<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Webscarab Tutorial Part 1 (learning the basics)</title>
	<atom:link href="http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/feed/" rel="self" type="application/rss+xml" />
	<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/</link>
	<description></description>
	<lastBuildDate>Wed, 16 May 2012 13:17:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Divya</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-1171</link>
		<dc:creator>Divya</dc:creator>
		<pubDate>Thu, 05 Apr 2012 06:40:25 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-1171</guid>
		<description>Hi Tavis,

Sorry ..There is a small correction in the above post.

Error in paros is 407 Proxy Authorization required.

For URL http://localhost./webgoat/attack the browser is prompting for my corporate domain credentials. Though I provide correct credentials the broswser is displaying Proxy Authorization error.

My corporate is not allowing Webscrab so Im working on paros. Though this is a webscrab tutorial please help me on paros.

Thanks</description>
		<content:encoded><![CDATA[<p>Hi Tavis,</p>
<p>Sorry ..There is a small correction in the above post.</p>
<p>Error in paros is 407 Proxy Authorization required.</p>
<p>For URL <a href="http://localhost./webgoat/attack" rel="nofollow">http://localhost./webgoat/attack</a> the browser is prompting for my corporate domain credentials. Though I provide correct credentials the broswser is displaying Proxy Authorization error.</p>
<p>My corporate is not allowing Webscrab so Im working on paros. Though this is a webscrab tutorial please help me on paros.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Divya</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-1170</link>
		<dc:creator>Divya</dc:creator>
		<pubDate>Thu, 05 Apr 2012 06:00:47 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-1170</guid>
		<description>Hi Travis,
Problem with Webgoat on Paros.
Below are my settings:
Using IE7
Using Paros Proxy(not webscrab)
Working under corporate proxy.
Webgoat configured on 8080.(hope this is the default port)
Configured paros with corporate proxy with username and password
IE LAN settings configured as localhost 8080


Error in Paros:502 Connection Refused.

URL used: http://localhost/webgoat/attack/- If this URL is used the Webgoat page is displayed in browser but traffic not routed to paros

URL used: http://localhost./webgoat/attack/- If this URL is used the Webgoat page is not displayed in browser(browser showing 502 error) but traffic is routed to paros with HTTP response error 502 connection refused.


Pls help me on this.

Thanks Divya</description>
		<content:encoded><![CDATA[<p>Hi Travis,<br />
Problem with Webgoat on Paros.<br />
Below are my settings:<br />
Using IE7<br />
Using Paros Proxy(not webscrab)<br />
Working under corporate proxy.<br />
Webgoat configured on 8080.(hope this is the default port)<br />
Configured paros with corporate proxy with username and password<br />
IE LAN settings configured as localhost 8080</p>
<p>Error in Paros:502 Connection Refused.</p>
<p>URL used: <a href="http://localhost/webgoat/attack/-" rel="nofollow">http://localhost/webgoat/attack/-</a> If this URL is used the Webgoat page is displayed in browser but traffic not routed to paros</p>
<p>URL used: <a href="http://localhost./webgoat/attack/-" rel="nofollow">http://localhost./webgoat/attack/-</a> If this URL is used the Webgoat page is not displayed in browser(browser showing 502 error) but traffic is routed to paros with HTTP response error 502 connection refused.</p>
<p>Pls help me on this.</p>
<p>Thanks Divya</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: travis</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-1106</link>
		<dc:creator>travis</dc:creator>
		<pubDate>Thu, 01 Mar 2012 02:19:54 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-1106</guid>
		<description>Sorry for the late reply, did you try starting and stopping the proxy as in the first figure? Sounds like you&#039;ve got everything configured correctly to me.</description>
		<content:encoded><![CDATA[<p>Sorry for the late reply, did you try starting and stopping the proxy as in the first figure? Sounds like you&#8217;ve got everything configured correctly to me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ru</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-1101</link>
		<dc:creator>Ru</dc:creator>
		<pubDate>Mon, 27 Feb 2012 13:58:11 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-1101</guid>
		<description>A good and helpful post!
I&#039;m having the same issue, user &quot;problem&quot; asked earlier. FYI, i&#039;m running webgoat on   port 8080(by executing webgoat_8080.bat) and changed my browser, http proxy settings to IP:127.0.0.1 and Port:8008. Soon after changing proxy settings, i&#039;m unable to connect any of websites(either localhost or other outside hosts). I have already removed &#039;localhost&#039; from ignored hosts. The area where the issue i&#039;m having i guess is http proxy is not started. The error message popped when i refresh browser is &quot;Cannot connect to the proxy server&quot;. 
Please help me out in solving this issue..

Thanking you in advance..:-)</description>
		<content:encoded><![CDATA[<p>A good and helpful post!<br />
I&#8217;m having the same issue, user &#8220;problem&#8221; asked earlier. FYI, i&#8217;m running webgoat on   port 8080(by executing webgoat_8080.bat) and changed my browser, http proxy settings to IP:127.0.0.1 and Port:8008. Soon after changing proxy settings, i&#8217;m unable to connect any of websites(either localhost or other outside hosts). I have already removed &#8216;localhost&#8217; from ignored hosts. The area where the issue i&#8217;m having i guess is http proxy is not started. The error message popped when i refresh browser is &#8220;Cannot connect to the proxy server&#8221;.<br />
Please help me out in solving this issue..</p>
<p>Thanking you in advance..:-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Is there a program that automaticly finds .PHP files on a web server and tests them for SQL injections? - Admins Goodies</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-966</link>
		<dc:creator>Is there a program that automaticly finds .PHP files on a web server and tests them for SQL injections? - Admins Goodies</dc:creator>
		<pubDate>Thu, 11 Aug 2011 21:42:41 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-966</guid>
		<description>[...] WebScarab Howto: http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/ [...]</description>
		<content:encoded><![CDATA[<p>[...] WebScarab Howto: <a href="http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/" rel="nofollow">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: travis</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-931</link>
		<dc:creator>travis</dc:creator>
		<pubDate>Mon, 06 Jun 2011 17:01:54 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-931</guid>
		<description>Mo,

Glad you found your answer.  Also some browsers will automatically not allow proxies for localhost, so you may have to specifically check a box inside the browsers settings to allow for localhost. Thanks for adding you info and experience.</description>
		<content:encoded><![CDATA[<p>Mo,</p>
<p>Glad you found your answer.  Also some browsers will automatically not allow proxies for localhost, so you may have to specifically check a box inside the browsers settings to allow for localhost. Thanks for adding you info and experience.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mo</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-928</link>
		<dc:creator>Mo</dc:creator>
		<pubDate>Thu, 26 May 2011 15:10:08 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-928</guid>
		<description>Travis,

This is Mo again. I just found an answer to my problem (please feel free to add this to any FAQ&#039;s you build). If someone decides to build a test environment and has the webserver and the proxy run on the same box, make sure not to use the URL: http://localhost/mysite...

Using &quot;localhost&quot; means traffic is not routed the classic way (web browser to http server listening port) and therefore the webscarab user wont be able to intercept traffic. Best practice is to use the local box IP address instead.

URL: http://192.168.1.5/mysite...

This solution took me a while to find. I hope it can help a lost soul somewhere.</description>
		<content:encoded><![CDATA[<p>Travis,</p>
<p>This is Mo again. I just found an answer to my problem (please feel free to add this to any FAQ&#8217;s you build). If someone decides to build a test environment and has the webserver and the proxy run on the same box, make sure not to use the URL: <a href="http://localhost/mysite.." rel="nofollow">http://localhost/mysite..</a>.</p>
<p>Using &#8220;localhost&#8221; means traffic is not routed the classic way (web browser to http server listening port) and therefore the webscarab user wont be able to intercept traffic. Best practice is to use the local box IP address instead.</p>
<p>URL: <a href="http://192.168.1.5/mysite.." rel="nofollow">http://192.168.1.5/mysite..</a>.</p>
<p>This solution took me a while to find. I hope it can help a lost soul somewhere.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mo</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-927</link>
		<dc:creator>Mo</dc:creator>
		<pubDate>Thu, 26 May 2011 14:32:52 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-927</guid>
		<description>Hi Travis,

Great work! Thank you for all the help. I&#039;m trying to test an in-house web application with webscarab and I&#039;m running into issues (my experience is limited). I have the web application running on my local XP IIS and I can&#039;t figure out a way to intercept traffic.

I have followed all of your instructions above (I am using IE 8.0) and still having issues with locally installed web apps. Any help would be greatly appreciated.

Keep up the good work :)</description>
		<content:encoded><![CDATA[<p>Hi Travis,</p>
<p>Great work! Thank you for all the help. I&#8217;m trying to test an in-house web application with webscarab and I&#8217;m running into issues (my experience is limited). I have the web application running on my local XP IIS and I can&#8217;t figure out a way to intercept traffic.</p>
<p>I have followed all of your instructions above (I am using IE 8.0) and still having issues with locally installed web apps. Any help would be greatly appreciated.</p>
<p>Keep up the good work <img src='http://travisaltman.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: travis</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-893</link>
		<dc:creator>travis</dc:creator>
		<pubDate>Wed, 19 Jan 2011 12:51:52 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-893</guid>
		<description>Fabrizio,

I&#039;m not quite sure what your problem could be, sounds like you have everything setup correctly. Maybe try the same setup with Internet Explorer and see if you have the same issue. Also you might want to clear your history and cookies inside of firefox that gives it a fresh start. I&#039;ve sometimes gotten hangups on old history and cookies. Try that and let me know if that works.</description>
		<content:encoded><![CDATA[<p>Fabrizio,</p>
<p>I&#8217;m not quite sure what your problem could be, sounds like you have everything setup correctly. Maybe try the same setup with Internet Explorer and see if you have the same issue. Also you might want to clear your history and cookies inside of firefox that gives it a fresh start. I&#8217;ve sometimes gotten hangups on old history and cookies. Try that and let me know if that works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fabrizio</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/comment-page-1/#comment-892</link>
		<dc:creator>Fabrizio</dc:creator>
		<pubDate>Wed, 19 Jan 2011 11:39:57 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-1-learning-the-basics/#comment-892</guid>
		<description>Hi,
I am trying to solve WebGoat lessons using Webscarab. I&#039;m also using the browser 
Firefox. I set webscarab listen on port 8008. I&#039;ve configured firefox to connect on 
HTTP proxy on port 8008. The problem is that Webscarab is able to intercept the request, but my 
browser don&#039;t receive data. It remains  waiting for localhost response. Please tell me 
any solution.

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,<br />
I am trying to solve WebGoat lessons using Webscarab. I&#8217;m also using the browser<br />
Firefox. I set webscarab listen on port 8008. I&#8217;ve configured firefox to connect on<br />
HTTP proxy on port 8008. The problem is that Webscarab is able to intercept the request, but my<br />
browser don&#8217;t receive data. It remains  waiting for localhost response. Please tell me<br />
any solution.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
</channel>
</rss>

