Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

[OT] Multi-tier web app client-server response time?!?

Subject: [OT] Multi-tier web app client-server response time?!?
Date: Wed, 15 Sep 2004 20:04:23 -0500
I apologize in advance, as I know this is not the right mailing list,
but considering the level of expertise here, I would dare to post my
question: I am a network geek, with very few knowledge of application
level (especially Java-based) issues, but I am being challenged by
something that I have not seen resolved anywhere else (yet): in an
environment with Oracle 11i web based applications, with an Oracle 9i
database, I am trying to figure out if there is a way to script a
session from a client, to the first tier (forms/web server), then all
the way back into the database, and back to the client, continuously
(every "n" minutes), for "real life transaction RTT measurements" for
"end user experience" measurements.

So far I have attempted a simple macro recording on the host/client
machines, with some time stamps triggered by the change in pointer or
the hour glass or (hard to control) java-controlled pop-up windows,
but that seem to be very flaky (sometimes it works, sometimes it
doesn't). I have also started looking at OpenSTA, but have note had
the chance to figure it out completely.

Out of consideration for a fellow network and security colleague,
could anyone of you - web gurus - point me in the right direction for
either methodologies for scripting this type of transations, or at
least some links as to where to get this type of information?

As a last resort - with my limited knowledge in the upper layers - I
was going to resort to attempting to replay network captures
(traces/dumps), over the various links I am trying to test this
application, but I really see that as too "artificial" to be the best
choice.

Sorry again for the wasted bandwidth on an off-topic subject (now that
I think about it - perhaps I can force a relationship to websec by
asking how to replay multi-tier web-based applications?!? ;))

TIA,
Stef

<Prev in Thread] Current Thread [Next in Thread>