Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: NTLM and man-in-the-middle proxies not working

Re: NTLM and man-in-the-middle proxies not working

From: <raymond_b_jimenez_at_yahoo.com>
Date: 3 Oct 2005 19:32:37 -0000
('binary' encoding is not supported, stored as-is) >From the tests I've done last week, I can confirm that Burp Proxy effectively deals with the NTLM authentication problem. What is more interesting is that even without fixing the NTLM credentials, the browser works with NTLM authentication. This behaviour might suggest that the HTTP headers introduced by other proxies might really explain why the NTLM authentication might not work with a proxy.

It does not explain though why it works in my testing scenario. I'll be testing it with Burp and other proxies in the next days and will post my results back.

rj
Received on Oct 03 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]