3 ms·
The normal chain is app > server. Mitmproxy acts as a middleman. Typically you’ll run it on another device on the same network. app > proxy > server Which mea
by bransonf 7y ago
The normal chain is app > server.
Mitmproxy acts as a middleman. Typically you’ll run it on another device on the same network.
app > proxy > server
Which means every time the app makes a GET request (for example) the proxy can log the url/ip as well as the parameters passed to the server.
Then, to get the data yourself, you use a web client like Curl (or Requests in Python) and send the same headers/auth/parameters as the app did. But now instead of returning it to the app, it’s in a format you can store/manipulate.
- thepete2 7y agoI understand that. My question is since this is https - encrypted http - how do you decrypt the traffic? Is there something running on the phone too? Otherwise you would need the server's private key, right?
- nicksantamaria 7y agoI haven't done this myself, but I assume you would install the certificate mitmproxy uses on your phone. That would result in a successful handshake