LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #2  
Old 22-Jul-2009, 06:00 PM
 
Join Date: Feb 2008
Posts: 2,030
edmaa 30-39 reputation pointsedmaa 30-39 reputation pointsedmaa 30-39 reputation pointsedmaa 30-39 reputation points
Default Re: iChain Form Fill Dynamic Input Tag Names

rrawson wrote:

>
> I have a client using a commerical application (Oracle) which in it's
> latest incarnation is trying to foil some sort of attack by randomly
> salting the names of input tags. So a static form fill policy cannot
> match the form fields.
>
> The question I have is:
>
>
> - Is there any way to specify a wild card in the name of the input
> tag in the form fill policy?


Nope

> - Is there any way to specify the input tag by an enumeration
> (input[first()], input[2], input[last()], etc.)


Nope

> - Is there any way to inject some sort of javascript content that
> could be used to look at the form and do a more customized fill?


Not sure

Maybe you can use the authentication header instead ? OLAC allows you
to inject the credentials into the authentication header and send it to
the backend webserver.

--
Cheers,
Edward
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -6. The time now is 09:40 PM.


© 2007 Novell, Inc. All Rights Reserved.

Search Engine Friendly URLs by vBSEO 3.3.0 RC2