13 ms·
Mitmproxy – Open-source console-based proxy
- eapen 9y agoThis tool recently helped me troubleshoot a bug I was facing and unable to solve due to the lack of Safari's development tools. Here's a link for anyone interested: http://eapen.in/mitmproxy-for-troubleshooting/ http://eapen.in/mitmproxy-for-troubleshooting/
- mpeg 9y agoI love mitmproxy, super easy to use (and to install an interception certificate) and the scripting support makes it very useful for pentesting iOS app traffic etc where I can't easily modify the client
- cowabungamann 9y agohow do disable certificate pinning on iOS?
- mpeg 9y agoHaven't had to as the apps I targeted weren't using it. Can't think of an obvious way without rooting the device though...
- bitexploder 9y agoThat is because there isn't a good solution. You can get away with repackaging an IPA and hand modifying the binary depending on how they are performing the pinning, but it is always going to be time consuming to do it this way. If you are serious about tinkering you pretty much need a jailbroken device, which is getting harder to maintain by the year.
- jenscow 9y agoJust what I was looking for. All I wanted to do was change a request header for one host. After ~15 minutes I now have a transparent MITM https proxy - and I didn't even have to google the openssl command. Edit: Also, the documentation is excellent as the software.
- CameronBanga 9y agomitmproxy is great for iOS and Android pen testing. A must have tool.
- deleted 9y ago[deleted]
- pvg 9y agoMany previous discussions: https://hn.algolia.com/?query=mitmproxy&sort=byPopularity&prefix=false&page=0&dateRange=all&type=story https://hn.algolia.com/?query=mitmproxy&sort=byPopularity&pr...
- diegorbaquero 9y agoMitmproxy is amazing! And you can get it easily in macOS with brew. Highly recommended
- sheharyarn 9y agoI love Mitmproxy and how easy it is to use! One of my favorite pentesting tools!
- brazzledazzle 9y agoThis tool has really helped me on several occasions with a wide variety of issues up and down the stack. Even with debugging web apps because while the chrome Dev tools are awesome they (at least at the time as far as I know) didn't expose the initial headers/network exchange for certain types of auth like NTLM.
- emj 9y agoMitmproxy is nice, but I think dev tools have become alot better, I discovered that because my standard work horse Chrome+Wireshark is very fincky with SSL: SSLKEYLOGFILE=$HOME/ssl_crt_dbg google-chrome --user-data-dir=TEMPUSER Then you configure wireshark SSL decoding with with pre master key file as "ssl_crt_dbg", it fails too often for me. Now days I use remote-debugging and Python a lot: $ google-chrome --remote-debugging-port=9222 import PyChromeDevTools chrome = PyChromeDevTools.ChromeInterface(host="localhost", port=9222) chrome.Network.enable() while True: print chrome.wait_message(timeout=0.1) But the simplicity of a Mitmproxy is almost as great as wireshark.
- pimlottc 9y agoCan you explain more what you're doing with the python code?
- phsource 9y agoOh my gosh... don't get me started on NTLM. Chrome Network Tools doesn't expose it at all, so the proxy was a lifesaver in our case. We've shifted to using https://github.com/joeferner/node-http-mitm-proxy https://github.com/joeferner/node-http-mitm-proxy as a part of WrapAPI Proxy (https://wrapapi.com/proxy https://wrapapi.com/proxy), which is a zero-install proxy in the style of mitmproxy and Charles. The node proxy is really great in that it's fully extensible, allows you to generate certificates, and filter/save the kinds of traffic you get to simple JSON structures. We've found it to be a huge boon in development, but it's clearly inspired by mitmproxy (which predates node), so credit where it's due.
- mrtksn 9y agoIt's not just a console, it also has a web based interface: http://docs.mitmproxy.org/en/stable/mitmweb.html http://docs.mitmproxy.org/en/stable/mitmweb.html
- hans_mueller 9y agoI'd say, it's not just a web based interface, it also is a console.
- c7h 9y agoone of the best tools for reverse engineering mobile apps. I'm just having problems when certificate pinning is enabled. Does anyone have an idea (or even a solution) how to deal with that?
- pnutjam 9y agowhat kind of problems?
- gregsadetsky 9y agoCertificate Pinning (in apps) stops mitmproxy from proxying traffic to the servers you're mostly interested in proxying... see: http://docs.mitmproxy.org/en/stable/certinstall.html#certificate-pinning http://docs.mitmproxy.org/en/stable/certinstall.html#certifi...
- s0l1dsnak3123 9y agoI'd also love to know if there's a solution for this problem!
- bitexploder 9y agoThere is. It depends on the mobile OS and device. We deal with this routinely. Solutions tend to vary. On iOS just use SSL kill switch (if you are jailbroken). If you are not jailbroken you don't have a lot of options. On Android there are some well documented approaches. Usually decompiling the app and adding to the local app's cert store will work and then rearchive and sign it. Function hooking key network calls can work as well. It is pretty much required that if you want to do serious tinkering or assessment you need a jailbroken or rooted device. This can be a significant effort investment, but once done is generally reliable.
- scandinavian 9y agoIt's been a while, but when I have been reversing android apps with certificate pinning in the past, I had the most luck with decompiling the apk with apktool, removing the certificate pinning in the samli bytecode, then recompiling and signing the apk again. For iOS, I know there are jailbreak cydia tweaks that try to disable certificate pinning, but I have no experience with this.
- bitexploder 9y agoDon't forget mitmdump. It is a great way to log sessions and chain to other proxies at the same time. Also, mitmdump is one of the best and fastest ways to get ahold of web requests with Python to modify it on the fly. http://docs.mitmproxy.org/en/stable/mitmdump.html http://docs.mitmproxy.org/en/stable/mitmdump.html I have been using mitmproxy over Burp for day to day web app hacking these days. But we still use Burp scanner for lots of chores. I almost always chain through both to then go back in and use Burp features missing in mitmproxy (exploring site contents, etc.). But those are edge cases mostly needed for professional use and not for tinkering.
- nopcode 9y agoI don't understand how this can be faster or more friendly than using Burp. Would you mind sharing an example flow?
- bitexploder 9y agoI just like working in terminal. Some things I can do faster in mitmproxy (filtering with lots of constraints, shooting response or request data to a pipe). It has a mutt like interface so if mutt seems fast and intuitive then mitmproxy will feel similar. I have spent a lot of years thrashing around in the Burp GUI and mostly I don't need all the features all the time :) Things that are a few clicks in Burp are a few terse keystrokes or key presses in mitmproxy. IDK, give it a shot and see if it makes sense . Most of our team just sticks with Burp FWIW.
- ijustdontcare 9y agohttps://docs.mitmproxy.org/en/latest/mitmproxy.html https://docs.mitmproxy.org/en/latest/mitmproxy.html Nice TLS work
- humanjvm 9y agoI've been using mitmproxy to inspect HTTPS traffic. Are there any Chrome/Wireshark configurations to allow me to inspect HTTPS with Wirshark?
- platz 9y agoMitmproxy works pretty well for HTTPS - but it doesn't seem to generate HTTPS certs as well as Fiddler does
- mhils 9y agoMitmproxy dev here - please feel free to file a bug on GitHub if you have a reproducible example where we fail. :)
- Lightbody 9y agoAlthough I don't contribute to it anymore, I worked on a similar project that seems to have some continued activity: https://github.com/lightbody/browsermob-proxy https://github.com/lightbody/browsermob-proxy It's Java-based and forked out from some old MITM code from Selenium. It has a bunch of APIs for manipulating traffic, tweaking DNS resolution, rewriting content, etc. Just passing along in case anyone is looking for alternatives.
- abraae 9y agoI was just looking for something like this. Googling led me to Charles proxy, which seems a pretty capable tool, and I'm growing fond of it though the Java UI is jarringly ugly. Does anyone have any experience with charles vs mitmproxy?
- jwilk 9y agoBeware that it listens on all interfaces by default: https://github.com/mitmproxy/mitmproxy/issues/1293 https://github.com/mitmproxy/mitmproxy/issues/1293 I learned this the hard way. If you run a proxy on an unfirewalled machine with public IPv4, it's going to be abused really fast. :-(