Skip to content

jas20202/PasswordManagerSecurityDemo

Repository files navigation

PasswordManagerSecurityDemo

Demo of an insecure PW manager for Software Engeneering lecture e-Portfolio.

Topic for the e-Portfolio: OWASP ZAP

The aim of the e-portfolio was to familiarize myself with the OWASP ZAP tool and to introduce the software engineering course to the topic of web app security. To show how the OWASP ZAP tool works I created a little demo app containing vulnerabilies so that the ZAP Scan can find them. The presentation slides can be found in this repository as well.

Vulnerabilies:

  • SQL Injections
  • CORS missconfiguration
  • CSRF Token missconfiguration

And ZAP found some few more.

About

Demo of an insecure PW manager for SoftwareEng lecture

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published