官术网_书友最值得收藏!

HTTP Proxy

The most important tool for testing web applications is the HTTP Proxy. This tool allows you to intercept all the communication between the browser and the server in both directions. These proxies are called man-in-the-middle proxies. These tools will let us understand how an application works, and most importantly, it will allow us to intercept the requests, responses, and modify them.

Usually, the proxy will run in the same machine as the browser you're using for testing the application. The most used HTTP proxies by security professionals are Burp Suite from PortSwigger security (https://portswigger.net/burp/proxy.html) and Zed Attack Proxy (ZAP) (https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project). We also have the MITM proxy. It is a newer alternative developed in Python and is good to build tools or automate certain scenarios. The downside is that it's the only console, and there is no GUI, which for our purposes, is a benefit.

主站蜘蛛池模板: 清镇市| 丹东市| 尤溪县| 彩票| 萍乡市| 禹城市| 犍为县| 临安市| 华坪县| 晋州市| 凤阳县| 云南省| 酒泉市| 遂宁市| 临桂县| 丰顺县| 普洱| 健康| 建阳市| 宜宾市| 庄浪县| 丁青县| 泽库县| 宝兴县| 永昌县| 胶州市| 墨玉县| 崇明县| 尖扎县| 岢岚县| 中西区| 驻马店市| 龙口市| 冷水江市| 馆陶县| 芷江| 桂阳县| 万盛区| 苍溪县| 新乐市| 德惠市|