Showing posts with label Browser. Show all posts
Showing posts with label Browser. Show all posts

August 20, 2009

Freely available web measurement solutions

Analog

http://www.analog.cx

Web server logfile Software

Win/Unix/Mac Analog is highly scalable, ultra-fast, easily configured to report in over 30 languages, and it works on any operating system. Analog is purportedly the most popular measurement application in the world.

AWStats

http://awstats.sourceforge.net

Web server logfiles, FTP logs, mail logs Software

Win/Unix/Mac An open source Perl-based measurement tool, AWStats is a very flexible tool for technically minded folks.

WWWStat

http://ftp.ics.uci.edu/pub/websoft/wwwstat/

Web server logfiles Software

Unix-based systems, Relatively simple and easily modified Perl-based logfile parser for Unix systems and common logfile (CLF) format web servers.

Log Parser 2.0

http://www.microsoft.com/technet/scriptcenter/tools/logparser/default.mspx

Web server logfiles Software

Windows Microsoft tool that allows SQL-like queries against Microsoft Internet Information Server (IIS) log files.

FunnelWeb

http://www.funnelwebcentral.com

Web server log files Software

Win/Unix/Mac Surprisingly well-supported by moderately active bulletin boards maintained by a regular software com

January 26, 2009

Protecting cookie

XSS attacks can be used to hack cookie information. Following code is demonstrates simple steps to hack unprotected cookie values.
Create Javascript file “getMe.js” with just one line

alert(document.cookie);

Create hackMe.htm file as shown

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<HTML>
<HEAD>
<TITLE>A document with SCRIPT</TITLE>
<META http-equiv="Content-Script-Type" content="text/tcl">
<SCRIPT type="text/javascript" src="http://someHost/myDir/getMe.js">
</SCRIPT>
</HEAD>
<BODY>
</BODY>
</HTML>

Now you can use hackme.htm to perform XSS attack.

To protect cookie attacks set HttpOnly flag to true as shown.

MyCookie = Request.Cookies("MyID")   
if MyCookie is Nothing then
MyCookie = New HttpCookie("MyID")
MyCookie.HttpOnly = true
Response.AppendCookie(MyCookie)
end if
MyCookie.Value = sAppId & sSessionId
Response.Cookies.Set(MyCookie)
Or
Response.Cookies("MyID") = “MySecId”
Response.Cookies("MyID").HttpOnly=true 

You can get more info -
http://en.wikipedia.org/wiki/HTTP_cookie
http://www.codinghorror.com/blog/archives/001167.html

November 18, 2008

How to dump Internet Explorer settings to a textfile?

If this is on XP or Vista, try running gpedit.msc, then navigate to Local Computer Policy > Computer Configuration-> Administrative Templates > Windows Components > Internet Explorer. Right click on Internet Explorer and you'll be able to export all the settings.

If you need to do this programmatically, you could try looking at the IE registry settings in the hive.

IE settings:
[HKEY_CURRENT_USER\software\microsoft\Windows\CurrentVersion\InternetSettings]
[HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\InternetSettings]
[HKEY_CURRENT_USER\software\microsoft\Internet Explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\Internet Explorer]