Sie sind auf Seite 1von 16

Parsing Office Traffic:

Message Analyzer & Fiddler


Jingyu Shao
Software Engineer
Agenda
Message Analyzer
Whats Message Analyzer
Protocol analysis
Parsers available
Demo
Resources
Fiddler
Office Inspectors
Demo
Resources
Comparison and how to chose
What is Message Analyzer?
Message Analyzer Protocol analysis
Message Analyzer Parsers Overview
Protocol Analysis

Parsers for public protocols (e.g. HTTP, SOAP) and Windows protocols

Message Analyzer
Office Parsers Packages
Office & Exchange MAPI
SharePoint

14 parsers Skype for


Exchange Active MS-OXCDATA,
Sync Business
92 parsers MS-OXCROPS,
MS-LISTSWS, MS-OXCRPC,
MS-ADMINS, 4 parsers MS-OXCMAPIHTTP,
MS-ASCMD, 12 parsers
MS-WEBSS,
MS-ASHTTP, MS-CONFBAS,
MS-ASPROV, MS-SIPREGE,
Exchange Web MS-ASWBXML MS-TURN,
WOPI/FSSHTTP
Service MS-ICE,

5 parsers
MS-FSSHTTP,
35 parsers MS-FSSHTTPB, MS-
MS-OXWSCORE, FSSHTTPD,
MS-OXWSFOLD, MS-WOPI,
MS-OXWSSYNC,. FileSyncBasic
Demo
Office Parses Features

Message Recognition Binary XML decoding Validation*


* Not available for all parsers yet
WBXML decoder for EAS
Message Analyzer Resources
Download:
http://www.microsoft.com/en-us/download/details.aspx?id=44226
Operating Guide:
https://technet.microsoft.com/en-us/library/jj649776.aspx
Office Interoperability Blog:
http://blogs.msdn.com/b/officeinteroperability/
MA Blog:
http://blogs.technet.com/b/messageanalyzer/
Forum:
https://social.technet.microsoft.com/Forums/en-
US/home?forum=messageanalyzer
Agenda
Message Analyzer
Whats Message Analyzer
Protocol analysis
Parsers available
Demo
Resources
Fiddler
Office Inspectors
Demo
Resources
Comparison and how to chose
Fiddler Office Inspectors
WOPI/FSSHTTP Exchange MAPI

MS-FSSHTTP, MS-OXCDATA,
MS-FSSHTTPB, MS-OXCROPS,
MS-FSSHTTPD, MS-OXCRPC,
MS-WOPI MS-OXCMAPIHTTP,

Demo
Fiddler Office Inspectors Resources
Github Repos:
MAPIHTTP:
https://github.com/OfficeDev/Office-Inspectors-for-
Fiddler/tree/master/MAPIInspector
WOPI/FSSHTTP:
https://github.com/OfficeDev/Office-Inspectors-for-
Fiddler/tree/master/FSSHTTPWOPIInspector

Office Interoperability Blog:


http://blogs.msdn.com/b/officeinteroperability/
Agenda
Message Analyzer
Whats Message Analyzer
Protocol analysis
Parsers available
Demo
Resources
Fiddler
Office Inspectors
Demo
Resources
Comparison and how to chose
Comparison and how to choose

Capture Capture
Numerous transport protocols supported HTTP/S only
Protocol families supported Protocol families supported
Office & SP Office & SP (let us know if you want this)
EWS EWS (let us know if you want this)
EAS EAS
MAPI MAPI (HTTP)
WOPI/FSSHTTP WOPI/FSSHTTP
Skype for Business Skype for Business
Community Participation Community Participation
Parser source code Open Source in Github
Share through asset
Thank You!

Das könnte Ihnen auch gefallen