28 Aug 2012 @ 8:09 PM 

For better viewing try http://www.testalways.com/extra/2012-08-28_2148.swf

I have here an example how I can use Fiddler to replay a submission on a web form. I isolate the exact HTTP request and I execute it again.

The server in this case is responding positively and it’s sending an email each time.

Replaying HTTP requests can be useful not only to receive a confirmation email back, but has other various utilities.

You can repeat (if there isn’t a protection blocking mechanism of course):

-creating a post on a forum

-creating a new thread

-sending reset password emails

etc…

Fiddler can be used to decrypt locally the HTTPS traffic, but for many types of spamming.

I use it successfully in some cases for Load Testing and when I overloaded the server I got error pages with sensitive information, so I found security issues in this way.

ShareThis
Posted By: Eusebiu Blindu
Last Edit: 28 Aug 2012 @ 08:09 PM

EmailPermalink
Tags
Categories: Tools


 

Responses to this post » (None)

 
Post a Comment

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


 Last 50 Posts
 Back
  • Users » 2
  • Posts/Pages » 136
  • Comments » 148
Change Theme...
  • VoidVoid
  • LifeLife
  • EarthEarth
  • WindWind
  • WaterWater
  • FireFire
  • LightLight « Default

bug bounty

  • No categories

Bugs

  • No categories

Carnivals

  • No categories

challenge

  • No categories

Classic Tests

  • No categories

conferences

  • No categories

EWT

  • No categories