[sqlmap-users] (no subject)
Brought to you by:
inquisb
From: Manuel Z. <man...@gm...> - 2014-03-07 07:28:10
|
<?xml version="1.0"?> <!DOCTYPE items [ <!ELEMENT items (item*)> <!ATTLIST items burpVersion CDATA ""> <!ATTLIST items exportTime CDATA ""> <!ELEMENT item (time, url, host, port, protocol, method, path, extension, request, status, responselength, mimetype, response, comment)> <!ELEMENT time (#PCDATA)> <!ELEMENT url (#PCDATA)> <!ELEMENT host (#PCDATA)> <!ATTLIST host ip CDATA ""> <!ELEMENT port (#PCDATA)> <!ELEMENT protocol (#PCDATA)> <!ELEMENT method (#PCDATA)> <!ELEMENT path (#PCDATA)> <!ELEMENT extension (#PCDATA)> <!ELEMENT request (#PCDATA)> <!ATTLIST request base64 (true|false) "false"> <!ELEMENT status (#PCDATA)> <!ELEMENT responselength (#PCDATA)> <!ELEMENT mimetype (#PCDATA)> <!ELEMENT response (#PCDATA)> <!ATTLIST response base64 (true|false) "false"> <!ELEMENT comment (#PCDATA)> ]> <items burpVersion="1.5" exportTime="Fri Mar 07 07:45:18 CET 2014"> <item> <time>Fri Mar 07 07:34:26 CET 2014</time> <url><![CDATA[http://localhost/WebGoat/attack?Screen=6&menu=1100]]></url> <host ip="127.0.0.1">localhost</host> <port>80</port> <protocol>http</protocol> <method>POST</method> <path><![CDATA[/WebGoat/attack?Screen=6&menu=1100]]></path> <extension>null</extension> <request base64="true"><![CDATA[UE9TVCAvV2ViR29hdC9hdHRhY2s/U2NyZWVuPTYmbWVudT0xMTAwIEhUVFAvMS4xDQpIb3N0OiBsb2NhbGhvc3QNClVzZXItQWdlbnQ6IE1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgV09XNjQ7IHJ2OjI3LjApIEdlY2tvLzIwMTAwMTAxIEZpcmVmb3gvMjcuMA0KQWNjZXB0OiB0ZXh0L2h0bWwsYXBwbGljYXRpb24veGh0bWwreG1sLGFwcGxpY2F0aW9uL3htbDtxPTAuOSwqLyo7cT0wLjgNCkFjY2VwdC1MYW5ndWFnZTogZGUtZGUsZGU7cT0wLjgsZW4tdXM7cT0wLjUsZW47cT0wLjMNCkFjY2VwdC1FbmNvZGluZzogZ3ppcCwgZGVmbGF0ZQ0KUmVmZXJlcjogaHR0cDovL2xvY2FsaG9zdC9XZWJHb2F0L2F0dGFjaw0KQ29va2llOiBKU0VTU0lPTklEPTE0MTI3MjUxNDIzNDE2MkIwODJGMzU0OERDQ0Y2MEM4DQpBdXRob3JpemF0aW9uOiBCYXNpYyBaM1ZsYzNRNlozVmxjM1E9DQpDb25uZWN0aW9uOiBrZWVwLWFsaXZlDQpDb250ZW50LVR5cGU6IGFwcGxpY2F0aW9uL3gtd3d3LWZvcm0tdXJsZW5jb2RlZA0KQ29udGVudC1MZW5ndGg6IDI2DQoNCnVzZXJpZD1qc21pdGgmU1VCTUlUPUdvJTIx]]></request> <status>200</status> <responselength>30452</responselength> <mimetype>HTML</mimetype> <response base64="true"><![CDATA[HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=ISO-8859-1
Date: Fri, 07 Mar 2014 06:34:26 GMT
Content-Length: 30302




<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1" />
<title>Add Data with SQL Injection</title>
<link rel="stylesheet" href="css/webgoat.css" type="text/css" />
<link rel="stylesheet" href="css/lesson.css" type="text/css" />
<link rel="stylesheet" href="css/menu.css" type="text/css" />
<link rel="stylesheet" href="css/layers.css" type="text/css" />
<script language="JavaScript1.2" src="javascript/javascript.js" type="text/javascript"></script>
<script language="JavaScript1.2" src="javascript/menu_system.js" type="text/javascript"></script>
<script language="JavaScript1.2" src="javascript/lessonNav.js" type="text/javascript"></script>
<script language="JavaScript1.2" src="javascript/makeWindow.js" type="text/javascript"></script>
<script language="JavaScript1.2" src="javascript/toggle.js" type="text/javascript"></script>
</head>

<body class="page" onload="setMenuMagic1(10,40,10,'menubottom','menu5','submenu5','mbut5','menu100','submenu100','mbut100','menu200','submenu200','mbut200','menu400','submenu400','mbut400','menu500','submenu500','mbut500','menu600','submenu600','mbut600','menu700','submenu700','mbut700','menu800','submenu800','mbut800','menu900','submenu900','mbut900','menu1000','submenu1000','mbut1000','menu1100','submenu1100','mbut1100','menu1200','submenu1200','mbut1200','menu1300','submenu1300','mbut1300','menu1400','submenu1400','mbut1400','menu1500','submenu1500','mbut1500','menu1600','submenu1600','mbut1600','menu1700','submenu1700','mbut1700','menu1800','submenu1800','mbut1800','menu1900','submenu1900','mbut1900','menu2000','submenu2000','mbut2000','menu3000','submenu3000','mbut3000');trigMM1url('menu',1);MM_preloadImages('images/buttons/hintLeftOver.jpg','images/buttons/hintOver.jpg','images/buttons/hintRightOver.jpg','images/buttons/paramsOver.jpg','images/buttons/htmlOver.jpg','images/buttons/cookiesOver.jpg','images/buttons/javaOver.jpg','images/buttons/plansOver.jpg','images/buttons/logout.jpg','images/buttons/helpOver.jpg'); initIframe();">

	<div id="wrap">
	
		<div id="menu5" style="position:absolute; left:30px; top:140px; width:160px; z-index:105"><a href="javascript:;" onclick="trigMenuMagic1('menu5',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut5" border="0" alt=""/>Introduction</a></div>
		
		<div id="menu100" style="position:absolute; left:30px; top:170px; width:160px; z-index:106"><a href="javascript:;" onclick="trigMenuMagic1('menu100',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut100" border="0" alt=""/>General</a></div>
		
		<div id="menu200" style="position:absolute; left:30px; top:200px; width:160px; z-index:107"><a href="javascript:;" onclick="trigMenuMagic1('menu200',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut200" border="0" alt=""/>Access Control Flaws</a></div>
		
		<div id="menu400" style="position:absolute; left:30px; top:230px; width:160px; z-index:108"><a href="javascript:;" onclick="trigMenuMagic1('menu400',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut400" border="0" alt=""/>AJAX Security</a></div>
		
		<div id="menu500" style="position:absolute; left:30px; top:260px; width:160px; z-index:109"><a href="javascript:;" onclick="trigMenuMagic1('menu500',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut500" border="0" alt=""/>Authentication Flaws</a></div>
		
		<div id="menu600" style="position:absolute; left:30px; top:290px; width:160px; z-index:110"><a href="javascript:;" onclick="trigMenuMagic1('menu600',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut600" border="0" alt=""/>Buffer Overflows</a></div>
		
		<div id="menu700" style="position:absolute; left:30px; top:320px; width:160px; z-index:111"><a href="javascript:;" onclick="trigMenuMagic1('menu700',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut700" border="0" alt=""/>Code Quality</a></div>
		
		<div id="menu800" style="position:absolute; left:30px; top:350px; width:160px; z-index:112"><a href="javascript:;" onclick="trigMenuMagic1('menu800',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut800" border="0" alt=""/>Concurrency</a></div>
		
		<div id="menu900" style="position:absolute; left:30px; top:380px; width:160px; z-index:113"><a href="javascript:;" onclick="trigMenuMagic1('menu900',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut900" border="0" alt=""/>Cross-Site Scripting (XSS)</a></div>
		
		<div id="menu1000" style="position:absolute; left:30px; top:410px; width:160px; z-index:114"><a href="javascript:;" onclick="trigMenuMagic1('menu1000',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1000" border="0" alt=""/>Improper Error Handling</a></div>
		
		<div id="menu1100" style="position:absolute; left:30px; top:440px; width:160px; z-index:115"><a href="javascript:;" onclick="trigMenuMagic1('menu1100',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1100" border="0" alt=""/>Injection Flaws</a></div>
		
		<div id="menu1200" style="position:absolute; left:30px; top:470px; width:160px; z-index:116"><a href="javascript:;" onclick="trigMenuMagic1('menu1200',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1200" border="0" alt=""/>Denial of Service</a></div>
		
		<div id="menu1300" style="position:absolute; left:30px; top:500px; width:160px; z-index:117"><a href="javascript:;" onclick="trigMenuMagic1('menu1300',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1300" border="0" alt=""/>Insecure Communication</a></div>
		
		<div id="menu1400" style="position:absolute; left:30px; top:530px; width:160px; z-index:118"><a href="javascript:;" onclick="trigMenuMagic1('menu1400',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1400" border="0" alt=""/>Insecure Configuration</a></div>
		
		<div id="menu1500" style="position:absolute; left:30px; top:560px; width:160px; z-index:119"><a href="javascript:;" onclick="trigMenuMagic1('menu1500',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1500" border="0" alt=""/>Insecure Storage</a></div>
		
		<div id="menu1600" style="position:absolute; left:30px; top:590px; width:160px; z-index:120"><a href="javascript:;" onclick="trigMenuMagic1('menu1600',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1600" border="0" alt=""/>Malicious Execution</a></div>
		
		<div id="menu1700" style="position:absolute; left:30px; top:620px; width:160px; z-index:121"><a href="javascript:;" onclick="trigMenuMagic1('menu1700',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1700" border="0" alt=""/>Parameter Tampering</a></div>
		
		<div id="menu1800" style="position:absolute; left:30px; top:650px; width:160px; z-index:122"><a href="javascript:;" onclick="trigMenuMagic1('menu1800',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1800" border="0" alt=""/>Session Management Flaws</a></div>
		
		<div id="menu1900" style="position:absolute; left:30px; top:680px; width:160px; z-index:123"><a href="javascript:;" onclick="trigMenuMagic1('menu1900',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut1900" border="0" alt=""/>Web Services</a></div>
		
		<div id="menu2000" style="position:absolute; left:30px; top:710px; width:160px; z-index:124"><a href="javascript:;" onclick="trigMenuMagic1('menu2000',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut2000" border="0" alt=""/>Admin Functions</a></div>
		
		<div id="menu3000" style="position:absolute; left:30px; top:740px; width:160px; z-index:125"><a href="javascript:;" onclick="trigMenuMagic1('menu3000',1);return false" onfocus="if(this.blur)this.blur()"><img src="images/menu_images/1x1.gif" width="1" height=1"20" name="mbut3000" border="0" alt=""/>Challenge</a></div>
		    
		<div id="submenu5" class="pviimenudiv" style="position:absolute; left:200px; top:72px; width:150px; visibility: hidden; z-index:126">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><img src="images/buttons/lessonComplete.jpg"><a href="attack?Screen=32&menu=5">How to work with WebGoat</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=48&menu=5">Tomcat Configuration</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=5&menu=5">Useful Tools</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=42&menu=5">How to create a Lesson</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu100" class="pviimenudiv" style="position:absolute; left:200px; top:102px; width:150px; visibility: hidden; z-index:127">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=16&menu=100">Http Basics</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=3&menu=100">HTTP Splitting</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu200" class="pviimenudiv" style="position:absolute; left:200px; top:132px; width:150px; visibility: hidden; z-index:128">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=53&menu=200">Using an Access Control Matrix</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=57&menu=200">Bypass a Path Based Access Control Scheme</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=65&menu=200">LAB: Role Based Access Control</a></td>
	    		</tr>
	    		
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=65&menu=200&stage=1">Stage 1: Bypass Business Layer Access Control</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=65&menu=200&stage=2">Stage 2: Add Business Layer Access Control</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=65&menu=200&stage=3">Stage 3: Bypass Data Layer Access Control</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=65&menu=200&stage=4">Stage 4: Add Data Layer Access Control</a>
						</td></tr>
				
			<tr>
	      		<td><a href="attack?Screen=10&menu=200">Remote Admin Access</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu400" class="pviimenudiv" style="position:absolute; left:200px; top:162px; width:150px; visibility: hidden; z-index:129">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=41&menu=400">Same Origin Policy Protection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=49&menu=400">LAB: DOM-Based cross-site scripting</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=55&menu=400">LAB: Client Side Filtering</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=74&menu=400">DOM Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=59&menu=400">XML Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=44&menu=400">JSON Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=68&menu=400">Silent Transactions Attacks</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=22&menu=400">Dangerous Use of Eval</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=43&menu=400">Insecure Client Storage</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu500" class="pviimenudiv" style="position:absolute; left:200px; top:192px; width:150px; visibility: hidden; z-index:130">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=66&menu=500">Password Strength</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=64&menu=500">Forgot Password</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=35&menu=500">Basic Authentication</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=33&menu=500">Multi Level Login 2</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=61&menu=500">Multi Level Login 1</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu600" class="pviimenudiv" style="position:absolute; left:200px; top:222px; width:150px; visibility: hidden; z-index:131">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=50&menu=600">Off-by-One Overflows</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu700" class="pviimenudiv" style="position:absolute; left:200px; top:252px; width:150px; visibility: hidden; z-index:132">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=40&menu=700">Discover Clues in the HTML</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu800" class="pviimenudiv" style="position:absolute; left:200px; top:282px; width:150px; visibility: hidden; z-index:133">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=69&menu=800">Thread Safety Problems</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=15&menu=800">Shopping Cart Concurrency Flaw</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu900" class="pviimenudiv" style="position:absolute; left:200px; top:312px; width:150px; visibility: hidden; z-index:134">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=54&menu=900">Phishing with XSS</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=20&menu=900">LAB: Cross Site Scripting</a></td>
	    		</tr>
	    		
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=20&menu=900&stage=1">Stage 1: Stored XSS</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=20&menu=900&stage=2">Stage 2: Block Stored XSS using Input Validation</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=20&menu=900&stage=3">Stage 3: Stored XSS Revisited</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=20&menu=900&stage=4">Stage 4: Block Stored XSS using Output Encoding</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=20&menu=900&stage=5">Stage 5: Reflected XSS</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=20&menu=900&stage=6">Stage 6: Block Reflected XSS</a>
						</td></tr>
				
			<tr>
	      		<td><a href="attack?Screen=70&menu=900">Stored XSS Attacks</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=31&menu=900">Reflected XSS Attacks</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=52&menu=900">Cross Site Request Forgery (CSRF)</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=45&menu=900">CSRF Prompt By-Pass</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=2&menu=900">CSRF Token By-Pass</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=8&menu=900">HTTPOnly Test</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=75&menu=900">Cross Site Tracing (XST) Attacks</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1000" class="pviimenudiv" style="position:absolute; left:200px; top:342px; width:150px; visibility: hidden; z-index:135">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=39&menu=1000">Fail Open Authentication Scheme</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1100" class="pviimenudiv" style="position:absolute; left:200px; top:372px; width:150px; visibility: hidden; z-index:136">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=11&menu=1100">Command Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=77&menu=1100">Numeric SQL Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=76&menu=1100">Log Spoofing</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=46&menu=1100">XPATH Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=36&menu=1100">String SQL Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=71&menu=1100">LAB: SQL Injection</a></td>
	    		</tr>
	    		
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=71&menu=1100&stage=1">Stage 1: String SQL Injection</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=71&menu=1100&stage=2">Stage 2: Parameterized Query #1</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=71&menu=1100&stage=3">Stage 3: Numeric SQL Injection</a>
						</td></tr>
				
			    		<tr><td class="pviimenudivstage"><a href="attack?Screen=71&menu=1100&stage=4">Stage 4: Parameterized Query #2</a>
						</td></tr>
				
			<tr>
	      		<td><img src="images/buttons/lessonComplete.jpg"><a href="attack?Screen=38&menu=1100">Modify Data with SQL Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><img src="images/buttons/lessonComplete.jpg"><a href="attack?Screen=6&menu=1100">Add Data with SQL Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><img src="images/buttons/lessonComplete.jpg"><a href="attack?Screen=12&menu=1100">Database Backdoors </a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=4&menu=1100">Blind Numeric SQL Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=13&menu=1100">Blind String SQL Injection</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1200" class="pviimenudiv" style="position:absolute; left:200px; top:402px; width:150px; visibility: hidden; z-index:137">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=63&menu=1200">Denial of Service from Multiple Logins</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1300" class="pviimenudiv" style="position:absolute; left:200px; top:432px; width:150px; visibility: hidden; z-index:138">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=67&menu=1300">Insecure Login</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1400" class="pviimenudiv" style="position:absolute; left:200px; top:462px; width:150px; visibility: hidden; z-index:139">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=37&menu=1400">Forced Browsing</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1500" class="pviimenudiv" style="position:absolute; left:200px; top:492px; width:150px; visibility: hidden; z-index:140">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=62&menu=1500">Encoding Basics</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1600" class="pviimenudiv" style="position:absolute; left:200px; top:522px; width:150px; visibility: hidden; z-index:141">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=18&menu=1600">Malicious File Execution</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1700" class="pviimenudiv" style="position:absolute; left:200px; top:552px; width:150px; visibility: hidden; z-index:142">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=51&menu=1700">Bypass HTML Field Restrictions</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=34&menu=1700">Exploit Hidden Fields</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=47&menu=1700">Exploit Unchecked Email</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=17&menu=1700">Bypass Client Side JavaScript Validation</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1800" class="pviimenudiv" style="position:absolute; left:200px; top:582px; width:150px; visibility: hidden; z-index:143">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=72&menu=1800">Hijack a Session</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=73&menu=1800">Spoof an Authentication Cookie</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=56&menu=1800">Session Fixation</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu1900" class="pviimenudiv" style="position:absolute; left:200px; top:612px; width:150px; visibility: hidden; z-index:144">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=19&menu=1900">Create a SOAP Request</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=23&menu=1900">WSDL Scanning</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=7&menu=1900">Web Service SAX Injection</a></td>
	    		</tr>
	    		
			<tr>
	      		<td><a href="attack?Screen=60&menu=1900">Web Service SQL Injection</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu2000" class="pviimenudiv" style="position:absolute; left:200px; top:642px; width:150px; visibility: hidden; z-index:145">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=25&menu=2000">Report Card</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>    
		<div id="submenu3000" class="pviimenudiv" style="position:absolute; left:200px; top:672px; width:150px; visibility: hidden; z-index:146">
	  		<table width="150" border="0" cellspacing="6" cellpadding="0"><tr>
	      		<td><a href="attack?Screen=9&menu=3000">The CHALLENGE!</a></td>
	    		</tr>
	    		
			
	  		</table>
		</div>
		<div id="top"></div>
		<div id="topLeft">
		<div align="left">
		
			Internationalization is not available for this lesson
		
		</div></div>
		<div align="right" id="topRight">
		<a href="attack?action=Logout" onmouseout="MM_swapImgRestore()"
			onmouseover="MM_swapImage('logout','','images/buttons/logoutOver.jpg',1)"><img
			src="images/buttons/logout.jpg" alt="LogOut" name="logout" width="45"
			height="22" border="0" id="logout" /></a> <a href="#getFAQ()"
			onmouseout="MM_swapImgRestore()"
			onmouseover="MM_swapImage('help','','images/buttons/helpOver.jpg',1)"><img
			src="images/buttons/help.jpg" alt="Help" name="help" width="22"
			height="22" border="0" id="help" /></a>
		</div>
<div id="lessonTitle" align="right">Add Data with SQL Injection</div>
			<div id="hMenuBar">
				
				<a href="attack?Screen=6&menu=1100&show=PreviousHint" target="_top" onclick="MM_nbGroup('down','group1','hintLeft','',1)" 
				onmouseover="MM_nbGroup('over','hintLeft','images/buttons/hintLeftOver.jpg','',1)" 
				onmouseout="MM_nbGroup('out')">
				<img src="images/buttons/hintLeft.jpg" alt="Previous Hint" name="hintLeft" width="20" height="20" border="0" id="hintLeft"/>
				</a>
				<a href="attack?Screen=6&menu=1100&show=NextHint" target="_top" onclick="MM_nbGroup('down','group1','hint','',1)" 
				onmouseover="MM_nbGroup('over','hint','images/buttons/hintOver.jpg','',1)" 
				onmouseout="MM_nbGroup('out')">
				<img src="images/buttons/hint.jpg" alt="Hints" name="hint" width="35" height="20" border="0" id="hint"/>
				</a>
				<a href="attack?Screen=6&menu=1100&show=NextHint" target="_top" onclick="MM_nbGroup('down','group1','hintRight','',1)" 
				onmouseover="MM_nbGroup('over','hintRight','images/buttons/hintRightOver.jpg','',1)" 
				onmouseout="MM_nbGroup('out')">
				<img src="images/buttons/hintRight.jpg" alt="Next Hint" name="hintRight" width="20" height="20" border="0" id="hintRight"/>
				</a>
				
				<a href="attack?Screen=6&menu=1100&show=Params" target="_top" onclick="MM_nbGroup('down','group1','params','',1)" 
				onmouseover="MM_nbGroup('over','params','images/buttons/paramsOver.jpg','',1)" 
				onmouseout="MM_nbGroup('out')">
				<img src="images/buttons/params.jpg" alt="Show Params" name="attack?Screen=6&menu=1100&show=Params" width="87" height="20" border="0" id="params"/>
				</a>
				<a href="attack?Screen=6&menu=1100&show=Cookies" target="_top" onclick="MM_nbGroup('down','group1','cookies','',1)" 
				onmouseover="MM_nbGroup('over','cookies','images/buttons/cookiesOver.jpg','',1)" 
				onmouseout="MM_nbGroup('out')">
				<img src="images/buttons/cookies.jpg" alt="Show Cookies" name="cookies" width="99" height="20" border="0" id="cookies"/>
				</a>
				<a href="javascript:toggle('lessonPlans')" target="_top" onclick="MM_nbGroup('down','group1','plans','',1)" 
				onmouseover="MM_nbGroup('over','plans','images/buttons/plansOver.jpg','',1)" 
				onmouseout="MM_nbGroup('out')">
				<img src="images/buttons/plans.jpg" alt="Lesson Plans" width="89" height="20" border="0" id="plans"/>
				</a>
				
				<a href="source" onclick="makeWindow(this.href+ '?source=true', 'Java Source');return false;" target="javaWin"
				onmouseover="MM_nbGroup('over','java','images/buttons/javaOver.jpg','',1)" 
				onmouseout="MM_nbGroup('out')">
				<img src="images/buttons/java.jpg" alt="Show Java" name="java" width="75" height="20" border="0" id="java"/>
				</a>
				<a href="source" onclick="makeWindow(this.href + '?solution=true', 'Java Solution');return false;" target="javaWin"
				onmouseover="MM_nbGroup('over','solutions','images/buttons/solutionsOver.jpg','',1)" 
				onmouseout="MM_nbGroup('out')">
				<img src="images/buttons/solutions.jpg" alt="Show Solution" name="solutions" width="73" height="20" border="0" id="solutions"/>
				</a>
				
								
			</div>
			<div id="twoCol">
	 	 	<div id="menuSpacer"></div>
	 	 	<div id="lessonAreaTop">
	 	 	
			    	<div id="training_wrap">
			    	<div id="training" class="info"><a href="http://yehg.net/lab/pr0js/training/webgoat.php" target="_blank">Solution Videos</a></div>
			    	<div id="reset" class="info"><a href="attack?Screen=6&menu=1100&Restart=6">Restart this Lesson</a></div>
			    	</div>
	    			
	 	 	</div>
	 	 	<div id="lessonArea">
	 	 	
				<div id="lessonPlans" style="visibility:hidden; height:1px; position:absolute; left:260px; top:130px; width:425px; z-index:105;">Could not find lesson plan for: SqlAddData and language English
				<br/>
				<br/>
				<a href="javascript:toggle('lessonPlans')" target="_top" onclick="MM_nbGroup('down','group1','plans','',1)">Close this Window</a>
				</div>
				<div id="lessonContent">
		    		
				The form below allows a user to view salaries associated with a userid (from the table named <b>salaries</b>).  This form is vulnerable to String SQL Injection.  In order to pass this lesson, use SQL Injection to add a record to the table.</div>
				<div id="message" class="info"></div>
	
			
			<div id="lessonContent"><form accept-charset='UNKNOWN' method='POST' name='form' action='attack?Screen=6&menu=1100' enctype=''><p>Enter your userid:<input name='userid' type='TEXT' value='jsmith'><input name='SUBMIT' type='SUBMIT' value='Go!'><table cellpadding='1' border='1'><tr><td><b>USERID</b></td><td><b>SALARY</b></td></tr><tr><td>jsmith</td><td>20000</td></tr></table></form></div>
			
				<div id="credits">
		  		<table align='RIGHT' cellspacing='0' width='90%' border='0' cellpadding='0'><tr><td valign='MIDDLE' width='100%' align='RIGHT'>Created by Chuck Willis&nbsp;</td><td valign='MIDDLE' align='RIGHT'><a href='http://www.mandiant.com'><img hspace='0' vspace='0' border='0' alt='MANDIANT' src='images/logos/mandiant.png'></a></td></tr></table>

		  		</div>
			</div>
	  	</div>

		<div id="bottom">
			<div align="center"><a href="http://www.owasp.org">OWASP Foundation</a> | 
								<a href="http://www.owasp.org/index.php/OWASP_WebGoat_Project">Project WebGoat</a> | 
								<a href="reportBug.jsp">Report Bug</a>
			</div>
	  	</div>
	</div>
</body>
</html>
]]></response> <comment></comment> </item> </items> |