Testing web requests to back-end servers make up the bulk of Web Application tesing. To capture those requests we need to use Web Proxies. These are tools that can be set up between a browser and a back-end server to capture and view all the web requests being sent between both ends.

URL Encoding

Our request data should be URL-encoded and our request headers should be correctly set. Some of the characters that need to be encoded are

  • Spaces: May indicate the end of request data if not encoded
  • &: Otherwise interpreted as a parameter delimiter
  • #: Otherwise interpreted as a fragment identifier

Proxying Tools

We may want route tool traffic through a Web Proxy.

# Point proxychains to the web proxy
sudo nano /etc/proxychains.conf
# metasploit
msf6 auxiliary(scanner/http/robots_txt) > set PROXIES HTTP:127.0.0.1:8080

Burp Intruder

Burp’s Web Fuzzing tool. It has several attacks

  • Sniper - attack with only payload position
  • Cluster Bomb - several payload positions