CAIDO
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Modern web security testing proxy. Fast, lightweight alternative to Burp Suite with a clean UI and efficient workflow.
INSTALLATION#
# Download from https://caido.io/download # Available for: Linux, macOS, Windows # Linux (AppImage) chmod +x caido-desktop-linux-x86_64.AppImage ./caido-desktop-linux-x86_64.AppImage # macOS # Download .dmg, drag to Applications # CLI version (headless) ./caido-cli --listen 127.0.0.1:8080 # Docker docker run -p 8080:8080 caido/caido
SETUP#
# 1. Start Caido # 2. Access UI at http://127.0.0.1:8080 (or desktop app) # 3. Configure browser proxy: 127.0.0.1:8080 # 4. Install CA certificate for HTTPS interception: # Settings > CA Certificate > Download # Import into browser/system trust store # FoxyProxy (browser extension) recommended for proxy toggling
CORE FEATURES#
INTERCEPT (PROXY)#
# Similar to Burp Proxy - Intercept HTTP/S requests and responses - Forward, drop, or modify intercepted traffic - Breakpoints: pause on matching requests - WebSocket support # Keyboard shortcuts Forward request: Enter Drop request: Delete Send to Replay: R Send to Automate: A
HTTP HISTORY#
# View all proxied traffic - Filter by method, status, host, path - Search request/response content - Color-coded status codes - Sort by any column # Filters host:example.com # By hostname method:POST # By HTTP method status:200 # By status code path:/api # By path ext:json # By extension body:password # By body content # Scope - Define target scope (domains/paths) - Filter history to in-scope only - Reduces noise from out-of-scope traffic
REPLAY (REPEATER)#
# Manual request manipulation and resending 1. Select request from History or Intercept 2. Send to Replay (right-click or keyboard shortcut) 3. Modify request as needed 4. Click Send 5. Compare responses side-by-side # Features - Multiple tabs for different requests - Request/response highlighting - Auto-content-length update - Follow redirects toggle
AUTOMATE (INTRUDER/FUZZER)#
# Automated request fuzzing and testing
1. Send request to Automate
2. Mark insertion points (select text, click Mark)
3. Choose payload source:
- Wordlist file
- Numbers range
- Custom list
4. Configure settings:
- Concurrent connections
- Delay between requests
- Follow redirects
5. Start automation
6. Analyze results (filter, sort, compare)
# Payload positions
- Single position: test one parameter
- Multiple positions: test combinations
# Analysis columns
- Status code
- Response length
- Response time
- Content-type
- Custom match (regex/string)
MATCH & REPLACE#
# Auto-modify requests/responses in transit
- Add/modify headers
- Replace body content
- Change methods
- Useful for:
- Adding auth headers automatically
- Bypassing client-side checks
- Modifying Content-Type
- Testing header injections
SITEMAP#
# Hierarchical view of discovered content - Tree view of hosts and paths - Discovered via proxy history - Shows HTTP methods per path - Useful for understanding application structure
WORKFLOWS (PLUGINS)#
# Caido supports workflow automation - Custom JavaScript/TypeScript plugins - Convert/encode/decode data - Chain operations together - Community workflows available # Built-in conversions - Base64 encode/decode - URL encode/decode - HTML encode/decode - Hex encode/decode - JSON prettify - Hash generation (MD5, SHA1, SHA256)
COMPARE#
# Diff two responses - Side-by-side comparison - Highlighted differences - Useful for testing parameter effects - Compare baseline vs modified requests
EXPORT#
# Export requests/responses - Copy as cURL command - Copy as raw HTTP - Export filtered history - Save for reporting
TIPS FOR WEB TESTING#
# Authentication testing 1. Capture login request in History 2. Send to Replay 3. Test credential variations 4. Check for rate limiting 5. Test session token handling # Parameter fuzzing 1. Capture request with parameters 2. Send to Automate 3. Mark parameter value 4. Load wordlist (SecLists recommended) 5. Analyze response differences # API testing 1. Set scope to API base URL 2. Browse/interact with the app 3. Review API calls in History 4. Replay with modified parameters 5. Test for IDOR, injection, auth bypass # Header manipulation - Add X-Forwarded-For, X-Original-URL headers - Test Host header injection - Modify Accept, Content-Type headers - Test CORS with Origin header
CAIDO VS BURP SUITE#
Feature Caido Burp Suite ------- ----- ---------- Price Free + Pro ($) Free + Pro ($449/yr) Language Rust Java Speed Very fast Moderate UI Modern, clean Functional, dated Extensions Workflows BApp Store (huge) Scanner Coming/limited Comprehensive Intruder Automate Intruder Repeater Replay Repeater Memory Low High (Java) Learning curve Easy Moderate Maturity Newer Very mature Collaboration Coming Burp Enterprise Community Growing Very large
KEYBOARD SHORTCUTS#
Ctrl+I Toggle intercept Enter Forward intercepted request Delete Drop intercepted request Ctrl+R Send to Replay Ctrl+A Send to Automate Ctrl+F Search/filter Ctrl+L Clear history Ctrl+, Settings
TIPS#
- Much faster than Burp due to Rust backend - Lower memory footprint than Java-based tools - Define scope early to reduce noise - Use Match & Replace for persistent header injection - Automate is powerful but simpler than Burp Intruder - Great for API testing and quick manual testing - Export as cURL for scripting/automation - Combine with Nuclei for automated vuln scanning - Growing ecosystem; check for new workflows regularly - Free tier is generous for most pentest needs