🛡️ Security Testers

ProxyCeptor for Security Testers: A Lightweight In-Browser Interceptor Next to Burp

In one paragraph

Security testers use ProxyCeptor as a lightweight companion to Burp Suite: persistent in-browser rules that swap object IDs, change roles in JSON responses, strip security headers or inject scripts, without routing traffic through a desktop proxy. For scanning, fuzzing and manual request repeating, Burp or ZAP remain the right tools.

Problems security testers run into

Proxy context switching

Jumping between the browser and Burp for small, repeated changes slows exploration.

Client-side trust issues

Many bugs appear when the UI trusts a response field such as isAdmin or price, and the tester needs to flip it persistently.

Scope-limited devices

Some in-scope clients (TV apps, kiosks) cannot use your proxy certificate.

Workflows that fix them

Response trust testing

Deep-merge { "user": { "role": "admin" } } into the profile response to see which admin UI and API calls the client unlocks, then test those calls properly in Burp.

IDOR exploration

Rewrite /users/1001/ to /users/1002/ for a whole browsing session with a URL rewrite rule, then record which responses leak data.

Header and CSP experiments

Remove or change response headers such as Content-Security-Policy or X-Frame-Options for a target pattern to test client behaviour. Header rules run through declarativeNetRequest.

Script injection for recon

Use Snippets to inject a helper script (for example, to log every postMessage) on pages that match a pattern.

Example

Flip a client-side role flag
JSON
{
"name": "Pretend admin (client trust test)",
"match": { "urlPattern": "*/api/me", "matchType": "wildcard" },
"response": {
"body": { "enabled": true, "mode": "merge-json", "mergeValue": "{ \"user\": { \"role\": \"admin\" } }" }
}
}

Frequently asked questions

Is ProxyCeptor a Burp Suite replacement?

No. Burp has the scanner, Repeater, Intruder and extensions that security work depends on. ProxyCeptor is a faster tool for persistent client-side changes and certificate-free devices. See ProxyCeptor vs Burp Suite.

Can I only use this on targets I am authorised to test?

Yes. Only intercept and modify traffic for systems you own or that are explicitly in scope of a programme or engagement.

Does ProxyCeptor send captured traffic to the cloud?

No. Captured traffic stays in the extension. Only rules you choose to save in a cloud workspace, and AI analysis you trigger with your own key, leave the browser.

Related guides

Try these workflows free

Create a free ProxyCeptor account to mock, delay, block and rewrite API traffic, then share the same rules with your team.