I've just installed WebGoat and I'm going through it. This looks great, something like HackThisSite, but it runs on your own machine. I can't believe I missed this on OWASP before.


SQL Injection

I've been playing with SQL injection lately, and it's pretty fun. Especially getting to know all the database systems, their quirks and their particular syntaxes that allow things like LIMIT or EXEC. I'm thinking of doing another programming challenge based on SQL injection and other web application vulnerabilities. I'm interested to see what other people can come up with.


New Theme Deployed

I've deployed a new theme and pushed it out as the default. Anyone who manually changed their theme can change it to Midnight Glow by using the drop-down box at the bottom on the page. If you notice any problems with the theme, send me a PM.