Tool

Fiddler μ„€μΉ˜ 및 HTTPS ν”„λ‘œν† μ½œ νŒ¨ν‚· 뢄석 μ„€μ •

ν”„λ‘œκ·Έλž˜λ¨Έ μ˜€μ›” 2024. 12. 30.

 

ν”Όλ“€λŸ¬(Fiddler)λŠ” HTTP 및 HTTPS νŠΈλž˜ν”½μ„ μΊ‘μ²˜ν•˜κ³  뢄석할 수 μžˆλŠ” κ°•λ ₯ν•œ μ›Ή 디버깅 ν”„λ‘μ‹œ(Web Debugging Proxy) λ„κ΅¬μž…λ‹ˆλ‹€. 주둜 μ• ν”Œλ¦¬μΌ€μ΄μ…˜ 개발 및 디버깅 κ³Όμ •μ—μ„œ μ„œλ²„μ™€ ν΄λΌμ΄μ–ΈνŠΈ κ°„μ˜ λ„€νŠΈμ›Œν¬ 톡신을 λͺ¨λ‹ˆν„°λ§ν•˜κ±°λ‚˜ ν…ŒμŠ€νŠΈν•˜λŠ” 데 μ‚¬μš©λ©λ‹ˆλ‹€.

 

μ£Όμš” κΈ°λŠ₯

  1. HTTP/HTTPS νŠΈλž˜ν”½ 캑처
    • ν΄λΌμ΄μ–ΈνŠΈμ™€ μ„œλ²„ κ°„μ˜ λͺ¨λ“  HTTP 및 HTTPS μš”μ²­κ³Ό 응닡을 캑처.
    • νŠΈλž˜ν”½ λ‚΄μš©μ„ μ‹€μ‹œκ°„μœΌλ‘œ 확인 κ°€λŠ₯.
  2. μš”μ²­ 및 응닡 뢄석
    • μš”μ²­ 헀더, λ³Έλ¬Έ, μΏ ν‚€, 응닡 μ½”λ“œ 등을 μƒμ„Ένžˆ 뢄석.
    • JSON, XML, HTML λ“±μ˜ 데이터 ꡬ쑰λ₯Ό 보기 μ’‹κ²Œ ν‘œμ‹œ.
  3. λͺ¨μ˜ μš”μ²­ 및 응닡 ν…ŒμŠ€νŠΈ
    • κΈ°μ‘΄ μš”μ²­μ„ μˆ˜μ •ν•˜κ±°λ‚˜ μƒˆλ‘œμš΄ μš”μ²­μ„ μƒμ„±ν•˜μ—¬ μ„œλ²„μ™€ 톡신 ν…ŒμŠ€νŠΈ.
    • Mock μ„œλ²„ μ—­ν•  μˆ˜ν–‰.
  4. SSL 디버깅
    • HTTPS νŠΈλž˜ν”½μ„ λ””μ½”λ”©ν•˜μ—¬ μ•”ν˜Έν™”λœ 데이터λ₯Ό 확인 κ°€λŠ₯.
  5. μ„±λŠ₯ ν…ŒμŠ€νŠΈ
    • μš”μ²­/응닡 μ‹œκ°„, νŽ˜μ΄λ‘œλ“œ 크기 등을 λΆ„μ„ν•˜μ—¬ λ„€νŠΈμ›Œν¬ μ„±λŠ₯ μ΅œμ ν™”.
  6. μŠ€ν¬λ¦½νŒ… 및 μžλ™ν™”
    • FiddlerScriptλ₯Ό μ‚¬μš©ν•˜μ—¬ μš”μ²­/응닡을 μžλ™μœΌλ‘œ μ²˜λ¦¬ν•˜κ±°λ‚˜ λ³€κ²½.
    • ν™•μž₯성을 μœ„ν•œ ν”ŒλŸ¬κ·ΈμΈ 지원.
  7. νŠΈλž˜ν”½ μž¬μƒ(Replay)
    • 캑처된 μš”μ²­μ„ λ‹€μ‹œ μž¬μƒν•˜μ—¬ μ„œλ²„μ˜ λ°˜μ‘μ„ ν…ŒμŠ€νŠΈ.

 

λ‹€μš΄λ‘œλ“œ

https://www.telerik.com/download/fiddler

 

Download Fiddler Web Debugging Tool for Free by Telerik

Download and install Fiddler Classic web debugging tool. Watch a quick tutorial to get started.

www.telerik.com

 

 

0️⃣

 

λ‹€μš΄λ‘œλ“œλ₯Ό μ™„λ£Œν•˜κ³  μ„€μΉ˜ 싀행을 μ™„λ£Œν•˜λ©΄ μ•„λž˜μ™€ 같은 화면을 λ³Ό 수 μžˆμŠ΅λ‹ˆλ‹€. 

 

 

Fiddler(ν”Όλ“€λŸ¬)둜 μ›Ή / μ•± 디버깅을 ν•˜λ‹€λ³΄λ©΄ κ°„ν˜Ή νŒ¨ν‚· λ‚΄μš©μ΄ μ œλŒ€λ‘œ 보이지 μ•ŠλŠ” κ²½μš°κ°€ μžˆμŠ΅λ‹ˆλ‹€. 그쀑 μ•„λž˜μ™€ 같은 상황, λ©”μ„Έμ§€λ₯Ό 보신 뢄듀도 μžˆμ„ κ²ƒμž…λ‹ˆλ‹€. HTTPS ν”„λ‘œν† μ½œ, λ³΄μ•ˆμ΄ κ±Έλ¦° νŒ¨ν‚·μ„ μ΄μ œλŠ” ν”Όλ“€λŸ¬λ₯Ό 톡해 λ³Ό 수 μ—†λ‹€κ³  ν•˜μ§€λ§Œ,  λͺ¨λ“  μ‹Έμ΄νŠΈμ— ν•΄λ‹Ήν•˜λŠ” 건 μ•„λ‹Œ 것 κ°™μŠ΅λ‹ˆλ‹€. 그럼 HTTPS  ν”„λ‘œν† μ½œ νŒ¨ν‚· 뢄석 ν•  수 μžˆλ„λ‘ μ„€μ •ν•΄λ³΄κ² μŠ΅λ‹ˆλ‹€.

 

 

 

1️⃣

 

Tools νƒ­μ—μ„œ Options λ₯Ό ν΄λ¦­ν•΄μ€λ‹ˆλ‹€.

 

2️⃣

 

HTTPS νƒ­μ—μ„œ "Capture HTTPS CONNECTs" 및 "Decrypt HTTPS traffic 체크" 

이후 λ‚˜νƒ€λ‚˜λŠ” κ²½κ³  창은 λͺ¨λ‘ Yes μ²˜λ¦¬ν•΄ μ£Όλ©΄ λ©λ‹ˆλ‹€
(ex Root μΈμ¦μ„œ μ„€μΉ˜ μ—¬λΆ€λ₯Ό λ¬»λŠ” 경우 “Yes” 선택 / λ³΄μ•ˆμœΌλ‘œ 인해 확인 λ©”μ‹œμ§€κ°€ λ‚˜μ˜€λŠ” 경우 “예” 선택 )

 

 

3️⃣

 

 Protocols : <client>; ssl3; tls1.0 을 ν΄λ¦­ν•΄μ€λ‹ˆλ‹€. ν•„μžλŠ” 이미 섀정이 λ˜μ–΄ μžˆκΈ°μ— ν”„λ‘œν† μ½œμ΄ 이미 μΆ”κ°€ λ˜μ–΄ μžˆμŠ΅λ‹ˆλ‹€.

 

4️⃣

 

<client>; ssl3; tls1.0; tls1.1; tls1.2

 

μœ„μ™€ 같이 μ„œλ²„ 연결을 ν—ˆμš©ν•΄μ€„ λ‹€λ₯Έ λ²„μ „μ˜ ν”„λ‘œν† μ½œλ„ μΆ”κ°€ν•΄μ€λ‹ˆλ‹€.

 

 

5️⃣

 

 

섀정이 λͺ¨λ‘ μ™„λ£Œ 됐으면 "ok" λ₯Ό λˆŒλŸ¬μ„œ 섀정을 λ°˜μ˜ν•΄μ€λ‹ˆλ‹€.

μ•„λž˜μ™€ 같이 HTTPS νŒ¨ν‚· λ‚΄μš©λ„ μ—΄μ–΄ λ³Ό 수 μžˆλŠ”μ§€ ν™•μΈν•©λ‹ˆλ‹€.

 

 

 

https://goddaehee.tistory.com/176

 

[Fiddler_3] Fiddler https ν”„λ‘œν† μ½œ μ„€μ •

[Fiddler_3] Fiddler https ν”„λ‘œν† μ½œ μ„€μ • μ•ˆλ…•ν•˜μ„Έμš”. κ°“λŒ€ν¬ μž…λ‹ˆλ‹€. 이번 ν¬μŠ€νŒ…μ€ [ ν”Όλ“€λŸ¬ Fiddler https ν”„λ‘œν† μ½œ μ„€μ • ν•˜κΈ° μž…λ‹ˆλ‹€. : ) Fiddler(ν”Όλ“€λŸ¬)둜 μ›Ή / μ•± 디버깅을 ν•˜λ‹€λ³΄λ©΄ κ°„ν˜Ή νŒ¨ν‚· λ‚΄μš©μ΄

goddaehee.tistory.com

 

https://blog.naver.com/is_king/221909918323

 

[Fiddler] μ›Ή 디버깅/ν”„λ‘μ‹œ 도ꡬ Fiddler μ„€μΉ˜ν•˜κΈ°

κΉ€μš©μž¬μ”¨μ˜ μΆ”μ²œμœΌλ‘œ Fiddlerλ₯Ό μ•Œκ²Œ 되고, κ²€μƒ‰ν•΄λ³΄λ‹ˆ Burp Suite와 λŒ€λ“±ν•˜κ²Œ 웹해킹에 μœ μš©ν•œ 도ꡬ라...

blog.naver.com

 

 

[ Fiddler κ΄€λ ¨ 포슀트 λ°”λ‘œκ°€κΈ° ]

1. Fiddler μ„€μΉ˜ν•˜κΈ° : https://blog.naver.com/is_king/221909918323
2. HTTPS νŒ¨ν‚· μΊ‘μ²˜ν•˜κΈ° : https://blog.naver.com/is_king/221909988849
3. μ£Όμš”κΈ°λŠ₯ - νŒ¨ν‚· μΊ‘처/λ³€μ‘°(Break Point) : https://blog.naver.com/is_king/221910375849
4. μ£Όμš”κΈ°λŠ₯ - Filters κΈ°λŠ₯ : https://blog.naver.com/is_king/221915651398
5. QuickExec(슀크립트 λͺ…λ Ή) κΈ°λŠ₯ : https://blog.naver.com/is_king/221915946887
6. μ£Όμš” λ‹¨μΆ•킀와 μ„Έμ…˜ μ•„μ΄μ½˜/κΈ€μž μƒ‰ μ˜λ―Έ : https://blog.naver.com/is_king/221917033986
7. μ£Όμš”κΈ°λŠ₯ - Composer κΈ°λŠ₯ : https://blog.naver.com/is_king/221928829873
8. μ„Έμ…˜μ„ μž¬μš”μ²­ν•˜λŠ” Replay κΈ°λŠ₯ : https://blog.naver.com/is_king/221954541542

λŒ“κΈ€