Re: how to scan the WAP Application for security audit
Shlomi Narkolayev <[email protected]>
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.web-applications,gmane.comp.security.penetration |
|---|---|
| Message-ID | <[email protected]> |
Hi, Many WAP application checks some parameters like: User-Agent, IP (some countries assign different IPs to mobiles. So just change the user-agent to mobile user-agent in the web scanners you use and verify that the WAP don't filters your requests by IP checking (You can verify it by using emulator from your PC and see if it blocks your requests). The pen test is manual, for doing that, you can use an emulator from your PC, if the WAP blocks yours requests by IP, you'll need to connect your mobile to PC as a modem, or turn your mobile to access-point and make a network between your PC and the mobile, and change the rout in the PC to go to WWW thru mobile. Kind Regards, Narkolayev Shlomi. Visit my blog: http://Narkolayev-Shlomi.blogspot.com On Fri, Jul 16, 2010 at 4:15 AM, modversion <[email protected]> wrote: > Hi list: > I want to scan the wap application for security audit,but the > Acunetix Web Vulnerability Scanner did not work fine,Any1 could be > kind enough to suggest me another web security scan to audit the WAP > application via mobile phone or pc. > > thanks! > > > ---------------------------------------------------------------------------- > Join us on IRC: irc.freenode.net #webappsec > > Have a question? Search The Web Security Mailing List Archives: > http://www.webappsec.org/lists/websecurity/archive/ > > Subscribe via RSS: > http://www.webappsec.org/rss/websecurity.rss [RSS Feed] > > To unsubscribe email [email protected] and reply to > the confirmation email > > Join WASC on LinkedIn > http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > >