Penetration Testing mailing list archives
Re: java app question
From: Jan Muenther <jan.muenther () nruns com>
Date: Mon, 26 Apr 2010 20:48:49 +0200
Hello,
i am looking to pen test an app which is not a webapp :) . on browsing to the url it launches a java application using jnlp. i used a network traffic sniffer to see the traffic, and it is making post requests to several different urls (e.g. webapp.com/generatereport etc.), and the response is of type x-serialize object. any suggestions on what could be things to look at for such a pentest?
Manish Saindane gave a presentation on intercepting Java serialized object communication at BH Europe: http://www.blackhat.com/html/bh-eu-10/bh-eu-10-archives.html#Saindane Maybe that helps you. Apart from that, I'd advise you to try and decompile the Java binaries with e.g. jad and look at it. Cheers, Jan ------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------
Current thread:
- java app question learn lids (Apr 26)
- Re: java app question Rogan Dawes (Apr 26)
- Re: java app question ¨˜”°º•C0D3w (Apr 27)
- Re: java app question Jan Muenther (Apr 27)
- RE: java app question Paul Melson (Apr 27)
- Re: java app question Jonathan Cran (Apr 29)
- Re: java app question Rogan Dawes (Apr 26)