Sunday 28 September 2014

Know Tamper Data


What is tamper data?

Tamper Data is a Firefox Extension which gives users the power to view, record and even modify outgoing HTTP requests. It is simple yet effective tool which can be used to do penetration testing. Using this tool we can trace and time the http/https connections, responses and parameters being sent.


Download & Install Tamper data

Open your Mozilla fire fox browser on your machine( if already installed on your machine ) else you need to first download and install Mozilla fire fox browser on you machine in-order to use this tool. Now type "Tamper data add on" in google search.



Now click on the search result which is coming from the link https://addons.mozilla.org/en-US/firefox/addon/tamper-data this should redirect you to the page showing Tamper data add on by 'Adam Judson'



Click on the "Add to Firefox "option here and that will  start your download and will ask you to install it on your Firefox browser.Once the installation is done it will prompt to restart your browser and by clicking on "Restart Now",it will  restart your browser




How to use ?

Once the donwload and installation process is completed, on opening  the Firefox browser click on "Tools option" under this you can find Tamper data listed.


Clicking on the tamper data  will open up a Tamper Data window as shown below, with different columns like Time,Duration,Total Duration,Size,Method,Status,Content Type,URL,Load Page. We have an option here which allows users to customize their column views.



Start Tamper - Will initiate the tamper process and record all the HTTP request.
Stop Tamper - Will stop the tampering process as well as recording the HTTP request.
Clear- Will clear all the recorded HTTP request from the window.

Clicking on Start Tamper in this window,will start recording all your ongoing HTTP request  in the window below and it will prompt you for Tamper,Submit,Abort Request of each HTTP request.


TamperThis allows the users to modify request parameters before request submission.
Submit - This will just send the request without any modification in the request.
Abort Request - This will just stop the request from being sent.


Hitting on tamper button here will open Tamper pop-up showing requested header fields on the left side and the post parameter fields and values on the right side which allows the users to tamper/modify the post parameter values before actually submitting your requests. The only limitation we have here is if the request uses the GET method, then the right-hand side of the dialog will be empty.


"THANKS FOR RUNNING THROUGH MY BLOG. "
KEEP FOLLOWING FOR THE LATEST UPDATES.