Is there an option to find out version and ciphers for SSL connection directly from Fiddler

62 views
Skip to first unread message

Gregory Suvalian

unread,
May 15, 2018, 4:51:32 PM5/15/18
to Fiddler
Hello,


Fiddler provides wealth of information when it's used as SSL proxy for browser about negotiated SSL protocol, ciphers etc. But you use composer to directly hit HTTPS host all this valuable information is missing. Am I looking at wrong place or is there an option to find that information?

Thanks,
G

Eric Lawrence

unread,
May 15, 2018, 5:09:19 PM5/15/18
to Fiddler
Today, this only works the way you hope if there's an upstream proxy.

Assuming your environment doesn't have one, this can be simulated via the (cumbersome) process of running two Fiddler instances, one in normal Capturing mode and the other in Viewer mode (File > New Viewer) and using the Composer in the Viewer-mode instance. That Viewer-mode Composer will chain to the "upstream" capturing-mode version of Fiddler, and then you can examine the CONNECT tunnel in that instance.

(FWIW, it's probably possible to get a few of the pieces of data e.g. the selected cipher suite by writing some FiddlerScript. But that approach cannot possibly get the full set of data-- in particular you wouldn't be able to see the cipher list that Fiddler offered.)



Gregory Suvalian

unread,
May 15, 2018, 5:11:11 PM5/15/18
to Fiddler
Is it possible to request as a feature?

Eric Lawrence

unread,
May 15, 2018, 5:16:12 PM5/15/18
to Fiddler
https://fiddler.ideas.aha.io is the issue tracker where you can make the request.

Sadly, given the backlog, the relative complexity and risk of the change, and the availability of workarounds, I'm afraid I think it not especially likely that Telerik will get to it.

Stepping back though-- what do you hope to do with the data? It's important to recognize that, because Fiddler is doing HTTPS interception itself, the data in the ClientHello it sends differs from that sent by the client, and thus the data in the ServerHello response from the server is also likely different than would be sent in the absence of Fiddler.

Gregory Suvalian

unread,
May 15, 2018, 5:18:01 PM5/15/18
to Fiddler
I just want easy way to verify/troubleshoot SSL connectivity and protocols without resorting to running a proxy. I understand that SSL will work differently compared to direct connection from browser.

Jerry Lee Daniel

unread,
Dec 18, 2023, 4:26:34 PM12/18/23
to Fiddler

For Crypto Trading Investment Guidelines.
Business Administration
📱 Account Management
💳 Entrepreneurship
📈📉 Binary Options/Bitcoin Expert 💰 Loan
Best in stock marketing and Crypto currency investment.

NOTE: ONLY SERIOUS / ACTIVE TRADER CAN CONTACT.

DM ME ON WHATSAPP
+447487588816
Reply all
Reply to author
Forward
0 new messages