Penetration Testing mailing list archives

RE: WebScarab .NET SSL Error


From: "Maxime Ducharme" <mducharme () cybergeneration com>
Date: Tue, 3 Jun 2008 11:31:13 -0400



Hi Danux

I suggest that you try this Firefox extension :

- TamperData : http://tamperdata.mozdev.org/

Another interesting I didn’t tried yet : 
https://addons.mozilla.org/en-US/firefox/addon/2691

HTH

Maxime



-----Message d'origine-----
De : listbounce () securityfocus com [mailto:listbounce () securityfocus com] De
la part de Danux
Envoyé : 30 mai 2008 05:37
À : pen-test () securityfocus com
Objet : WebScarab .NET SSL Error

Hi Friends,

I  am testing a .NET-SSL enabled web application, and i discovered a
possible SQL Injection, then because of lack of space in the input
field of the form, i start trying to use a Proxy like WebScarab or
Acunetix, but after submit the request through this proxies the
application stops responding  and i am not able to inject any code.
I think could be because of .NET certificate trust validation, if so?
Do you know how to bypass this issue?

Have you ever been able to test an https .NET application through a Proxy?

Thanks in Advanced.

-- 
Danux

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes 
in Securing Web Applications  
Find out now! Get Webinar Recording and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------




------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes
in Securing Web Applications
Find out now! Get Webinar Recording and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------


Current thread: