[OWASP-WEBGOAT]Challenge #3 problem

Jeff Williams jeff.williams at aspectsecurity.com
Fri Dec 10 15:49:00 EST 2004


Maybe there's a way to know the installation directory?  You do have to know 
a little about Tomcat (aka CATALINA -- hint hint).

--Jeff

----- Original Message ----- 
From: "Cynick Young" <cynick.young at utoronto.ca>
To: <owasp-webgoat at lists.sourceforge.net>
Sent: Friday, December 10, 2004 2:48 PM
Subject: [OWASP-WEBGOAT]Challenge #3 problem


> There's a problem with challenge #3 on Windows 2000 in that starting the 
> shell cmd.exe from SSI, your current working directory is wherever you 
> started WebGoat from, ie. C:\webgoat and NOT the webapp context path. 
> Thus, <!--#exec cmd="echo defaced > %CD%/index_guest.html"--> will put the 
> file in C:\webgoat\index_guest.html and not where it needs to be.  Without 
> knowing the installation, one cannot complete the challenge properly.
>
>
> -------------------------------------------------------
> SF email is sponsored by - The IT Product Guide
> Read honest & candid reviews on hundreds of IT Products from real users.
> Discover which products truly live up to the hype. Start reading now. 
> http://productguide.itmanagersjournal.com/
> _______________________________________________
> OWASP-WEBGOAT mailing list
> OWASP-WEBGOAT at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/owasp-webgoat 





More information about the Owasp-webgoat mailing list