Figure 4-2: IEWatch performing HTTP and HTML analysis from within the browser
HACK STEPS
■
Configure your browser to use either Burp or WebScarab as a local proxy
(see Chapter 19 for specific details about how to do this if you are unsure).
■
Browse the entire application normally, attempting to visit every single
link/URL you discover, submitting every single form, and proceeding
through all multistep functions to completion. Try browsing with
JavaScript enabled and disabled, and with cookies enabled and disabled.
Many applications can handle various browser configurations, and you
Do'stlaringiz bilan baham: