Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Paros - Web App Security Assessment Tool
Ethical Hacker Community Forums
January 09, 2009, 10:46:27 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Paros - Web App Security Assessment Tool  (Read 7739 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2442


Editor-In-Chief


View Profile WWW
« on: June 08, 2006, 03:46:27 PM »

Quote
We wrote a program called "Paros" for people who need to evaluate the security of their web applications. It is free of charge and completely written in Java. Through Paros's proxy nature, all HTTP and HTTPS data between server and client, including cookies and form fields, can be intercepted and modified.

http://www.parosproxy.org/index.shtml

If data is allowed to be modified before it is sent, this opens a whole can of hacking worms. Let your imagination run wild.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Dengar13
Full Member
***
Offline Offline

Posts: 224



View Profile
« Reply #1 on: June 15, 2006, 03:16:10 PM »

This is a good tool but it missed dome things that we were looking for like XSS vulnerabilities.  It has a pretty good output and is not messy like most free tools.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
charlottebandit
Newbie
*
Offline Offline

Posts: 30


View Profile
« Reply #2 on: July 26, 2006, 02:55:20 PM »

Paros is very interesting.  In one of our CEH labs, we used to inject variables and change the prices of products. 

We even tried it on a website (unsanctioned by the class, of course!!!) for a plasma tv and changed the price to $200.   Grin

Of course we didn't execute it.  It works as a proxy to examine web scripting.
Logged

MS, CCSP, CCNP, CCDP, CEH, CHFI, CPTS
Hug_It
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #3 on: July 28, 2006, 11:54:36 AM »

Dan Kuykendall of MightySeek.com put together a page for a web hacking toolkit. It includes Paros and some other proxies. There's a cool Firefox extension that allows for quick switching of proxies also.

http://www.mightyseek.com/web-hacking-toolkit/

He has a hands on series podcast that covers sql injection and now cross site scripting. Very informative and easy to follow. Even has a sandbox server set up to test out his stuff.
Logged

CISSP
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #4 on: July 29, 2006, 11:48:53 AM »

paros is a good tool and you can get thru most of the webgoat levels with it.

an alternate to it (without the site scanning piece) is the tamper data extension for firefox, the poster above aludes to it.  its a quick easy tool to modify data on the fly.  useful on those hackme websites as well.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
chugh_a
Newbie
*
Offline Offline

Posts: 15


View Profile
« Reply #5 on: September 26, 2006, 06:18:53 AM »

Another good tool is burp-suite. This contains many more features rather than just intercepting & modifying request / response.
Logged

CEH
psychorugger
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #6 on: December 07, 2006, 11:08:30 AM »

I'm looking at Paros now in my lab, along with Spike, burpsuite (which I already like), webscarab, and Nikto.  I'll let you know what my thoughts are when I'm done in a couple of weeks... if I remember to.  haha
Logged

IAM, IEM, CPTS
Cutaway
Jr. Member
**
Offline Offline

Posts: 96


Cutaway


View Profile WWW
« Reply #7 on: December 25, 2006, 01:25:46 PM »

Paros is a great tool to have in your suite.  It provides a great proxy for, as mentioned, the modification of requests and responses.  It can spider a website and analyze it for XSS, SQL injection, and unwanted file vulnerabilities.  The biggest feature it is lacking, IMHO, is a fuzzer.  But since there are plenty of other tools out there to perform this function it is probably not necessary.

One thing to watch out for when using this tool is that fact that it includes the Paros name in the User Agent string.  The program is configured to automatically place Paros and the version number at the end of the User Agent and, the last time I checked, you could not change this through the GUI.  Why is this a problem, you ask?  Well, by placing the name of the tool in the User Agent it gives the web developers a mechanism to monitor for and deny access to this tool.  It was probably included explicitly for this purpose.  The good news is that the Paros Proxy project provides the source code for their tool.  This proxy is written in Java and therefore can easily be modified.  A while back I blogged about this subject.  Although the version is dated the concept and steps should still be the same.  If you are interested you can find the post at http://www.cutawaysecurity.com/blog/archives/9.

I hope this helps.
Logged

Go forth and do good things,
Cutaway
jimbob
Sr. Member
****
Offline Offline

Posts: 333



View Profile WWW
« Reply #8 on: December 29, 2006, 03:38:32 AM »

Paros is indespensible as one of those tools that isn't quite matched by anything else. If you are looking to tamper with HTTP requests it's worth taking a look at Fiddler.

http://www.fiddlertool.com/fiddler/

Fiddler will also allow you to alter requests before they are sent by setting a breakpoint before each request. It's a great tool that fits with MSIE almost seamlessly, so no need to change your proxy settings.

Jim
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.246 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.