docs

Comparer

Diff two responses by line, word, or character (or by structure), mask the tokens that cause false positives, and confirm blind injection from a baseline/true/false triple.

Comparer diffs two HTTP responses so you can see exactly what changed between two requests. Pick two flows (filter them with a query) or paste content directly.

The Comparer view diffing two responses side by side
Diff two responses at line, word, or byte granularity — and confirm blind injection from a baseline/true/false triple.

Diff modes and views

Diff at line, word, or character granularity. View the result three ways:

  • Diff — a git-style view with added / removed / changed lines and counts.
  • Parsed — header summary plus syntax-highlighted body panels.
  • Hex — a byte-level diff that highlights the differing ranges ("N bytes differ").

Hugin also scores how similar the two responses are, with a match count and a structured list of differences.

Compare structure, not bytes

A line or character diff reads the body as plain text. When the body has structure, tell Comparer to compare the structure instead — reordered fields, reindented markup, and a token that changes in an attribute stop counting as changes. Set the body type to json, html, xml, or binary and the similarity score follows whichever comparison you pick.

JSON

Parses both bodies and compares the set of field values. Two responses with the same fields in a different key order score as identical, so only a real value or field change registers. Falls back to a text diff if a body isn't valid JSON.

HTML

Compares the tag skeleton — the sequence of tag names — and ignores attribute values and text. A rotating CSRF token in a hidden field, a changing nonce, or edited copy won't read as a difference; an added or removed element will. Use it when structure is the signal and the text is noise.

XML

The same tag-skeleton comparison as HTML — structure only, attribute values and text ignored.

Binary

For non-text bodies like images or octet-streams: compares the two for exact equality and by size. No structure is read — you get same-or-different plus the length gap.

Mask out the noise that fakes a difference

The single biggest source of false positives is content that changes on every response: CSRF tokens, timestamps, nonces, request ids, view-state. Left in, they dominate both the diff and the similarity score, and the change you came for hides in the churn.

Hand Comparer a list of regex patterns (ignore_patterns) and it replaces every match in both responses with a placeholder before it diffs or scores them. Mask the token, the timestamp, the nonce, and what's left is the change you're hunting. Patterns that don't compile are skipped, so one bad regex never aborts the comparison.

This pays off most in blind detection: a value that differs on every response can swallow the true/false similarity gap and flip the verdict. Mask it, and the gap reflects only the injection.

More comparison options

Drop more headers

Comparer already ignores the volatile headers that always differ — Date, Set-Cookie, ETag, Last-Modified, Age, Expires, and the X-Request-Id / X-Correlation-Id / X-Trace-Id family — so they never show as differences. Add your own with excluded_headers.

Ignore case

ignore_case compares the two bodies case-insensitively.

Normalize whitespace

normalize_whitespace collapses runs of spaces, tabs, and newlines to a single space, so a reindented or reflowed body isn't flagged as changed.

Timing gap

Comparer flags a response-time gap over one second as one of the differences — a cheap signal when you're watching for time-based blind injection.

The structure modes and the masking patterns travel in the request you send to Comparer's API, not in the GUI toolbar. In the window you get the visual diff, the Parsed and Hex views, the similarity score, and blind detection. Comparer is also an MCP tool, so an AI agent can run a compare, a blind-detect, or a similarity check for you.

Blind injection detection

Give Comparer a baseline, a true response, and a false response and it tells you whether the endpoint is vulnerable, with a confidence and the true/false similarity gap — the fast way to confirm a blind SQLi or boolean-based bug without eyeballing diffs.

If the responses carry per-request tokens, mask them first so the gap reflects the injection, not the noise.

Swap sides, sync-scroll, and keep multiple comparisons in tabs. "Explain differences" hands the diff to the Copilot (Pro).

Last updated 2026-06-17.