RE: java app question
"Paul Melson" <[email protected]>
| Newsgroups | gmane.comp.security.penetration,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <002401cae575$cfc44040$6f4cc0c0$@com> |
> i am looking to pen test an app which is not a webapp :) . on browsing to the url it launches a java > application using jnlp. > > i used a network traffic sniffer to see the traffic, and it is making post requests to several different urls > (e.g. webapp.com/generatereport etc.), and the response is of type x-serialize object. > > any suggestions on what could be things to look at for such a pentest? Rather than try and reverse the POST requests by looking at packet captures, I would simply decompile the Java file using jad or JD-Core. The code generating those requests should be easy enough to find and read. http://java.decompiler.free.fr/ PaulM ------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------