|
|||||||||||
|
RE: HTTPS Web site testing
From: Dawes, Rogan (ZA - Johannesburg) <rdawes(at)deloitte.co.za>
Date: Fri May 16 2003 - 02:04:04 EDT
You can either modify an intercepted request, or generate one manually, by using the "manual request" tab. Simply type in the request using the full hostname and protocol, and press submit. Exodus will automatically calculate your content-length for you, just to simplify things a bit, and return the server's response. E.g.
POST https://vulnerable.site/path/app.asp HTTP/1.0
Header: value
var1=val1&var2=val2 You can get Exodus at http://mysite.mweb.co.za/residents/rdawes/exodus.html Rogan
-----Original Message-----
I apologize if this is a simple question. I am testing a HTTPS web site for a vulnerability and need to do a "POST /blah.html /etc...." command and get the results back. I have tried using IE with Achilles, but IE prepends a GET before the POST which invalidates the result. Opera works the same. Is there a way to do this through Achilles or another proxy or any other method so I can examine the web page output? R Smith
To get your FREE white paper visit us at: http://www.securityfocus.com/AirDefense-pen-test Important Notice: This email is subject to important restrictions, qualifications and disclaimers ("the Disclaimer") that must be accessed and read by clicking here or by copying and pasting the following address into your Internet browser's address bar: http://www.Deloitte.co.za/Disc.htm. The Disclaimer is deemed to form part of the content of this email in terms of Section 11 of the Electronic Communications and Transactions Act, 25 of 2002. If you cannot access the Disclaimer, please obtain a copy thereof from us by sending an email to ClientServiceCentre(at)Deloitte.co.za.
To get your FREE white paper visit us at: http://www.securityfocus.com/AirDefense-pen-test Received on Fri May 16 11:44:25 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:36 EDT |
||||||||||
|
|||||||||||