Fiddler2 extension: Burp-like inspector
How to use session handling macro
- Launch Fiddler2 and browsing target web site: http://yamagata.int21h.jp/tool/BurplikeInspector/testapp/
data:image/s3,"s3://crabby-images/18c91/18c91dfa2d6602ce683cdcccb10347d40d6b992f" alt=""
data:image/s3,"s3://crabby-images/34714/34714cb67fe441bb2c00bdbc079e68b2a8924242" alt=""
data:image/s3,"s3://crabby-images/1c189/1c189e7f1872314008ceafb9effabe4c6423d0d0" alt=""
- Select first request (Pre-processing request) and right click, "Add to Session Handling Macro"
data:image/s3,"s3://crabby-images/8739b/8739b9dff2910c2abb17b8d1c112a460ed3c7994" alt=""
- Input macro description and click "OK"
data:image/s3,"s3://crabby-images/a5948/a59488cb81998bc30629a4784fcf95f841a07b58" alt=""
- Select third request (Post-processing request) and right click, "Add to Session Handling Macro"
data:image/s3,"s3://crabby-images/2eadc/2eadc457dfca343abd7a0141f911e2c739668e7a" alt=""
- Input macro description and click "OK"
data:image/s3,"s3://crabby-images/885e9/885e9b5bc75542ba508ada417256af325e7d22f7" alt=""
- Click [Add] button on Session Handling Rules section.
data:image/s3,"s3://crabby-images/4cede/4cede7e056938b118ec625e46d1efc793a93ed93" alt=""
- Click [Add] button on Rule Editor.
data:image/s3,"s3://crabby-images/0ef86/0ef868996a04855dd46ea768f113e1a834a305d6" alt=""
- Select "Run a macro" radio button, and click [Add] button on (1)Run a macro.
Then, on Select Macro window, check "show input" macro and click [OK] button.
data:image/s3,"s3://crabby-images/6fdf7/6fdf754186c62cb2101915a241acbcc8e44b1bb8" alt=""
- Click [Edit] button on (4)Update current request section.
Then, on Configure Macro Item window, select "Derived from prior response" pulldown menu at "PHPSESSID" and "sid". Click [OK] button.
data:image/s3,"s3://crabby-images/e9c92/e9c92ae6da27e5294b77ce94f0cdf8d8653159ae" alt=""
- Click [OK] button.
data:image/s3,"s3://crabby-images/c434a/c434ad99ae801ff4e307ac14cdda6469811cacd8" alt=""
- Click [Add] button to add a post-processing macro.
data:image/s3,"s3://crabby-images/2db88/2db886aa88d5e17f6e11927e8cb4e7f9d7f75865" alt=""
- Select "Run a post-request macro" radio button, and click [Add] button on (1)Run a macro section. Then, check "submit" macro on Select Macro window. Click [OK] button.
data:image/s3,"s3://crabby-images/42785/42785a6b5145a0842ad29f23983f3a07f0a7bd84" alt=""
- Click [OK] button.
data:image/s3,"s3://crabby-images/dca68/dca6848552c062187496cacf55f5cbc2458c610a" alt=""
- Session handling macro and rule setting was finished.
Repeater21
- Select second request (target request) and "Send to Repeater21".
data:image/s3,"s3://crabby-images/e1c49/e1c49e916e5ac5aba3869cb6b9b2115f191ccadc" alt=""
- Click [Pre (F4)] button, then run a pre-processing macro, and refresh "PHPSESSID" and "sid" parameter.
Modify request and click [Go (F5)] button, then send target request.
Click [Post (F6)] button, then run a post-processing macro.
data:image/s3,"s3://crabby-images/909b9/909b97da027425a80049269f125515b6833a242f" alt=""
Intruder21
- "Send to Intruder21", you should enable Pre/Post macro on "Session" panel.
data:image/s3,"s3://crabby-images/bf430/bf430e619ba83710896bc304cfc4621ff2e6d0bb" alt=""
return to tool page
by yamagata21