The Fiddler program provided by Telerik is awesome, it has the ability to capture traffic, and this means, that it is also able to capture traffic from Virtualbox environments.
In this article, we will take a look on how you can adjust Fiddler so it will capture VirtualBox traffic.
Before we start, we need to:
- Have the virtualbox machine in the same network as Fiddler
- Have Fiddler listen on a specific port
- Have the source IP address of the system that is running Fiddler
In this article, the values for the above are:
- We have a Windows 7 machine with Internet Explorer
- We have Fiddler listening on port 1337
- Our system IP address is 192.168.1.103
Proxy it up with Fiddler
Fiddler has a build in proxy, make use of it. You can adjust the proxy details by navigating to:
In the picture above, you will see that we have enabled “Allow remote computers to connect“, and we have adjusted the Fiddler listen port to ‘1337‘.
The steps to perform are:
- Enable remote computers to connect
- Adjust the Fiddler listen port to your preference
The VirtualBox machine
Now that you have adjusted Fiddler to listen, it is time to forward the browser in the VirtualBox VM to Fiddler.
Open your favorite web browser, and navigate to options, once you are at the options screen, forward towards the connections tab and adjust the proxy settings to it will send the data towards the IP address of the machine that is running Fiddler, and on the listening port of Fiddler.
In Internet Explorer the order to hold is:
- Internet Options
- LAN Settings
- Enable Proxy server: Use a proxy server for your LAN
- Provide destination IP address 192.168.1.103 and destination port 1337
- Press OK
Now navigate to a website with the browser in your VirtualBox environment, and head back to Fiddler. If everything is correct, you should see the traffic of your VirtualBox environment.
In a previous post, we discussed how you can crank up Fiddler with malware analysis tools. Combinate that with your Virtualbox environment, and you are up and running to have some fun.