Step 1 – prepare WebGoat environment

To better demonstrate the scanning results of the OWASP dependency check, we will use the WebGoat project instead of NodeGoat. The WebGoat project can be downloaded from Git. WebGoat is a purpose-built vulnerable web project used to practice security testing:

$ git    clone

We will also use the latest version of OWASP dependency-check, which can be downloaded here:

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.