xmitm: xml man in the middle tool
This post is a result of ideas and tools developed during the review of client-side applications that use the XMPP protocol to communicate with a server (opening a raw socket, not using HTTP as a transport).
The only way we could think of getting our hands on the communication was to write a small set of scripts to trick the client and encapsulate the communication inside HTTP requests that we could then manipulate using standard proxy tools such as burp.
Although the information and scripts described in this post are focussed on intercepting a XML communication, the same principles apply to man in the middle any ASCII protocol such as smtp, ftp or pop.
Continue reading here....
- Add new comment
- Get Our RSS Feeds
- Email this page
- 572 reads


















Recent comments
2 weeks 6 days ago
10 weeks 5 days ago
12 weeks 5 days ago
12 weeks 5 days ago
14 weeks 21 hours ago
14 weeks 3 days ago
15 weeks 6 days ago
16 weeks 1 day ago
21 weeks 5 days ago
22 weeks 11 hours ago