I've stuck it on pastebin instead of in this comment, so it doesn't spoil it for anyone not looking.
From there you basically only need curl.
curl --user user:pw --digest does digest authentication.
curl --verbose will show what headers are being sent down from the server.
curl --headers 'Cookie: blah' will send a header back.
So no special tools required.
Once I figured out what to do, it was only a matter of finding the right tool to do it. I didn't realize curl could [edit: --redacted--] (cool!), but I used OWASP ZAP and did a [edit: --redacted--]. Same method, different tool. Btw, thank you for explaining the curl options, I normally don't use curl much, but apparently I should :)
EDIT: Redacted stuff so as not to ruin the fun for others