RE: java app question

"Paul Melson" <[email protected]>
Newsgroups gmane.comp.security.penetration,gmane.comp.security.web-applications
Message-ID <002401cae575$cfc44040$6f4cc0c0$@com>
> i am looking to pen test an app which is not a webapp :) . on browsing to
the url it launches a java 
> application using jnlp. 
> 
> i used a network traffic sniffer to see the traffic, and it is making post
requests to several different urls 
> (e.g. webapp.com/generatereport etc.), and the response is of type
x-serialize object. 
>
> any suggestions on what could be things to look at for such a pentest? 

Rather than try and reverse the POST requests by looking at packet captures,
I would simply decompile the Java file using jad or JD-Core.  The code
generating those requests should be easy enough to find and read.

http://java.decompiler.free.fr/

PaulM



------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.