Using the WebScarab blur test

Source: Internet
Author: User
Tags decode all session id

Important: It is not discovered that the software can automatically generate test cases, but can only add their own written use cases. If you have this need please use other software or message sharing method, thank you.

1.1.1 WebScarab Tools Introduction

WebScarab is an agent software, the introduction is HTTP proxy, network crawling, network spider, you can use to view the post data. It provides includes HTTP proxy, network crawling, Web spider, Session ID analysis, automatic scripting interface, fuzzy Test tool, which can encode/decode all popular web formats, Web Service Description Language and SOAP parser etc.

1.1.2 Installation

1. Go to http://webscarab.updatestar.com/and select "Webscarab-installer-20070504-1631.jar" to download.

2. Double-click the file for WebScarab installation

3. Set the proxy mode for Chrome browser. On set-up and advanced settings--system-on-on system agent,

Choose Connect-LAN Settings

Configure the proxy server, set the address to "localhost" and the port to "8008" (this is the default port for this tool). if the project is running locally (for example, local tomcat), remember to uncheck "Do not use proxy server for this address", otherwise local requests cannot be crawled.

Click OK and the configuration is complete.

Note: If you want to access the Internet through your browser, Chrome will report a warning and no access. The workaround is to restore the above settings and access the Internet after saving.

1.1.3 Use

Run the project (my project is under test locally) and WebScarab software.

Note: What happens if the interface is as follows?

Solution:

Click menu Tools->use full-featured interface

Turn off the software and turn it back on. To switch back to the original mode, simply tick clear.

Fill out the form, click Submit, will pop up an edit window, there is information about the elements in the form.

Click "Accept changes" to leave the POST request. The tested software displays the results after the request.

Click Tools Software Summary.

Right-click the "Use as Fuzz template" for the POST request you just requested (you want to blur the test), and then tap the Fuzzer interface. Select the prepared file for the entry you want to test.

How do I choose a fuzzy data file?

Click Source

Click Browse

Select File, enter a description

Click Close to close the window and complete the test file additions.

Click Start to start the test and view the results to see that the requests are from "Fuzzer".

Double-click to view more information.

Using the WebScarab blur test

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.