19.09.2017 Views

the-web-application-hackers-handbook

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

750 Chapter 20 n A Web Application Hacker’s Toolkit<br />

A large number of browser extensions are available for Firefox that may be<br />

useful when attacking <strong>web</strong> <strong>application</strong>s, including <strong>the</strong> following:<br />

n HttpWatch is also available for Firefox.<br />

n FoxyProxy enables flexible management of <strong>the</strong> browser’s proxy configuration,<br />

allowing quick switching, setting of different proxies for different<br />

URLs, and so on.<br />

n LiveHTTPHeaders lets you modify requests and responses and replay<br />

individual requests.<br />

n PrefBar allows you to enable and disable cookies, allowing quick access<br />

control checks, as well as switching between different proxies, clearing<br />

<strong>the</strong> cache, and switching <strong>the</strong> browser’s user agent.<br />

n Wappalyzer uncovers technologies in use on <strong>the</strong> current page, showing<br />

an icon for each one found in <strong>the</strong> URL bar.<br />

n The Web Developer toolbar provides a variety of useful features. Among<br />

<strong>the</strong> most helpful are <strong>the</strong> ability to view all links on a page, alter HTML<br />

to make form fields writable, remove maximum lengths, unhide hidden<br />

form fields, and change a request method from GET to POST.<br />

Chrome<br />

Chrome is a relatively new arrival on <strong>the</strong> browser scene, but it has rapidly gained<br />

popularity, capturing approximately 15% of <strong>the</strong> market.<br />

A number of browser extensions are available for Chrome that may be useful<br />

when attacking <strong>web</strong> <strong>application</strong>s, including <strong>the</strong> following:<br />

n XSS Rays is an extension that tests for XSS vulnerabilities and allows<br />

DOM inspection.<br />

n Cookie editor allows in-browser viewing and editing of cookies.<br />

n Wappalyzer is also available for Chrome.<br />

n The Web Developer Toolbar is also available for Chrome.<br />

Chrome is likely to contain its fair share of quirky features that can be used<br />

when constructing exploits for XSS and o<strong>the</strong>r vulnerabilities. Because Chrome<br />

is a relative newcomer, <strong>the</strong>se are likely to be a fruitful target for research in <strong>the</strong><br />

coming years.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!