[Owasp-webgoat] VMWare Image of Webgoat

jfvanmeter at comcast.net jfvanmeter at comcast.net
Thu Oct 23 08:14:17 EDT 2008


I have a isolated virtual network/domain that I use to try new things in and to test. The risk is if the host computer got access to the Internet, maybe the nic could be set to Host Only to help reduce some of the risk.

//John

--
"When the legend becomes fact, print the legend." 
!

 -------------- Original message ----------------------
From: "Bruce Mayhew" <Bruce.Mayhew at OunceLabs.com>
> I think this is a interesting idea.  One of the ant build tags creates a
> "classroom" environment.  The image would be quite large, but I'd be
> willing to put it on sourceforge (if it would allow it) if people think
> it is a good idea.  The question I have is: Would you download a VM that
> you didn't create and run it on your machine?  
> 
> Anyone have any thoughts on this?  I'm not that familiar with potential
> risks of running an "untrusted" VM.
> 
> Bruce
> 
> -----Original Message-----
> From: Brad Andrews [mailto:andrews at rbacomm.com] 
> Sent: Wednesday, October 22, 2008 10:36 AM
> To: webgoat at owasp.org
> Subject: VMWare Image of Webgoat
> 
> 
> Has anyone thought of creating a VMWare Player image of Webgoat (on  
> some kind of Linux) to allow people to be able to run Webgoat without  
> exposing themselves to external attack?  Networking could be setup to  
> not connect to the host machine.
> 
> I thought of this the other day and it would be worth doing, though I  
> am not very knowledgeable on configuring Linux VMWare images,  
> unfortunately.
> 
> Brad
> _______________________________________________
> Owasp-webgoat mailing list
> Owasp-webgoat at lists.owasp.org
> https://lists.owasp.org/mailman/listinfo/owasp-webgoat



More information about the Owasp-webgoat mailing list