PaulDotCom mailing list archives

Need a name for a project (teaching app for web security)


From: jd.mubix at gmail.com (Rob Fuller)
Date: Wed, 25 Feb 2009 20:39:28 -0500

http://en.wikipedia.org/wiki/Mutillidae


2009/2/25 Adrian Crenshaw <irongeek at irongeek.com>:
Awhile back I wrote an article on deliberately insecure web applications
http://www.irongeek.com/i.php?page=security/deliberately-insecure-web-applications-for-learning-web-app-security

Now I want to write my own for a class I plan to teach, and release it
online. I plan to do it all in PHP and make it easy to use with Xampp.

For the sake if teaching core concepts, I plan to implement the OWASP Top 10
vulnerabilities . Here are the core goals:

1. Make the code and examples simple to understand to get the point across.
With some of the stuff in Webgoat it is s a little hard to figure out what
they want. My app won't be very realistic, but it should illustrate the
concepts.
2. Be geared in such a way that it's easy to update.
3. Easy to install and run (I plan to distribute it with XAMMP).
4. When folks find bugs in my crappy code, I can legitimately say it's a
feature.


I'm leaning towards the name: CowKiller: Oh, What A Shitty Program

A CowKiller is a type of WASP, and the 2nd part is a double acronym. Any
better ideas for naming it?

Adrian

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com



Current thread: