Penetration Testing mailing list archives

Re: HTTPS Web site testing


From: Pablo Sisca <psisca () cisiar org>
Date: Thu, 15 May 2003 15:33:38 -0300

Smith:

You can use Sleuth 1.36 (free) and a good one for Linux, that=
 acts
like a proxy (with ssl also) HTTPPUSH.
The links you can find them on the fyodor's site (nmap) 75 tools.=

(www.insecure.org)

Bye

P Sisca


On Thu, 15 May 2003 11:31:27 -0600, Robert Smith wrote:
I apologize if this is a simple question.
I am testing a HTTPS web site for a vulnerability and need to do a
"POST
/blah.html /etc...." command and get the results back.
I have tried using IE with Achilles, but IE prepends a GET before
the POST
which invalidates the result. Opera works the same.
Is there a way to do this through Achilles or another proxy or any
other
method so I can examine the web page output?


R Smith

---------------------------------------------------------------------
------
*** Wireless LAN Policies for Security & Management - NEW White
Paper ***
Just like wired networks, wireless LANs require network security
policies
that are enforced to protect WLANs from known vulnerabilities and
threats.
Learn to design, implement and enforce WLAN security policies to
lockdown enterprise WLANs.

To get your FREE white paper visit us at:
http://www.securityfocus.com/AirDefense-pen-test
---------------------------------------------------------------------
-------





---------------------------------------------------------------------------
*** Wireless LAN Policies for Security & Management - NEW White Paper ***
Just like wired networks, wireless LANs require network security policies
that are enforced to protect WLANs from known vulnerabilities and threats.
Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.

To get your FREE white paper visit us at:
http://www.securityfocus.com/AirDefense-pen-test
----------------------------------------------------------------------------


Current thread: