SShortSingh.
Back to feed

Pentester Builds Custom Traffic Listener After Burp Suite Fails on Unstable VPN App

0
·1 views

A security researcher encountered persistent proxy failures while pentesting an internal financial web app for a student loan servicer, with Burp Suite, Caido, and other tools all failing to capture traffic reliably. The app exhibited an unusual pattern where requests would succeed briefly, then time out for up to an hour, and any modified request — such as one containing a quote or script tag — would receive no response at all. After three largely unproductive days, the researcher concluded that the unstable connection was being worsened by a man-in-the-middle proxy decrypting and resending traffic. Instead of intercepting requests, they built a lightweight browser extension that captures outgoing traffic and immediately forwards it to a local listener program, avoiding the performance issues of storing data in localStorage. The solution resolved both the CORS preflight problem and browser slowdowns by keeping the extension stateless and offloading all storage to the local listener.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Event-Driven Architecture: Key Patterns, Benefits, and Common Pitfalls

Event-Driven Architecture (EDA) is a software design pattern that enables loosely coupled, highly scalable systems by having components communicate through asynchronous events rather than direct calls. Core benefits include easier scalability, component flexibility, and a complete audit trail when events are stored as an immutable sequence. Developers are advised to separate read and write models, design events to be immutable, and implement robust error handling with retry mechanisms. Common mistakes include over-engineering solutions, introducing unnecessary complexity, and misusing events for synchronous communication. In cloud-native environments, EDA pairs well with services like AWS Lambda and Google Cloud Functions to handle real-time event spikes at scale.

0
ProgrammingDEV Community ·

Why Structured Workflows Often Outperform Autonomous AI Agents in Practice

A developer and AI builder argues that structured workflows deserve more attention than autonomous agents, which have become the default recommendation across the AI community. While agents offer flexibility, they introduce compounding complexity — more prompts, APIs, failure points, and harder-to-trace errors — that many projects do not actually require. Predictable, step-by-step workflows are easier to test, debug, monitor, and scale over time, since each component holds a clearly defined responsibility. The author also emphasizes that integration with external systems like GitHub, databases, and APIs often delivers greater business value than sophisticated but isolated agent architectures. The core advice is to first ask what the simplest workflow is that solves a problem, rather than defaulting to an autonomous agent from the outset.

0
ProgrammingDEV Community ·

Engineers Design Fail-Closed WORM Architecture for Multi-Agent AI Coordination

A development team has published details of a 10-tuple canonical envelope architecture designed to ensure reliable state management across asynchronous, multi-agent AI systems. The approach enforces five strict invariants, including transactional ingestion boundaries using PostgreSQL ACID transactions and cryptographic HMAC witness seals on all inter-agent messages. A fail-closed default principle means any unverified or unwitnessed claim is automatically placed on hold, preventing unauthorized state mutations. Chaos testing across 82 continuous integration cycles reportedly achieved a 100% pass rate for single-effect-per-event enforcement with zero duplicate state transitions. The team recommends that system architects avoid unauthenticated webhooks, isolate secrets outside cloud workspaces, and use autonomous cleanup agents to manage expired claims.