Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | NTLM and man-in-the-middle proxies not working |
|---|---|
| Date: | 14 Sep 2005 18:41:08 -0000 |
While doing an application evaluation using man-in-the-midle proxies (Odysseus, then Paros, Achilles) I've found an internal site that doesn't work. Since it seems to be independent of the proxies used and really protects the aplication from fuzzing with parameters, it seems appropriate to seek help here. Normal Scenario is the following: -IIS6 servers with IWA -Application validates users through IWA Internal Browser configured with man-in-the-middle proxy scenario is: -Access to the site gives an 401 HTTP error, which also occurs above, but here IWA information is not sent by the browser -No object is visible on the site -HTTP Headers and code are the same in both circunstances -Advanced Internet Options in IE were explored, with no result, including "Use HTTP/1.1 through proxy connections" and "Enable Integrated Windows AUthentication" -Changing Security zones in IE were also tried, but also with no result External Browser configured with man-in-the-middle proxy scenario is: -Access to the application is possible, after authentication information is inserted -Application denies access to the same user that works in the normal scenario -GIF objects are visible though Seems there's a problem with the way the browser/user/machine is being validated. IP validation is not an option, as testing were always done with the same IP. I've a fealing this might be related to Kerberos or something like GP. Any ideas? rj
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | simplicity improves security?, Saqib Ali |
|---|---|
| Next by Date: | Online quiz for CISSP (new material), Saqib Ali |
| Previous by Thread: | simplicity improves security?, Saqib Ali |
| Next by Thread: | Re: NTLM and man-in-the-middle proxies not working, Amit Klein (AKsecurity) |
| Indexes: | [Date] [Thread] [Top] [All Lists] |