WebApp Sec mailing list archives

Re: New tool HTTP Traceroute


From: Robin Wood <robin () digininja org>
Date: Wed, 12 Nov 2014 09:16:53 +0000

On 12 November 2014 06:32, oxdef <oxdef () oxdef info> wrote:
Robin, what is the difference between your tool and curl -v/i?

I'd like to think slightly nicer output, checking for invalid SSL/TLS
certs, dumping cert info (will get better when I get time), checking
for long bodies on redirects. Being scripted you can easily modify it
to add in your own features.

The idea started as an add on to EyeWitness and I mostly developed it
for my own interest and practice with the net/http gem, as I say in
the write up, it is a bit over kill for what it does.

Robin

--
oxdef


-------- Исходное сообщение --------
От: Robin Wood <robin () digininja org>
Дата:03.11.2014 11:34 (GMT+03:00)
Кому: webappsec () securityfocus com
Копия:
Тема: New tool HTTP Traceroute

I've just released a new tool, HTTP Traceroute. This tool takes a URL
and follows any redirects from it till it reaches the end of the line.
At each stage it it shows all headers, cookies, warns about long
bodies and bad SSL certificates.

Hopefully it will be useful when you get large redirect chains where
you need to gather information from every step along the way. Cookies
collected can be saved to a file, modified then replayed on a second
run through.

You can get it from here:

http://digi.ninja/projects/http_traceroute.php

Any problems or questions let me know.

Robin



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now!
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------




This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now!
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------


Current thread: