Settings

Theme

Show HN: Your Raw HTTP Response -> URL

response.ee

10 points by ukusormus · 4 comments · 1 min read

Reader

I wanted a tool to be able to effortlessly check out how browsers (and other clients) react to different headers (and anomalies) in the HTTP response, so I made it.

Source: https://github.com/ukusormus/response-machine

3 threads
cloths

I'm not sure if just me "https://response.ee/" takes a very long time to load.

Kharacternyk

It can be a nice stub for testing when integrating an API that doesn't have a sandbox environment.

darajava

Nicely done! What do/did you use it for? ie what was the motivation behind building it?

  • ukusormusOP

    I’ve had the idea for some time. Since I started working as a pentester last year, there’s been numerous occasions where I’ve wanted to quickly check how browsers react to different responses. E.g. for testing a CSP bypass, Set-Cookie behaviour, or Content-Disposition header (since it often includes user input - a filename).

    Yes, you can get similar results with Burp or a custom script, but that is more hassle and doesn’t cover all the use cases (publicly accessible, linkable open redirector, …).

    The last drop(s) in the bucket were 1) seeing a WebKit patch about Content-Type sniffing (XSS with SVG & text-plain) and wanting to test out a potential bypass on my phone 2) seeing a tool online that allowed you to test out your responses (I wondered what happened if the HTTP standards were violated or if I inserted null-bytes or sth like that)

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection