19.09.2017 Views

the-web-application-hackers-handbook

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

766 Chapter 20 n A Web Application Hacker’s Toolkit<br />

function built in to <strong>the</strong> suite means that you can quickly retrieve an interesting<br />

request from ano<strong>the</strong>r component (proxy, spider, or fuzzer) for manual investigation.<br />

It also means that <strong>the</strong> manual request tool benefits from <strong>the</strong> various shared<br />

functions implemented within <strong>the</strong> suite, such as HTML rendering, support for<br />

upstream proxies and au<strong>the</strong>ntication, and automatic updating of <strong>the</strong> Content-<br />

Length header. Figure 20-11 shows a request being reissued manually.<br />

Figure 20-11: A request being reissued manually using Burp Repeater<br />

The following features are often implemented within manual request tools:<br />

n Integration with o<strong>the</strong>r suite components, and <strong>the</strong> ability to refer any request<br />

to and from o<strong>the</strong>r components for fur<strong>the</strong>r investigation<br />

n A history of all requests and responses, keeping a full record of all manual<br />

requests for fur<strong>the</strong>r review, and enabling a previously modified request<br />

to be retrieved for fur<strong>the</strong>r analysis

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!