Above (《Web Application Security Series: install and configure WVS (1)") We talked about how to configure a proxy server and how to configure HTTP proxy settings and SOCKS proxy settings. To sniff HTTP Communication, you must configure the web browser on your computer and configure WVS as a proxy server. This allows you to direct WVS to pages that cannot be automatically discovered or accessed, so that you can scan these pages.
Note: To use a browser, you need to start WVS and enable HTTP Sniffer. Therefore, we recommend that you install the second browser and use it for sniffing data communication. Then you can continue to use your favorite browser for normal browsing.
IE configuration
Here, we will first introduce the configuration of Microsoft's IE browser. To configure Internet Explorer, you must first start IE and select "Tools> Internet Options> connection> LAN Settings ",
Enable "Use a proxy server for your LAN ...", Specify the IP address and port of the computer on which WVS runs (8080 by default ). If the browser runs on the same computer as WVS, you can use 127.0.0.1 or localhost as the proxy server address.
Mozilla Firefox Configuration
To configure Firefox to use the WVS proxy, follow these steps:
1. Start your firefox browser and select "Tools> options ",
2. Click the "advanced" button, switch to the "network" tab, and click "set ",
3. Select "manually configure proxy" and specify the IP address and port number (8080 by default) for the HTTP proxy and SSL Proxy ).
4. If you want to use HTTP Sniffer to browse a local Web site running on the same host as WVS, clear the content in the "Do not use proxy" text box.
5. Click OK to save the changes.
Password protection WVS
To use a password to protect the main interfaces of WVS and support applications including Reporter, Vulnerability Editor (Vulnerability Editor), and scheduler, follow these steps:
1. Click "Configuration> Settings> Application Settings> General" to enable password protection Configuration.
2. In the "Password protection" setting, enter the Current password in the "Current Password" text box. If you configure the password for the first time, you do not need to set it.
3. enter a New password in the "new password" and "Confirm New password" text boxes.
4. Click "Set Password" to save the settings.
Once a password is set in WVS, you will see a password protection dialog box next time and later when you start it or start it to support the application. You only need to enter the password configured in WVS
This program can be used normally.