<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to 63: Better remote access</title><link>https://sourceforge.net/p/websecuritydojo/feature-requests/63/</link><description>Recent changes to 63: Better remote access</description><atom:link href="https://sourceforge.net/p/websecuritydojo/feature-requests/63/feed.rss" rel="self"/><language>en</language><lastBuildDate>Tue, 22 May 2018 12:20:13 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/websecuritydojo/feature-requests/63/feed.rss" rel="self" type="application/rss+xml"/><item><title>Better remote access</title><link>https://sourceforge.net/p/websecuritydojo/feature-requests/63/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Currently enabling remote access has some problems.&lt;br/&gt;
Reasons for adding remote access:&lt;br/&gt;
&lt;em&gt; Use 3rd party tools against these targets (tools not installed inside the Dojo already)&lt;br/&gt;
&lt;/em&gt; Allow multiple students to use the same instance of score tracking targets, such as WebGoat&lt;/p&gt;
&lt;p&gt;Problems:&lt;br/&gt;
* need to comment out the “limit access to local area network” directives in /var/www/.htaccess (specal thanks to Etienne for discovering this issue.&lt;/p&gt;
&lt;p&gt;Solution:&lt;br/&gt;
&lt;em&gt; include README-remote-access.txt with instructions on how to enable remote access&lt;br/&gt;
&lt;/em&gt; consider script that would lower any intentional defenses that were intended for traditional Dojo use (e.g. hands-on conference where you do NOT want students accessing someone else's Dojo instance).&lt;br/&gt;
* fix misconfigurations that are making this hard, and that serve no defensive purpose&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Rhoades</dc:creator><pubDate>Tue, 22 May 2018 12:20:13 -0000</pubDate><guid>https://sourceforge.net3e4210249d908af484f5ca0eab71efcc782609f2</guid></item></channel></rss>