[Owasp-webscarab] Problem with Webscarab/Spider : authenticated proxy
Rogan Dawes
rogan at dawes.za.net
Fri Nov 6 15:19:35 EST 2009
Cedric MICHEL wrote:
> Hi,
> I use Webscarab (version 20090427-1304) with Firefox 3.5.3 through an
> authenticated proxy.
> Webscarab is properly configured to use my enterprise proxy.
> When Firefox is instructed to use Webscarab proxy (127.0.0.1:8008
> <http://127.0.0.1:8008>), I am asked (by webscarab) for the
> authenticated proxy credentials.
> I am able to reach internet sites through Webscarab in Firefox.
>
> But, when i use the "Spider" fonctionality in the Webscarab UI, every
> request fails in Webscarab ("407 - Proxy authorization").
> Anybody knows how to use "Spider" through an authenticated proxy?
>
> --DrM--
Hmmm, looks like the spider is not programmed to get the credentials
from the credential store when authentication is needed.
If your proxy is performing Basic Auth, you should be able to work
around it by providing a suitable header using the Headers button on the
Spider page. i.e. Copy and paste the Proxy-Authenticate: Basic xxx
header from a proxied conversation.
Let me know if that works for you.
Rogan
More information about the Owasp-webscarab
mailing list