<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8503755746105415394.post3413211736867047080..comments</id><updated>2011-03-16T12:10:52.225Z</updated><category term='beer'/><category term='scanners'/><category term='law'/><category term='authentication'/><category term='burp'/><category term='sockets'/><category term='books'/><category term='ajax'/><category term='hacktools'/><category term='input'/><category term='memory'/><category term='burp intruder'/><category term='MoBP'/><category term='sql injection'/><category term='ASP.NET'/><category term='black hat'/><category term='PortSwigging'/><category term='firefox'/><category term='V13P'/><category term='encryption'/><category term='session tokens'/><category term='ldap'/><category term='null bytes'/><category term='2.0'/><category term='browser security'/><category term='xpath'/><category term='burp extender'/><category term='pen testing'/><category term='windows'/><category term='deflate'/><category term='dns pinning'/><category term='xss'/><category term='viewstate'/><category term='xsrf'/><category term='thick clients'/><category term='automation'/><category term='nonsense'/><category term='training'/><category term='blogs'/><category term='snake oil'/><title type='text'>Comments on PortSwigger Web Security Blog: Intercepting thick client communications</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.portswigger.net/feeds/3413211736867047080/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html'/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-7937209585152229745</id><published>2011-03-16T12:10:52.225Z</published><updated>2011-03-16T12:10:52.225Z</updated><title type='text'>Hi.

I have a question which isn&amp;#39;t actually re...</title><summary type='text'>Hi.&lt;br /&gt;&lt;br /&gt;I have a question which isn&amp;#39;t actually related to this post but that I thought it could be. &lt;br /&gt;&lt;br /&gt;My thick client authentifies to the server with a USB stored certificate (as in a smart card reader) which isn&amp;#39;t, afak, usable (forwarded as is) by BURP. And then, the servers starts a HTTPS session authenticated with real CA certificate, which is replaced by BURP and </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/7937209585152229745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/7937209585152229745'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html?showComment=1300277452225#c7937209585152229745' title=''/><author><name>Vince</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html' ref='tag:blogger.com,1999:blog-8503755746105415394.post-3413211736867047080' source='http://www.blogger.com/feeds/8503755746105415394/posts/default/3413211736867047080' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1368486939'/></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-4308936873101572747</id><published>2010-03-23T14:10:00.382Z</published><updated>2010-03-23T14:10:00.382Z</updated><title type='text'>Really Triggering..

We ill enter 127.0.0.1 in lan...</title><summary type='text'>Really Triggering..&lt;br /&gt;&lt;br /&gt;We ill enter 127.0.0.1 in lan settings. Imagine already a Browser is connected via proxy server(192.168.5.3).. Replacing loopback ip address(127.0.0.1) in already assigned ip address(192.168.5.3 causing no internet connectivity.. Plss Help.. Thanks in Advance...</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/4308936873101572747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/4308936873101572747'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html?showComment=1269353400382#c4308936873101572747' title=''/><author><name>Jabes</name><uri>http://www.blogger.com/profile/06951086666097566978</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html' ref='tag:blogger.com,1999:blog-8503755746105415394.post-3413211736867047080' source='http://www.blogger.com/feeds/8503755746105415394/posts/default/3413211736867047080' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1854695600'/></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-6542892277912832713</id><published>2009-04-20T20:21:00.000Z</published><updated>2009-04-20T20:21:00.000Z</updated><title type='text'>I've used a commercial product called ProxyCap to ...</title><summary type='text'>I've used a commercial product called ProxyCap to create rules to redirect proxy-unaware apps.  You can have a rule for each individual application and/or a default catch-all rule, and each rule can forward to a different local or remote proxy.  You can even redirect Burp itself (javaw.exe) through a proxy such as TOR.  I've heard FreeCap is a similar product, but I haven't used it myself.&lt;br /&gt;&lt;</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/6542892277912832713'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/6542892277912832713'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html?showComment=1240258860000#c6542892277912832713' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html' ref='tag:blogger.com,1999:blog-8503755746105415394.post-3413211736867047080' source='http://www.blogger.com/feeds/8503755746105415394/posts/default/3413211736867047080' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1539978693'/></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-5809714499843639163</id><published>2009-04-19T09:21:00.000Z</published><updated>2009-04-19T09:21:00.000Z</updated><title type='text'>@S. Hamid Kashfi

Re contact point, there is an em...</title><summary type='text'>@S. Hamid Kashfi&lt;br /&gt;&lt;br /&gt;Re contact point, there is an email link at the bottom of every page on my site.&lt;br /&gt;&lt;br /&gt;Why don't you email me an example of a match/replace rule that isn't working for, and I'll look into it? Thanks.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/5809714499843639163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/5809714499843639163'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html?showComment=1240132860000#c5809714499843639163' title=''/><author><name>PortSwigger</name><uri>http://www.blogger.com/profile/04744809054520271899</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html' ref='tag:blogger.com,1999:blog-8503755746105415394.post-3413211736867047080' source='http://www.blogger.com/feeds/8503755746105415394/posts/default/3413211736867047080' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1025034285'/></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-6869883951211890653</id><published>2009-04-17T17:48:00.000Z</published><updated>2009-04-17T17:48:00.000Z</updated><title type='text'>Hi ,

Not actually related to this post ,but since...</title><summary type='text'>Hi ,&lt;br /&gt;&lt;br /&gt;Not actually related to this post ,but since I had no other contact point  I`m using here :&lt;br /&gt;&lt;br /&gt;&amp;quot;match &amp;amp; replace&amp;quot; option in proxy section of Burp suite 1.2 seems broken ! &lt;br /&gt;I&amp;#39;ve no problem using this feature in 1.1 but it seems not working in 1.2 . Maybe something has changed in 1.2 that make it not working the way I use it on 1.2 ?&lt;br /&gt;&lt;br /&gt;thanks </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/6869883951211890653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/6869883951211890653'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html?showComment=1239990480000#c6869883951211890653' title=''/><author><name>S. Hamid Kashfi</name><uri>http://www.blogger.com/profile/08049067812791150826</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_xfgY61-qtLI/Sc61DXBu91I/AAAAAAAAAZQ/eyyBWn8ClP4/S220/DSC04665.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html' ref='tag:blogger.com,1999:blog-8503755746105415394.post-3413211736867047080' source='http://www.blogger.com/feeds/8503755746105415394/posts/default/3413211736867047080' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-394395694'/></entry><entry><id>tag:blogger.com,1999:blog-8503755746105415394.post-8359704525747737931</id><published>2009-04-10T21:38:00.000Z</published><updated>2009-04-10T21:38:00.000Z</updated><title type='text'>very helpful. thank you.</title><summary type='text'>very helpful. thank you.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/8359704525747737931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8503755746105415394/3413211736867047080/comments/default/8359704525747737931'/><link rel='alternate' type='text/html' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html?showComment=1239399480000#c8359704525747737931' title=''/><author><name>emotional-stuntman</name><uri>http://www.blogger.com/profile/11756816848235984626</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.portswigger.net/2009/04/intercepting-thick-client.html' ref='tag:blogger.com,1999:blog-8503755746105415394.post-3413211736867047080' source='http://www.blogger.com/feeds/8503755746105415394/posts/default/3413211736867047080' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-366314705'/></entry></feed>
