XML man in the middle



Sometime ago I did some research trying to find a tool that could be
used for man-in-the-middle an XML communication and could not find many.

We were trying to intercept the communication between a Macromedia Flash
application and a remote server. They used the XMPP protocol, but not
over HTTP, instead they communicate through a raw socket.

At the end we realized that we could use standard web proxy tools
provided that we could tunnel the communication over HTTP. Just in case
anyone has been in the same situation I have put the ideas and tools
together in this post:

http://weblog.nomejortu.com/?p=38

regards,

daniel

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: FrontEnd/BackEnd Vs ISA (reverse proxy)
    ... Let me clarify the FE/BE communication. ... SSL Bridging is possible when using multiple ISA servers, but has nothing to do with Exchange. ... PROXIED back to the appropriate BE server utilizing the equivalent decrypted protocol (i.e. HTTPS becomes ... HTTP, POPS becomes POP3, IMAPS becomes IMAP4). ...
    (microsoft.public.exchange2000.protocols)
  • Re: unable to view remote front panel in web browser
    ... panel is being requested they communicate with our binary protocol. ... Firewalls sometimes block binary traffic through the HTTP port." ... The communication between the browser client and the LabVIEW Web ...
    (comp.lang.labview)
  • RE: HTTP based trojans
    ... Yes, except that in Setiri, for example, the communication adheres to ... HTTP standards. ... firewalls and IDS systems unnoticed; ... > standard TCP communication standard, ...
    (Focus-IDS)
  • Re: Python to Python communication
    ... > I have a group of Python programms which I want to teach to "talk to each ... > protocols / intra computer communication). ... For the communication UDP, TCP or HTTP can be used. ...
    (comp.lang.python)
  • HTTPS question
    ... I'm writing an extension to an existing client / server suite that ... currently uses UDP for all of its communication. ... HTTP calls. ... This makes the proxy think that the client is simply ...
    (comp.os.linux.networking)