WebGoat

1.Broken Access Control: Hijack a session

post-thumbnail

2.Broken Access Control: Insecure Direct Object Reference

post-thumbnail

3.Broken Access Control: Missing Function Level Access Control

post-thumbnail

4.Broken Access Control: Spoofing an Authentication Cookie

post-thumbnail

5.Cryptographic Failures: Crypto Basics

post-thumbnail