Using the Mutillidae login page with level 1 security, we look at two methods to bypass javascript validation. One method is disabling JavaScript but this has consequences for pages which use JavaScript to help render the page correctly. After viewing these limitations, we use Burp-Suite to allow the page to render normally whhile still having control of the HTTP requests and responses. Mutillidae is a free web application which is vulnerable on purpose to give a training envoronment for pen testers, security enthusiasts, universities, and as a target for evaluating vulnerability assessment tools. Updates about Mutillidae are announced on Twitter at @webpwnized. Mutillidae can be downloaded from irongeek.com.
Link to this comment:
All Comments (0)