Fiddler Introducing Fiddler HTTP/HTTPS Debugger Runs as a

Fiddler Introducing Fiddler  HTTP/HTTPS Debugger  Runs as a

Fiddler Introducing Fiddler HTTP/HTTPS Debugger Runs as a proxy server on the local machine or on a remote server Written in C# (.NET Framework v2.0) Freely available from

http://www.fiddler2.com How does Fiddler work? Firewall Firefox CryptoAPI WinHTTP

Internet Explorer WinINET Office Fiddler

CorpNET Proxy example.com Mac Mac

PC PC Debugging non-Windows clients PocketPC PocketPC Linux

Linux Fiddler Internet Who uses Fiddler? Microsoft engineers Support teams

Lots of external web developers (10K+ downloads per week) Security researchers Some bad guys What can Fiddler do? HTTP/HTTPS traffic monitoring and

analysis Request and response modification Timing and network manipulation HTTPS Traffic Decryption Fiddler UI: Session List Icons show status of request/response

Lists all traffic URLs, size, and key headers Icons show status of request/response Fiddler UI: Inspectors

Inspectors allow you to visualize requests and responses in meaningful ways. FiddlerScript Rules Rules are where Fiddler gets really fun! Use JavaScript to manipulate request or response headers or entity body. Extending Fiddler UI

FiddlerScript and extensions can add new menu items or tabs. Using Simple Filters Flag, modify or remove headers from all requests and responses.

AutoResponder Replay previously captured or generated traffic. Request Builder Create hand-built HTTP

requests, or modify and reissue a request previously captured. Traffic Comparison Use WinDiff to compare HTTP requests and responses.

QuickExec QuickExec allows you to issue textual commands directly Search Traffic

Search for strings in all captured traffic. Text Encoding / Decoding Convert text between popular web encodings.

SAZ Files Session Archive ZIP files store raw traffic. SAZ files are compressed and may be password protected. SAZ files can be reopened by Fiddler or standard ZIP utilities. FiddlerCap allows capture of SAZ files by non-technical, often remote, users.

FiddlerCap Use FiddlerCap for remote collection of evidence. www.fiddlercap.com Fiddler application with extensions Fiddler 2

Your application hosting FiddlerCore YourApp.exe ExecAction.exe ExecAction.exe Inspector2

Inspector2 IFiddlerExtension IFiddlerExtension Fiddler ScriptEngine Your FiddlerScript FiddlerCore Xceed*.dll

Makecert.exe FiddlerCore Xceed*.dll Makecert.exe Questions?

https://www.fiddler2.com 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Recently Viewed Presentations

  • Gentilezza in Ateneo - Unife

    Gentilezza in Ateneo - Unife

    E ancora: «La generosità cioè la capacità di farsi carico della vulnerabilità degli altri e quindi anche della propria, è diventata un segno di debolezza». Psicologia UNIFE Cameron-Curry & Lavarini, 2012 La gentilezza suscita sospetto perché sembra nascondere un progetto...
  • Sessions about to start Get your rig on!

    Sessions about to start Get your rig on!

    A SPROC is run by the Management Point. The SPROC queries the ResPolicyMap and DepPolicyAssignment SQL Tables. The more records found, the more CPU time required. Troubleshooting Approach. MP_GetMachinePolicyAssinmentis the SPROC for Machine Policy.
  • What do you already know about Queen Elizabeth

    What do you already know about Queen Elizabeth

    A Tudor. Additional that they might not know: Queen of England when America was started. Queen of England when the slave trade started (consider its modern impact on the US even now) Queen of England during the during an invasion...
  • Social Psychology Outlines

    Social Psychology Outlines

    LaPiere's (1934) classic study Corey's cheating study Voting Behavior Rule: the closer the attitude-behavior relationship, the better the prediction. Davidson & Jaccard Attitudes towards birth control? What attitudes specifically predict our use of birth control? Family planning .11 Birth ...
  • 4.2.2. Linear Diffusion at a Planar Electrode The

    4.2.2. Linear Diffusion at a Planar Electrode The

    Fick's second law just determines how the concentration of species Ox changes with time. C. Ox. (x,t) : the concentration of Ox in the infinitesimal volume of solution between the planes x and x - dx :. Substituting such a...
  • The Meeting Place - Jefferson County Public Schools

    The Meeting Place - Jefferson County Public Schools

    7 days seven What day is it today? Thursday What day of the week was it yesterday? Wednesday What day of the week will it be tomorrow? Friday What is today's date? October 1, 2007 Draw a line to the...
  • ATTITUDE OF PROSPECTIVE TEACHERS Dr. Aniruddha Chakraborty Associate

    ATTITUDE OF PROSPECTIVE TEACHERS Dr. Aniruddha Chakraborty Associate

    An attitude is "a relatively enduring organization of beliefs, feelings, and behavioural tendencies towards socially significant objects, groups, events or symbols" (Hogg and Vaughan, 2005) "Attitudes are the evaluative judgments that integrate and summarize . . . cognitive/affective reactions" (Crano....
  • CHAPTER 1 Exploring Data 1.3 Describing Quantitative Data

    CHAPTER 1 Exploring Data 1.3 Describing Quantitative Data

    CALCULATE and INTERPRET measures of spread (range, IQR, standard deviation). CHOOSE the most appropriate measure of center and spread in a given setting. IDENTIFY outliers using the 1.5 × IQR. rule. MAKE and INTERPRET boxplots of quantitative data. USE appropriate...