Re: manipulating query strings

From: ma1ler_deamon (ma1ler_deamon_at_yahoo.com)
Date: 02/24/04

  • Next message: Ariel Martinez: "Re: question regarding nessus plug-in 10595 DNS AXFR"
    Date: Tue, 24 Feb 2004 11:33:13 -0800 (PST)
    To: pen-test@securityfocus.com
    
    

     if a form is designed to accept POST variables, it may also accept
     those same variables passed in through the querystring. It may not
     it depends on how lazy the developer was when they made it and if
     they pulled the values from the global collections or the specific
     ones.
     
     ie. foo = Request(bar) , vs foo = Request.QueryString(bar) etc

     you can manipulate hidden variables in a number of ways, you can use
     an intercept proxy which can be kinda overkill for this, or you can
     use custom tools to do it right inside of your browser such as IE

     one integrated IE integrated tool I found was this

     http://sandsprite.com/Sleuth

     it does some stuff ok, some stuff I really like, check out the "Browser
     Extensions" package, it adds a new right click menu item to your
     standard IE context menus that pops up a forms editor. I guess its an
     eval version, but there is a free build of the main app as well.

     -md

    __________________________________
    Do you Yahoo!?
    Yahoo! Mail SpamGuard - Read only the mail you want.
    http://antispam.yahoo.com/tools

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Ariel Martinez: "Re: question regarding nessus plug-in 10595 DNS AXFR"

    Relevant Pages

    • Re: IE Disinformation bar woes
      ... Evidently the security settings used ... emails at yahoo is sure to realize this. ... of the browser and logs into yahoo on one, ...
      (microsoft.public.windowsxp.security_admin)
    • Yahoo! Messenger Auth Bypass Vulnerability
      ... including the popular Yahoo! ... improper caching of pages by the browser. ... Response to this URL does not specify that the browser should not keep its entry in the cache. ... Therefore, even after the user logs out of both messenger and email account, the URL entry ...
      (Bugtraq)
    • Re: Getting Rid of a Yahoo Browser
      ... How to Make Internet Explorer the Default Web Browser ... where do I go to find and then install IE6 & OE. ... How do I dump Yahoo and replace it with IE6 and Outlook Express. ... client, not the SBC Yahoo! ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Help--IE 6 wont open
      ... and some images in my Yahoo DSL browser would ... Tech support at Yahoo said it was an Internet ... > set up and install files for a full Internet Explorer ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Cant Surf
      ... Are you using IE or Yahoo Browser? ... Any difference if you disable both Yahoo Companion and Google Toolbar via IE Tools> Manage add-ons? ... It just sits there with a "busy" cursor for as long as you want to look ... Internet Explorer 6 Service Pack 1 unexpectedly exits after you install ...
      (microsoft.public.windows.inetexplorer.ie6.browser)