I am looking for a very insecure ASP.NET application. Ideally i’m looking for an application that was written by a noob who has made a lot of security mistakes. If the app has a MS-SQL back-end that would be a bonus. I know of two cool projects for PHP and J2EE which fill my needs. Do you know anything like this for ASP.NET?
Share
Hacme Bank is a pretty good example from Foundstone of what not to do. It’s an older example, written in .NET 1.1 against SQL 2000, but covers most of the common vulnerabilities found in web applications.