Cenzic 232 Patent
Paid Advertising
sla.ckers.org is
ha.ckers sla.cking
Sla.ckers.org
This group should mostly be dealing with how web applications enable networking security issues that are otherwise not there. Everything is being tunneled over port 80 now so what does that enable and how do we fix it? 
Go to Topic: PreviousNext
Go to: Forum ListMessage ListNew TopicSearchLog In
Windows small Proxy which do header rewrite on the fly?
Posted by: dann
Date: March 11, 2009 05:16PM

Hi!

Does anyone know to easy install and configure an web proxy for windows which enable headers rewrite?

I need to setup a fast web proxy at my windows box to replace all headers (before they are sent to the webserver) of the "Cookie" field and a proprietary header.

Well, I did look at the Paros for example and BurpSuite, however I only found a way to do it manualy (request by request), and I need a way to do it transparent - without user interaction (in the case, I), like a header rewrite on the fly.

Ex.: Find header "Cookie: user=XXXXXXXXccxcxscscs; tamp=23434732674272" and
replace it on the fly with "Cookie: user=YYYYYYYccxcxscscs;
tamp=111111111111111111; admin=1", and we can't forget that the proxy
have to deal and fix the size of the content-lenght - so just send the packet to the webserver.

Not so easy, ahn?

Check for example the manual of Paros, it only explain a manual section named: Trapping HTTP requests and responses.

Thanks for any input.

Options: ReplyQuote
Re: Windows small Proxy which do header rewrite on the fly?
Posted by: holiman
Date: March 12, 2009 02:09AM

It was a while ago since I fiddled with it, so maybe it has changed now, but Burp proxy has possibilities for extensions in java. You can implement an interface (or maybe subclass an abstract class) and put your code where burp finds it, and then your class will be called at appropriate times, such as when a request comes in. You can then program in java to perform exactly what you want to do with your request.

(googling). Ah, it had not changed - check this out : http://portswigger.net/suite/help.html#extensibility

Options: ReplyQuote
Re: Windows small Proxy which do header rewrite on the fly?
Posted by: dann
Date: March 12, 2009 11:49AM

Hi holiman

Tnks for reply, but I look something ready, LOL, is not possible I will have to write a tool for it, I can't believe no other persons have this necessity and coded a tool like that.

Any other input is welcome.

Options: ReplyQuote
Re: Windows small Proxy which do header rewrite on the fly?
Posted by: kuza55
Date: March 13, 2009 11:14PM

Burp has this functionality natively, see the "match and replace" section in the options tab of the proxy.

----------------------------------------------------------
Don't forget our IRC: irc://irc.irchighway.net/#slackers
[kuza55.blogspot.com]

Options: ReplyQuote


Sorry, only registered users may post in this forum.