Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
passfree
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
61.
▲
Hack Like In The Movies
(suite.websecurify.com)
1 points
by
passfree
12y ago
|
0 comments
62.
▲
Proxy.app Now With WebView And A Debugger
(blog.websecurify.com)
1 points
by
passfree
12y ago
|
0 comments
63.
▲
Dir Bruteforcer In Go That Doesn't Work
(blog.websecurify.com)
1 points
by
passfree
12y ago
|
0 comments
64.
▲
Proxy.app Receives a Facelift
(blog.websecurify.com)
2 points
by
passfree
12y ago
|
0 comments
65.
▲
Proxy.app Now With Breakpoints
(blog.websecurify.com)
1 points
by
passfree
12y ago
|
0 comments
66.
▲
In the spirit of Heartbleed I propose to name the TweetDeck XSS vuln #tweetferno
(twitter.com)
1 points
by
passfree
12y ago
|
0 comments
67.
▲
by
passfree
12y ago
It is unknown because nobody checked. Why nobody checked? Because it is too simple so nobody thought that it will work until now.
68.
▲
Winning Security Bug Bounties
(learn.websecurify.com)
1 points
by
passfree
12y ago
|
0 comments
69.
▲
by
passfree
12y ago
This is so wrong in some many levels. 1. They should not ask for any password first of all 2. They post the password to their server when they could have checked it on the client 3. The password is sent as GET meaning that it is in the URL
70.
▲
by
passfree
12y ago
Awesome!
71.
▲
by
passfree
12y ago
My personal take is that you should always develop for the platform you are targeting. It is not so much about weather the UI is drawn so that it looks native and it is not about performance (although important). It is more about what you c
72.
▲
What To Expect In Proxy.app
(blog.websecurify.com)
1 points
by
passfree
12y ago
|
0 comments
73.
▲
Finding XML Entity Injection Problems
(blog.websecurify.com)
1 points
by
passfree
12y ago
|
0 comments
74.
▲
Climbing App Store Top Charts
(blog.websecurify.com)
1 points
by
passfree
12y ago
|
0 comments
75.
▲
by
passfree
12y ago
Hi everyone. I just wanted to let you know that we started pushing the documentation here: http://learn.websecurify.com/help/proxy/ - soon to be bundled with the app itself.
76.
▲
by
passfree
12y ago
Interesting. We have those libraries already written so if you let us know what you are building we may be able to help.
77.
▲
by
passfree
12y ago
Unfortunately at the moment we cannot think of any sensible way to do this. You can proxy both through the same proxy but we do not have capabilities to differentiate between the two types of traffic. This looks like a useful feature though
78.
▲
by
passfree
12y ago
Just use the ASK US button on your left-hand side.
79.
▲
by
passfree
12y ago
Hi, on point 1 you are correct. We have overlooked this and we feel stupid because of this. However, the good news is that this is already fixed. We are awaiting for Apple's approval. On point two - unfortunately this is how Chrome wor
80.
▲
by
passfree
12y ago
Thanks a lot. We will look into it for future releases.
81.
▲
by
passfree
12y ago
Hi Billy. I wonder if you are the same Billy I met years ago. :) If yes, long time no hear. These are all valid points. Writing security tools is technically very challenging even for the most basic things. Even a spider, regardless how bas
82.
▲
by
passfree
12y ago
Yes of course. We had to remove the integration with the notification API and also remove the facilities which allow us to install the CA certificate smoothly into your device. The second was flagged as breaking a clause which states that a
83.
▲
by
passfree
12y ago
Hi ahmadeus, Don't give up on us. :) It is probably something very simple. Just contact us via our contact form and we will get it sorted. http://www.websecurify.com/desktop/proxy.html
84.
▲
by
passfree
12y ago
We have no demo for this at the moment. We are not prepared to issue these kind of binaries at this stage. We will update as soon as we can.
85.
▲
by
passfree
12y ago
Hi hartator, That is a feature we are thinking about from day one but unfortunately to do this we either have to run multiple proxy servers and allow you to configure them individually or do process monitoring to understand who is connectin
86.
▲
by
passfree
12y ago
Hi hartator, Thanks for the support. Both fiddler and Proxy.app are proxies. Forms, JSON and XML are handled without a problem. At the moment there is no support for AMF if this is what you are referring to. We did not wanted to add this in
87.
▲
by
passfree
12y ago
Badly phrased. It will compete with Burp but not as a one-size-fits-all type of security solution.
88.
▲
by
passfree
12y ago
We did run into a few roadblocks and as a result we were forced to carve features out from the final product. However, the decision is not final and maybe if we manage to convince the app reviewers that these features are vital to the users
89.
▲
by
passfree
12y ago
Hi danpalmer, Some tools are much more useful in the browser - and not in the proxy. As for the session management security - you will rarely need this functionality these days unless you do security research. This tool was useful years ago
90.
▲
by
passfree
12y ago
Hi tptacek, Indeed security tools should be part of the developer's workflow but not necessarily the way they are presented in Burp. We are yet to see a horde of developers who can spend spare time fiddling with requests in order to fi
More ›