Thursday, August 18, 2011

Proxy detection via "Proxy-Connection" header

I found a site that threw this message to me while trying to use Burp proxy:




I fired up wireshark and captured a normal request and a burp request, then exported the headers to a file




A quick diff showed the difference




Now it's just a matter of using burp "match and replace" feature



Finally we can load the page correctly, but what if instead of showing us that helpful message the application just behaved differently?

No comments:

Post a Comment