A demonstration of a typical vulnerability scanner against a modern and not so
modern web app to demonstrate discovery of issues. We will use burp scanner for
scanning, issues that it can discover, how to fix those. We will also briefly
look at open source alternatives to Burp
Please note the example apps here are not to be taken as good examples of code
as they *intentionally* contain security issues to demonstrate the scanner and
even the "fixed" versions are not actually fixed (for example the password is
not hashed/salted/encrypted in the database)