)","check":"<p>Ensure that the HttpOnly flag is set for all cookies.</p>\n\n"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: Set-Cookie: JSESSIONID\nMethod: GET\nParam: JSESSIONID\nUri: http://mymac.com:8191/WebGoat/attack\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Set-Cookie: JSESSIONID\nMethod: GET\nParam: JSESSIONID\nUri: http://mymac.com:8191/WebGoat/logout\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Set-Cookie: access_token\nMethod: GET\nParam: access_token\nUri: http://mymac.com:8191/WebGoat/JWT/votings/login?user=Guest\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Set-Cookie: JSESSIONID\nMethod: GET\nParam: JSESSIONID\nUri: http://mymac.com:8191/WebGoat/fonts/fontawesome-webfont.woff?v=4.0.3\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Set-Cookie: JSESSIONID\nMethod: GET\nParam: JSESSIONID\nUri: http://mymac.com:8191/WebGoat/start.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Set-Cookie: JSESSIONID\nMethod: GET\nParam: JSESSIONID\nUri: http://mymac.com:8191/WebGoat/\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Set-Cookie: JSESSIONID\nMethod: GET\nParam: JSESSIONID\nUri: http://mymac.com:8191/WebGoat/login?logout\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Set-Cookie: JSESSIONID\nMethod: POST\nParam: JSESSIONID\nUri: http://mymac.com:8191/WebGoat/login\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10095","title":"Backup File Disclosure","desc":"A backup of the file was disclosed by the web server","impact":0.5,"tags":{"nist":["unmapped"],"cweid":"425","wascid":"34","sourceid":"1","confidence":"2","riskdesc":"Medium (Medium)","check":"<p>Do not edit files in-situ on the web server, and ensure that un-necessary files (including hidden files) are removed from the web server.</p>\n<p>http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%></p>\n<p>http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%></p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.old.baseUrl%>\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.old.baseUrl%>]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.old.baseUrl%>\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.2\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.2]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.2\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.backup\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.backup]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.backup\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bz2.baseUrl%>\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bz2.baseUrl%>]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bz2.baseUrl%>\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.old\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.old]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.old\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.gz\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.gz]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.gz\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.~bk\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.~bk]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.~bk\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.0\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.0]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.0\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>~\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>~]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>~\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bac\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bac]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bac\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.gz\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.gz]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.gz\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bak.baseUrl%>\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bak.baseUrl%>]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.bak.baseUrl%>\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.bac\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.bac]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.bac\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.orig.baseUrl%>\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.orig.baseUrl%>]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.orig.baseUrl%>\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.backup.baseUrl%>\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.backup.baseUrl%>]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.backup.baseUrl%>\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.exe\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.exe]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.exe\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.1\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.1]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.1\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.zip\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.zip]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.zip\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.swp\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.swp]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>.swp\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.1\nEvidence: A backup of [http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E] is available at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.1]\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.1\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90028.2","title":"Insecure HTTP Method - COPY","desc":"This HTTP method is a WEBDAV method: COPY. If this server is not offering any WEBDAV services, these methods should not be available.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Informational (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/lesson_js/password-reset-simple.js?_=1544107787923\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/HttpProxies.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting/stored-xss\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/lesson_js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/service\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/challenge/8/votes\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/SqlInjectionAdvanced.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/HttpBasics.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/SqlInjectionMitigations.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/SqlInjection\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/service/lessoninfo.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/lesson_js/bootstrap.min.js?_=1544107787922\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/AuthBypass.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/lesson_js/assignment12.js?_=1544107787919\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/WebGoatIntroduction.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544108073698\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/service/lessonoverview.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: COPY\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90028.3","title":"Insecure HTTP Method - MOVE","desc":"This HTTP method is a WEBDAV method: MOVE. If this server is not offering any WEBDAV services, these methods should not be available.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Informational (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting/stored-xss\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/lesson_js/challenge.js?_=1544107787918\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/service\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/HttpBasics.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/HttpProxies.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/lesson_js/password-reset-simple.js?_=1544107787923\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/challenge/8\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/SqlInjectionAdvanced.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/lesson_js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/service/lessonprogress.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/PasswordReset.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/lesson_js/stored-xss.js?_=1544108073699\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/service/debug/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/SqlInjection/servers?column=id\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/service/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/service/lessoninfo.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/service/debug\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: MOVE\nUri: http://mymac.com:8191/WebGoat/lesson_js/bypass.js?_=1544107787924\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90028.4","title":"Insecure HTTP Method - PUT","desc":"This method was originally intended for file managemant operations. It is now most commonly used in REST services, PUT is most-often utilized for **update** capabilities, PUT-ing to a known resource URI with the request body containing the newly-updated representation of the original resource..","impact":0.5,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Medium (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods, for understanding REST operations see http://www.restapitutorial.com/lessons/httpmethods.html</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods, for understanding REST operations see http://www.restapitutorial.com/lessons/httpmethods.html</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/service/ixvsrz0hz5\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/lesson_js/challenge.js?_=1544107787918/00dfqjxpr0\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/service/lessonprogress.mvc/ov8o4i4cxb\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting/stored-xss/l75ohjdbcz\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting/66hxlzn8iv\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/SqlInjectionMitigations.lesson.lesson/o0zqg3osop\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc/yxxfu40mzc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/service/labels.mvc/kqmx8plyqp\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/lesson_js/bootstrap.min.js?_=1544107787922/ry1v48bqo2\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/lesson_js/stored-xss.js?_=1544108073699/nup8fuk9jv\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/service/debug/wavpiy56r0\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/service/hint.mvc/2c7ugyjrbx\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/WebGoatIntroduction.lesson.lesson/0ovfht8qeu\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/service/lessonoverview.mvc/o7eg68rtmj\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/SqlInjectionAdvanced.lesson.lesson/ecpghb5i3h\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544108073698/0qcvijm5f6\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/AuthBypass.lesson.lesson/qo4qznscod\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/challenge/8/votes/hyp7hbjya6\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson/og02v787sa\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PUT\nUri: http://mymac.com:8191/WebGoat/HttpProxies.lesson.lesson/3ylc0lqab1\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10202","title":"Absence of Anti-CSRF Tokens","desc":"No Anti-CSRF tokens were found in a HTML submission form.A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.CSRF attacks are effective in a number of situations, including:    * The victim has an active session on the target site.    * The victim is authenticated via HTTP auth on the target site.    * The victim is on the same local network as the target site.CSRF has primarily been used to perform an action against a target site using the victim's privileges, but recent techniques have been discovered to disclose information by gaining access to the response. The risk of information disclosure is dramatically increased when the target site is vulnerable to XSS, because XSS can be used as a platform for CSRF, allowing the attack to operate within the bounds of the same-origin policy.","impact":0.3,"tags":{"nist":["AC-3","Rev_4"],"cweid":"352","wascid":"9","sourceid":"3","confidence":"2","riskdesc":"Low (Medium)","check":"<p>Phase: Architecture and Design</p><p>Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.</p><p>For example, use anti-CSRF packages such as the OWASP CSRFGuard.</p><p></p><p>Phase: Implementation</p><p>Ensure that your application is free of cross-site scripting issues, because most CSRF defenses can be bypassed using attacker-controlled script.</p><p></p><p>Phase: Architecture and Design</p><p>Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330).</p><p>Note that this can be bypassed using XSS.</p><p></p><p>Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.</p><p>Note that this can be bypassed using XSS.</p><p></p><p>Use the ESAPI Session Management control.</p><p>This control includes a component for CSRF.</p><p></p><p>Do not use the GET method for any request that triggers a state change.</p><p></p><p>Phase: Implementation</p><p>Check the HTTP Referer header to see if the request originated from an expected page. This could break legitimate functionality, because users or proxies may have disabled sending the Referer for privacy reasons.</p>\n<p>No known Anti-CSRF token [anticsrf, CSRFToken, __RequestVerificationToken, csrfmiddlewaretoken, authenticity_token, OWASP_CSRFTOKEN, anoncsrf] was found in the following HTML form: [Form 1: \"changeMe\" ].</p>\n<p>No known Anti-CSRF token [anticsrf, CSRFToken, __RequestVerificationToken, csrfmiddlewaretoken, authenticity_token, OWASP_CSRFTOKEN, anoncsrf] was found in the following HTML form: [Form 1: \"changeMe\" ].</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" name=\"intercept-request\" method=\"POST\" action=\"/WebGoat/HttpProxies/intercept-request\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/HttpProxies.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" name=\"task\" method=\"POST\" action=\"#attack/307/100\" enctype=\"application/json;charset=UTF-8\">\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"form-horizontal\" action=\"/WebGoat/register.mvc\" method=\"POST\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/registration\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" id=\"change-password-form\" method=\"POST\" name=\"form\" successCallback=\"onBypassResponse\" action=\"/WebGoat/auth-bypass/verify-account\" enctype=\"application/json;charset=UTF-8\" style=\"display:none\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/AuthBypass.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/WebWolf/mail/\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/WebWolfIntroduction.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/PasswordReset/reset/create-password-reset-link\" enctype=\"application/json;charset=UTF-8\" role=\"form\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/PasswordReset.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" name=\"task\" method=\"POST\" action=\"/WebGoat/InsecureLogin/task\" enctype=\"application/json;charset=UTF-8\">\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form id=\"register-form\" class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"PUT\" name=\"form\" action=\"SqlInjection/challenge\" enctype=\"application/json;charset=UTF-8\" style=\"display: none;\" role=\"form\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/SqlInjectionAdvanced.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" method=\"POST\" name=\"diff-form\" action=\"IDOR/diff-attributes\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/IDOR.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/1\" style=\"width: 200px;\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge1.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" name=\"frontendValidation\" id=\"frontendValidation\" method=\"POST\" action=\"/WebGoat/BypassRestrictions/frontendValidation/\" enctype=\"application/json;charset=UTF-8\" onsubmit=\"return validate()\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/BypassRestrictions.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/SqlInjection/attack5a\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/SqlInjection.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form method=\"POST\" style=\"width: 200px;\" action=\"/WebGoat/login\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/login?logout\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" action=\"/WebGoat/PasswordReset/questions\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/PasswordReset.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/HttpBasics/attack1\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/HttpBasics.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/flag\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge6.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form id=\"register-form\" class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"PUT\" name=\"form\" action=\"/WebGoat/challenge/6\" enctype=\"application/json;charset=UTF-8\" style=\"display: none;\" role=\"form\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge6.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form id=\"login-form\" class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/5\" enctype=\"application/json;charset=UTF-8\" role=\"form\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge5.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" name=\"fieldRestrictions\" method=\"POST\" action=\"/WebGoat/BypassRestrictions/FieldRestrictions\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/BypassRestrictions.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/flag\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge7.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10027","title":"Information Disclosure - Suspicious Comments","desc":"The response appears to contain suspicious comments which may help an attacker.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"13","sourceid":"3","confidence":"2","riskdesc":"Informational (Medium)","check":"<p>Remove all comments that return information that may help an attacker and fix any underlying problems they refer to.</p>\n<p><!-- do not remove the two following div's, this is where your feedback/output will land --></p><p><!-- do not remove the two following div's, this is where your feedback/output will land --></p><p></p>\n<p><!-- do not remove the two following div's, this is where your feedback/output will land --></p><p><!-- do not remove the two following div's, this is where your feedback/output will land --></p><p></p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/HttpBasics.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544108073698\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/lesson_js/jwt-voting.js?_=1544107787947\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/js/libs/text.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/start.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: POST\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/lesson_js/stored-xss.js?_=1544107787952\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/js/libs/backbone-min.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/lesson_js/assignment12.js?_=1544107787919\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/ClientSideFiltering.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/AuthBypass.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544106249403\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/js/libs/underscore-min.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/view/UserAndInfoView.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/js/libs/jquery.form.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/view/LessonContentView.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/js/modernizr-2.6.2.min.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/VulnerableComponents.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90028.5","title":"Insecure HTTP Method - PROPPATCH","desc":"This HTTP method is a WEBDAV method: PROPPATCH. If this server is not offering any WEBDAV services, these methods should not be available.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Informational (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/bootstrap.min.js?_=1544107787922\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/service/lessonprogress.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/SqlInjection\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/SqlInjectionMitigations.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/HttpBasics.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/service/debug/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/challenge.js?_=1544107787918\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/bypass.js?_=1544107787924\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/service\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/service/lessoninfo.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/SqlInjection/servers?column=id\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting/stored-xss\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/stored-xss.js?_=1544108073699\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/challenge/8\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/SqlInjectionAdvanced.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/service/debug\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/PasswordReset.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/assignment12.js?_=1544107787919\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPPATCH\nUri: http://mymac.com:8191/WebGoat/challenge/8/votes\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90028.6","title":"Insecure HTTP Method - PROPFIND","desc":"This HTTP method is a WEBDAV method: PROPFIND. If this server is not offering any WEBDAV services, these methods should not be available.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Informational (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/PasswordReset.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/service/lessoninfo.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/SqlInjectionAdvanced.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/lesson_js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/challenge/8/votes\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/service/lessonoverview.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/service/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/HttpProxies.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544108073698\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/AuthBypass.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/WebGoatIntroduction.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/lesson_js/assignment12.js?_=1544107787919\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/SqlInjection\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/challenge/8\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/lesson_js/stored-xss.js?_=1544108073699\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/service/lessonprogress.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/service/debug/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PROPFIND\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10023.1","title":"Information Disclosure - Debug Error Messages","desc":"The response appeared to contain common error messages returned by platforms such as ASP.NET, and Web-servers such as IIS and Apache. You can configure the list of common debug messages.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"13","sourceid":"3","confidence":"2","riskdesc":"Low (Medium)","check":"<p>Disable debugging messages before pushing to production.</p>\n\n"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E/%3C%25=index%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/challenge/7\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/IDOR/profile/alt-path\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/challenge/flag\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/IDOR/profile/%7BuserId%7D?View+Profile=View+Profile\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10023.2","title":"Information Disclosure - Debug Error Messages","desc":"The response appeared to contain common error messages returned by platforms such as ASP.NET, and Web-servers such as IIS and Apache. You can configure the list of common debug messages.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"13","sourceid":"3","confidence":"2","riskdesc":"Low (Medium)","check":"<p>Disable debugging messages before pushing to production.</p>\n\n"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E/%3C%25=index%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/challenge/7\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/IDOR/profile/alt-path\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/challenge/flag\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/IDOR/profile/%7BuserId%7D?View+Profile=View+Profile\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10023.3","title":"Information Disclosure - Debug Error Messages","desc":"The response appeared to contain common error messages returned by platforms such as ASP.NET, and Web-servers such as IIS and Apache. You can configure the list of common debug messages.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"13","sourceid":"3","confidence":"2","riskdesc":"Low (Medium)","check":"<p>Disable debugging messages before pushing to production.</p>\n\n"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E/%3C%25=index%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/challenge/7\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/IDOR/profile/alt-path\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/challenge/flag\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/IDOR/profile/%7BuserId%7D?View+Profile=View+Profile\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Internal Server Error\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90028.7","title":"Insecure HTTP Method - PATCH","desc":"This method is now most commonly used in REST services, PATCH is used for **modify** capabilities. The PATCH request only needs to contain the changes to the resource, not the complete resource.","impact":0.5,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Medium (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods, for understanding REST operations see http://www.restapitutorial.com/lessons/httpmethods.html</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods, for understanding REST operations see http://www.restapitutorial.com/lessons/httpmethods.html</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/service/lessonoverview.mvc/eh79fr0hqg\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc/wreq5y0a7l\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting.lesson.lesson/zm4mz99dlc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/bootstrap.min.js?_=1544107787922/lh51ktufa2\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/challenge/8/votes/2t85ricln1\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/HttpBasics.lesson.lesson/p0kmik78y1\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/SqlInjection/servers?column=id/czpve71c6f\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/service/f9r0o7rim6\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/SqlInjection/64anwrsu4c\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544108073698/7oq2rqa5sa\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/WebGoatIntroduction.lesson.lesson/6oiufjzooj\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/service/labels.mvc/nn288rrdbp\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/PasswordReset.lesson.lesson/fja4tms7h6\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/stored-xss.js?_=1544108073699/25gvf9s6s7\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/service/lessonprogress.mvc/omuhh6arma\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/c3e684sost\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/lesson_js/bypass.js?_=1544107787924/v0fu6lixpx\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/SqlInjectionAdvanced.lesson.lesson/n8prgootk5\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/service/lessoninfo.mvc/ruq25qpun7\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: PATCH\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson/0oqh22nenm\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90028.8","title":"Insecure HTTP Method - UNLOCK","desc":"This HTTP method is a WEBDAV method: UNLOCK. If this server is not offering any WEBDAV services, these methods should not be available.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Informational (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/service/lessonprogress.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/lesson_js/bootstrap.min.js?_=1544107787922\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/challenge/8\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/HttpBasics.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/service/debug/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/SqlInjection\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/service/hint.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting/stored-xss\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/service\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/service/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544108073698\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/service/lessonoverview.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/HttpProxies.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/WebGoatIntroduction.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/SqlInjectionMitigations.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/lesson_js/assignment12.js?_=1544107787919\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: UNLOCK\nUri: http://mymac.com:8191/WebGoat/AuthBypass.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10024","title":"Information Disclosure - Sensitive Informations in URL","desc":"The request appeared to contain sensitive information leaked in the URL. This can violate PCI and most organizational compliance policies. You can configure the list of strings for this check to add or remove values specific to your environment.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"13","sourceid":"3","confidence":"2","riskdesc":"Informational (Medium)","check":"<p>Do not pass sensitive information in URIs.</p>\n<p>The URL contains potentially sensitive information.</p>\n<p>The URL contains potentially sensitive information.</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: ZAP\nMethod: GET\nParam: username_reg\nUri: http://mymac.com:8191/WebGoat/challenge/6?confirm_password_reg=ZAP&email_reg=foo-bar%40example.com&password_reg=ZAP&register-submit=Register+Now&username_reg=ZAP\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: ZAP\nMethod: GET\nParam: confirm_password_reg\nUri: http://mymac.com:8191/WebGoat/challenge/6?confirm_password_reg=ZAP&email_reg=foo-bar%40example.com&password_reg=ZAP&register-submit=Register+Now&username_reg=ZAP\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: foo-bar@example.com\nMethod: GET\nParam: email_reg\nUri: http://mymac.com:8191/WebGoat/challenge/6?confirm_password_reg=ZAP&email_reg=foo-bar%40example.com&password_reg=ZAP&register-submit=Register+Now&username_reg=ZAP\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: Guest\nMethod: GET\nParam: user\nUri: http://mymac.com:8191/WebGoat/JWT/votings/login?user=Guest\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: ZAP\nMethod: GET\nParam: password_reg\nUri: http://mymac.com:8191/WebGoat/challenge/6?confirm_password_reg=ZAP&email_reg=foo-bar%40example.com&password_reg=ZAP&register-submit=Register+Now&username_reg=ZAP\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90028.9","title":"Insecure HTTP Method - LOCK","desc":"This HTTP method is a WEBDAV method: LOCK. If this server is not offering any WEBDAV services, these methods should not be available.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"45","sourceid":"1","confidence":"2","riskdesc":"Informational (Medium)","check":"<p></p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>\n<p>See the discussion on stackexchange: https://security.stackexchange.com/questions/21413/how-to-exploit-http-methods</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/SqlInjectionMitigations.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/service/hint.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/service/lessonprogress.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/challenge/8\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/lesson_js/stored-xss.js?_=1544108073699\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/service/labels.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting/stored-xss\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/service/lessoninfo.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/lesson_js/credentials.js?_=1544108073698\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/service/lessonoverview.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/service\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/WebGoatIntroduction.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/SqlInjection\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/CrossSiteScripting.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/HttpBasics.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/lesson_js/bootstrap.min.js?_=1544107787922\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/SqlInjectionAdvanced.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: response code 401 for potentially insecure HTTP METHOD\nMethod: LOCK\nUri: http://mymac.com:8191/WebGoat/challenge/8/votes\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90022","title":"Application Error Disclosure","desc":"This page contains an error/warning message that may disclose sensitive information like the location of the file that produced the unhandled exception. This information can be used to launch further attacks against the web application. The alert could be a false positive if the error message is found inside a documentation page.","impact":0.5,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"13","sourceid":"3","confidence":"2","riskdesc":"Medium (Medium)","check":"<p>Review the source code of this page. Implement custom error pages. Consider implementing a mechanism to provide a unique error reference/identifier to the client (browser) while logging the details on the server side and not exposing them to the user.</p>\n\n"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: HTTP/1.1 500\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/IDOR/profile/alt-path\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: HTTP/1.1 500\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/challenge/7\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: HTTP/1.1 500\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E/%3C%25=index%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: HTTP/1.1 500\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/IDOR/profile/%7BuserId%7D?View+Profile=View+Profile\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: HTTP/1.1 500\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: HTTP/1.1 500\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/challenge/flag\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"42","title":"Source Code Disclosure - SVN","desc":"The source code for the current page was disclosed by the web server","impact":0.7,"tags":{"nist":["unmapped"],"cweid":"541","wascid":"34","sourceid":"1","confidence":"1","riskdesc":"High (Low)","check":"<p>Ensure that SVN metadata files are not deployed to the web server or application server</p>\n<p>The source code for [<%=index%>] was found at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>/.svn/text-base/<%=index%>.svn-base]</p>\n<p>The source code for [<%=index%>] was found at [http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>/.svn/text-base/<%=index%>.svn-base]</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>/.svn/text-base/<%=index%>.svn-base\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>/<%=index%>\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: http://mymac.com:8191/WebGoat/js/goatApp/templates/.svn/text-base/<%=overview.baseUrl%>.svn-base\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/<%=overview.baseUrl%>\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10016","title":"Web Browser XSS Protection Not Enabled","desc":"Web Browser XSS Protection is not enabled, or is disabled by the configuration of the 'X-XSS-Protection' HTTP response header on the web server","impact":0.3,"tags":{"nist":["unmapped"],"cweid":"933","wascid":"14","sourceid":"3","confidence":"2","riskdesc":"Low (Medium)","check":"<p>Ensure that the web browser's XSS filter is enabled, by setting the X-XSS-Protection HTTP response header to '1'.</p>\n<p>The X-XSS-Protection HTTP response header allows the web server to enable or disable the web browser's XSS protection mechanism. The following values would attempt to enable it: </p><p>X-XSS-Protection: 1; mode=block</p><p>X-XSS-Protection: 1; report=http://www.example.com/xss</p><p>The following values would disable it:</p><p>X-XSS-Protection: 0</p><p>The X-XSS-Protection HTTP response header is currently supported on Internet Explorer, Chrome and Safari (WebKit).</p><p>Note that this alert is only raised if the response body could potentially contain an XSS payload (with a text-based content type, with a non-zero length).</p>\n<p>The X-XSS-Protection HTTP response header allows the web server to enable or disable the web browser's XSS protection mechanism. The following values would attempt to enable it: </p><p>X-XSS-Protection: 1; mode=block</p><p>X-XSS-Protection: 1; report=http://www.example.com/xss</p><p>The following values would disable it:</p><p>X-XSS-Protection: 0</p><p>The X-XSS-Protection HTTP response header is currently supported on Internet Explorer, Chrome and Safari (WebKit).</p><p>Note that this alert is only raised if the response body could potentially contain an XSS payload (with a text-based content type, with a non-zero length).</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Method: GET\nParam: X-XSS-Protection\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E/%3C%25=index%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Method: GET\nParam: X-XSS-Protection\nUri: http://mymac.com:8191/WebGoat/js/goatApp/templates/%3C%25=overview.baseUrl%25%3E\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"20012","title":"Anti CSRF Tokens Scanner","desc":"A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.CSRF attacks are effective in a number of situations, including:    * The victim has an active session on the target site.    * The victim is authenticated via HTTP auth on the target site.    * The victim is on the same local network as the target site.CSRF has primarily been used to perform an action against a target site using the victim's privileges, but recent techniques have been discovered to disclose information by gaining access to the response. The risk of information disclosure is dramatically increased when the target site is vulnerable to XSS, because XSS can be used as a platform for CSRF, allowing the attack to operate within the bounds of the same-origin policy.","impact":0.7,"tags":{"nist":["AC-3","Rev_4"],"cweid":"352","wascid":"9","sourceid":"1","confidence":"2","riskdesc":"High (Medium)","check":"<p>Phase: Architecture and Design</p><p>Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.</p><p>For example, use anti-CSRF packages such as the OWASP CSRFGuard.</p><p></p><p>Phase: Implementation</p><p>Ensure that your application is free of cross-site scripting issues, because most CSRF defenses can be bypassed using attacker-controlled script.</p><p></p><p>Phase: Architecture and Design</p><p>Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330).</p><p>Note that this can be bypassed using XSS.</p><p></p><p>Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.</p><p>Note that this can be bypassed using XSS.</p><p></p><p>Use the ESAPI Session Management control.</p><p>This control includes a component for CSRF.</p><p></p><p>Do not use the GET method for any request that triggers a state change.</p><p></p><p>Phase: Implementation</p><p>Check the HTTP Referer header to see if the request originated from an expected page. This could break legitimate functionality, because users or proxies may have disabled sending the Referer for privacy reasons.</p>\n\n"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: <form role=\"form\" method=\"POST\" action=\"http://localhost:9090/landing\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/WebWolf/landing/password-reset\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/1\" style=\"width: 200px;\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge1.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form id=\"login-form\" class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/6\" enctype=\"application/json;charset=UTF-8\" role=\"form\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge6.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/IDOR/login\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/IDOR.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/WebWolf/mail/send\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/WebWolfIntroduction.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form method=\"POST\" style=\"width: 200px;\" action=\"/WebGoat/login\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/login?logout\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form method=\"POST\" style=\"width: 200px;\" action=\"/WebGoat/login\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/login\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form method=\"POST\" style=\"width: 200px;\" action=\"/WebGoat/login\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/login?error\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/SqlInjection/attack5a\" enctype=\"application/json;charset=UTF-8\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/SqlInjection.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"form-horizontal\" action=\"/WebGoat/register.mvc\" method=\"POST\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/registration\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form id=\"login-form\" class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/5\" enctype=\"application/json;charset=UTF-8\" role=\"form\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge5.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"form-horizontal\" action=\"/WebGoat/register.mvc\" method=\"POST\">\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/register.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form id=\"login-form\" class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/7\" enctype=\"application/json;charset=UTF-8\" role=\"form\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge7.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" method=\"POST\" name=\"form\" action=\"/WebGoat/challenge/flag\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/Challenge8.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" method=\"POST\" name=\"form\" action=\"/WebGoat/access-control/hidden-menu\">\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/MissingFunctionAC.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form class=\"attack-form\" accept-charset=\"UNKNOWN\" name=\"task\" method=\"POST\" action=\"#attack/307/100\" enctype=\"application/json;charset=UTF-8\">\nMethod: POST\nUri: http://mymac.com:8191/WebGoat/InsecureLogin.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form>\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/libs/jquery.form.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"10026","title":"HTTP Parameter Override","desc":"Unspecified form action: HTTP parameter override attack potentially possible. This is a known problem with Java Servlets but other platforms may also be vulnerable.","impact":0.5,"tags":{"nist":["SI-10","Rev_4"],"cweid":"20","wascid":"20","sourceid":"3","confidence":"1","riskdesc":"Medium (Low)","check":"<p>All forms must specify the action URL.</p>\n\n"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: <form>\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/js/libs/jquery.form.js\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: <form>\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/PasswordReset.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"40018","title":"SQL Injection","desc":"SQL injection may be possible.","impact":0.7,"tags":{"nist":["SI-10","Rev_4"],"cweid":"89","wascid":"19","sourceid":"1","confidence":"2","riskdesc":"High (Medium)","check":"<p>Do not trust client side input, even if there is client side validation in place.  </p><p>In general, type check all data on the server side.</p><p>If the application uses JDBC, use PreparedStatement or CallableStatement, with parameters passed by '?'</p><p>If the application uses ASP, use ADO Command Objects with strong type checking and parameterized queries.</p><p>If database Stored Procedures can be used, use them.</p><p>Do *not* concatenate strings into queries in the stored procedure, or use 'exec', 'exec immediate', or equivalent functionality!</p><p>Do not create dynamic SQL queries using simple string concatenation.</p><p>Escape all data received from the client.</p><p>Apply a 'whitelist' of allowed characters, or a 'blacklist' of disallowed characters in user input.</p><p>Apply the principle of least privilege by using the least privileged database user possible.</p><p>In particular, avoid using the 'sa' or 'db-owner' database users. This does not eliminate SQL injection, but minimizes its impact.</p><p>Grant the minimum database access that is necessary for the application.</p>\n<p>The original page results were successfully replicated using the \"ORDER BY\" expression [query ASC  -- ] as the parameter value</p><p>The parameter value being modified was stripped from the HTML output for the purposes of the comparison</p>\n<p>The original page results were successfully replicated using the \"ORDER BY\" expression [query ASC  -- ] as the parameter value</p><p>The parameter value being modified was stripped from the HTML output for the purposes of the comparison</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Attack: query ASC  -- \nMethod: GET\nParam: query\nUri: http://mymac.com:8191/WebGoat/service/debug/labels.mvc?query=query+ASC++--+\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: query\" OR \"1\"=\"1\" -- \nMethod: GET\nParam: query\nUri: http://mymac.com:8191/WebGoat/service/lessonmenu.mvc?query=query%22+AND+%221%22%3D%221%22+--+\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: query\" OR \"1\"=\"1\" -- \nMethod: GET\nParam: query\nUri: http://mymac.com:8191/WebGoat/lesson_js?query=query%22+AND+%221%22%3D%221%22+--+\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: query AND 1=1\nMethod: GET\nParam: query\nUri: http://mymac.com:8191/WebGoat/register.mvc?query=query+AND+1%3D1\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: query OR 1=1\nMethod: GET\nParam: query\nUri: http://mymac.com:8191/WebGoat/challenge/8?query=query+AND+1%3D1\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Attack: query AND 1=1\nMethod: GET\nParam: query\nUri: http://mymac.com:8191/WebGoat/challenge/8?query=query+AND+1%3D1\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"2","title":"Private IP Disclosure","desc":"A private IP (such as 10.x.x.x, 172.x.x.x, 192.168.x.x) or an Amazon EC2 private hostname (for example, ip-10-0-56-78) has been found in the HTTP response body. This information might be helpful for further attacks targeting internal systems.","impact":0.3,"tags":{"nist":["SC-8","Rev_4"],"cweid":"200","wascid":"13","sourceid":"3","confidence":"2","riskdesc":"Low (Medium)","check":"<p>Remove the private IP address from the HTTP response body.  For comments, use JSP/ASP/PHP comment instead of HTML/JavaScript comment which can be seen by client browsers.</p>\n<p>192.168.1.151:9090</p><p></p>\n<p>192.168.1.151:9090</p><p></p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Evidence: 192.168.1.151:9090\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/WebWolfIntroduction.lesson.lesson\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"},{"status":"failed","code_desc":"Evidence: 192.168.4.0\nMethod: GET\nUri: http://mymac.com:8191/WebGoat/SqlInjection/servers?column=id\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]},{"id":"90011","title":"Charset Mismatch (Header Versus Meta Content-Type Charset)","desc":"This check identifies responses where the HTTP Content-Type header declares a charset different from the charset defined by the body of the HTML or XML. When there's a charset mismatch between the HTTP header and content body Web browsers can be forced into an undesirable content-sniffing mode to determine the content's correct character set.An attacker could manipulate content on the page to be interpreted in an encoding of their choice. For example, if an attacker can control content at the beginning of the page, they could inject script using UTF-7 encoded text and manipulate some browsers into interpreting that text.","impact":0.3,"tags":{"nist":["unmapped"],"cweid":"16","wascid":"15","sourceid":"3","confidence":"1","riskdesc":"Informational (Low)","check":"<p>Force UTF-8 for all text content in both the HTTP header and meta tags in HTML or encoding declarations in XML.</p>\n<p>There was a charset mismatch between the HTTP Header and the META content-type encoding declarations: [UTF-8] and [ISO-8859-1] do not match.</p>\n<p>There was a charset mismatch between the HTTP Header and the META content-type encoding declarations: [UTF-8] and [ISO-8859-1] do not match.</p>"},"descriptions":[],"refs":[],"source_location":{},"code":"","results":[{"status":"failed","code_desc":"Method: GET\nUri: http://mymac.com:8191/WebGoat/start.mvc\n","run_time":0.0,"start_time":"Thu, 6 Dec 2018 10:53:11"}]}],"sha256":"52d56a4dbf0d61150750aeeff78423db9d6b624deb3a4f4e98394973fcb36b5a"}]}