- Ensure the owaspbwa VM is running. Select the OWASP WebGoat application from the initial landing page of the VM. The landing page will be configured to an IP address specific to your machine.
- After you click the OWASP WebGoat link, you will be prompted for login credentials. Use these credentials: User Name: guest; password: guest.
- After authentication, click the Start WebGoat button to access the application exercises.
- Click AJAX Security | Insecure Client Storage from the left-hand menu. You are presented with a shopping cart:
- Switch to Burp's Proxy | HTTP history tab, Click the Filter button, and ensure your Filter by ...