<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Webscarab Tutorial Part 3 (fuzzing)</title>
	<atom:link href="http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/feed/" rel="self" type="application/rss+xml" />
	<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 10:51:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: MAFRI</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-993</link>
		<dc:creator>MAFRI</dc:creator>
		<pubDate>Wed, 05 Oct 2011 22:22:42 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-993</guid>
		<description>&lt;strong&gt;mafri...&lt;/strong&gt;

[...]&#187; Blog Archive &#187; Webscarab Tutorial Part 3 (fuzzing)[...]...</description>
		<content:encoded><![CDATA[<p><strong>mafri&#8230;</strong></p>
<p>[...]&raquo; Blog Archive &raquo; Webscarab Tutorial Part 3 (fuzzing)[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KiranKumar Pedda</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-745</link>
		<dc:creator>KiranKumar Pedda</dc:creator>
		<pubDate>Fri, 04 Dec 2009 03:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-745</guid>
		<description>This site rocks...</description>
		<content:encoded><![CDATA[<p>This site rocks&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mohamed</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-715</link>
		<dc:creator>Mohamed</dc:creator>
		<pubDate>Tue, 20 Oct 2009 10:57:17 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-715</guid>
		<description>Thank you Travis</description>
		<content:encoded><![CDATA[<p>Thank you Travis</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: travis</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-714</link>
		<dc:creator>travis</dc:creator>
		<pubDate>Mon, 19 Oct 2009 11:07:38 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-714</guid>
		<description>mohamed,

not all web applications use the &quot;location&quot; field in their headers.  it just so happens the example i used does.  when looking to see if the sql injection was successful it&#039;s better to look in the body of the response (aka the very bottom pane in webscarab).  if you see any errors or something that looks out of place then you may be able to perform sql injection.  it&#039;s not an exact science but be on the look out for a response that is abnormal.  does that answer your question?</description>
		<content:encoded><![CDATA[<p>mohamed,</p>
<p>not all web applications use the &#8220;location&#8221; field in their headers.  it just so happens the example i used does.  when looking to see if the sql injection was successful it&#8217;s better to look in the body of the response (aka the very bottom pane in webscarab).  if you see any errors or something that looks out of place then you may be able to perform sql injection.  it&#8217;s not an exact science but be on the look out for a response that is abnormal.  does that answer your question?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mohamed</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-713</link>
		<dc:creator>Mohamed</dc:creator>
		<pubDate>Mon, 19 Oct 2009 09:39:51 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-713</guid>
		<description>I added sql dictionary  and started scanning then I went to conversations to check if the expression will take me to another page, I didn&#039;t found &quot;Location&quot; :(</description>
		<content:encoded><![CDATA[<p>I added sql dictionary  and started scanning then I went to conversations to check if the expression will take me to another page, I didn&#8217;t found &#8220;Location&#8221; <img src='http://travisaltman.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: travis</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-712</link>
		<dc:creator>travis</dc:creator>
		<pubDate>Mon, 19 Oct 2009 08:27:34 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-712</guid>
		<description>mohamed,

are you saying there&#039;s no &quot;location&quot; in the header of the response?</description>
		<content:encoded><![CDATA[<p>mohamed,</p>
<p>are you saying there&#8217;s no &#8220;location&#8221; in the header of the response?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mohamed</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-709</link>
		<dc:creator>Mohamed</dc:creator>
		<pubDate>Sun, 18 Oct 2009 15:24:59 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-709</guid>
		<description>Hi Travis
I work on OWASP livecd Austin terrier Feb2009. When I tried webscarab as a sql scanner I didn&#039;t found the entry of Location 
please replay ASAP 
thanks in advance</description>
		<content:encoded><![CDATA[<p>Hi Travis<br />
I work on OWASP livecd Austin terrier Feb2009. When I tried webscarab as a sql scanner I didn&#8217;t found the entry of Location<br />
please replay ASAP<br />
thanks in advance</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harjeet</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-655</link>
		<dc:creator>Harjeet</dc:creator>
		<pubDate>Tue, 09 Jun 2009 14:37:01 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-655</guid>
		<description>Hi Travis

I am not getting any pop up window on security certificate for my application. Even though I clicked Intercept botton ON/OFF.Can you pls tell me wat to do?

Thanks
Harjeet</description>
		<content:encoded><![CDATA[<p>Hi Travis</p>
<p>I am not getting any pop up window on security certificate for my application. Even though I clicked Intercept botton ON/OFF.Can you pls tell me wat to do?</p>
<p>Thanks<br />
Harjeet</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: travis</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-654</link>
		<dc:creator>travis</dc:creator>
		<pubDate>Tue, 09 Jun 2009 13:22:06 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-654</guid>
		<description>harjeet,

that&#039;s somewhat of a general error but the first error is complaining about ssl, have you accepted the certificate so that webscarab can man in the middle the ssl traffic?  you should click yes / accept to this certificate.  below is a screen shot link to accepting a certificate.

http://www.dental.ufl.edu/IT/images/netstorage_accept_cert.jpg</description>
		<content:encoded><![CDATA[<p>harjeet,</p>
<p>that&#8217;s somewhat of a general error but the first error is complaining about ssl, have you accepted the certificate so that webscarab can man in the middle the ssl traffic?  you should click yes / accept to this certificate.  below is a screen shot link to accepting a certificate.</p>
<p><a href="http://www.dental.ufl.edu/IT/images/netstorage_accept_cert.jpg" rel="nofollow">http://www.dental.ufl.edu/IT/images/netstorage_accept_cert.jpg</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harjeet</title>
		<link>http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/comment-page-1/#comment-653</link>
		<dc:creator>Harjeet</dc:creator>
		<pubDate>Tue, 09 Jun 2009 09:03:55 +0000</pubDate>
		<guid isPermaLink="false">http://travisaltman.com/webscarab-tutorial-part-3-fuzzing/#comment-653</guid>
		<description>Hi Travis,

I was Testing an application through Webscarab in remote login which was deployed in &quot;http://training:8080/xyz/&quot; but unable to test.

On running the Web scarab i got following errors:

WebScarab encountered an error trying to retrieve 

GET https://training:8080/daytrader/ HTTP/1.0
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/xaml xml, application/vnd.ms-xpsdocument, application/x-ms-xbap, application/x-ms-application, application/x-shockwave-flash, */*
Accept-Language: en-us
UA-CPU: x86
Connection: Keep-Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Host: training:8080


The error was : 


Unrecognized SSL message, plaintext connection?
	at com.sun.net.ssl.internal.ssl.InputRecord.handleUnknownRecord(Unknown Source)
	at com.sun.net.ssl.internal.ssl.InputRecord.read(Unknown Source)
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(Unknown Source)
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(Unknown Source)
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.writeRecord(Unknown Source)
	at com.sun.net.ssl.internal.ssl.AppOutputStream.write(Unknown Source)
	at java.io.BufferedOutputStream.flushBuffer(Unknown Source)
	at java.io.BufferedOutputStream.flush(Unknown Source)
	at org.owasp.webscarab.model.Request.writeDirect(Request.java:233)
	at org.owasp.webscarab.model.Request.writeDirect(Request.java:214)
	at org.owasp.webscarab.httpclient.URLFetcher.fetchResponse(URLFetcher.java:241)
	at org.owasp.webscarab.plugin.proxy.CookieTracker$Plugin.fetchResponse(CookieTracker.java:130)
	at org.owasp.webscarab.plugin.proxy.BrowserCache$Plugin.fetchResponse(BrowserCache.java:101)
	at org.owasp.webscarab.plugin.proxy.RevealHidden$Plugin.fetchResponse(RevealHidden.java:100)
	at org.owasp.webscarab.plugin.proxy.BeanShell$Plugin.fetchResponse(BeanShell.java:229)
	at org.owasp.webscarab.plugin.proxy.ManualEdit$Plugin.fetchResponse(ManualEdit.java:243)
	at org.owasp.webscarab.plugin.proxy.ConnectionHandler.run(ConnectionHandler.java:223)
	at java.lang.Thread.run(Unknown Source)

Could you pls help me to solve my problem or any other site where i can post my problem.

Thanks

Harjeet</description>
		<content:encoded><![CDATA[<p>Hi Travis,</p>
<p>I was Testing an application through Webscarab in remote login which was deployed in &#8220;http://training:8080/xyz/&#8221; but unable to test.</p>
<p>On running the Web scarab i got following errors:</p>
<p>WebScarab encountered an error trying to retrieve </p>
<p>GET <a href="https://training:8080/daytrader/" rel="nofollow">https://training:8080/daytrader/</a> HTTP/1.0<br />
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/xaml xml, application/vnd.ms-xpsdocument, application/x-ms-xbap, application/x-ms-application, application/x-shockwave-flash, */*<br />
Accept-Language: en-us<br />
UA-CPU: x86<br />
Connection: Keep-Alive<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)<br />
Host: training:8080</p>
<p>The error was : </p>
<p>Unrecognized SSL message, plaintext connection?<br />
	at com.sun.net.ssl.internal.ssl.InputRecord.handleUnknownRecord(Unknown Source)<br />
	at com.sun.net.ssl.internal.ssl.InputRecord.read(Unknown Source)<br />
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(Unknown Source)<br />
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(Unknown Source)<br />
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.writeRecord(Unknown Source)<br />
	at com.sun.net.ssl.internal.ssl.AppOutputStream.write(Unknown Source)<br />
	at java.io.BufferedOutputStream.flushBuffer(Unknown Source)<br />
	at java.io.BufferedOutputStream.flush(Unknown Source)<br />
	at org.owasp.webscarab.model.Request.writeDirect(Request.java:233)<br />
	at org.owasp.webscarab.model.Request.writeDirect(Request.java:214)<br />
	at org.owasp.webscarab.httpclient.URLFetcher.fetchResponse(URLFetcher.java:241)<br />
	at org.owasp.webscarab.plugin.proxy.CookieTracker$Plugin.fetchResponse(CookieTracker.java:130)<br />
	at org.owasp.webscarab.plugin.proxy.BrowserCache$Plugin.fetchResponse(BrowserCache.java:101)<br />
	at org.owasp.webscarab.plugin.proxy.RevealHidden$Plugin.fetchResponse(RevealHidden.java:100)<br />
	at org.owasp.webscarab.plugin.proxy.BeanShell$Plugin.fetchResponse(BeanShell.java:229)<br />
	at org.owasp.webscarab.plugin.proxy.ManualEdit$Plugin.fetchResponse(ManualEdit.java:243)<br />
	at org.owasp.webscarab.plugin.proxy.ConnectionHandler.run(ConnectionHandler.java:223)<br />
	at java.lang.Thread.run(Unknown Source)</p>
<p>Could you pls help me to solve my problem or any other site where i can post my problem.</p>
<p>Thanks</p>
<p>Harjeet</p>
]]></content:encoded>
	</item>
</channel>
</rss>

