3 ms·
even the approach that charles takes for intercepting TLS traffic is a bit old school (proxies, fake root certs etc.) - cool kids use eBPF https://mitmproxy.or
by Maxious 1y ago
even the approach that charles takes for intercepting TLS traffic is a bit old school (proxies, fake root certs etc.) - cool kids use eBPF https://mitmproxy.org/posts/local-capture/linux/ https://mitmproxy.org/posts/local-capture/linux/
- stavros 1y agoI can see how you don't need a proxy any more, but I don't see how you can bypass TLS without fake root certs, even with eBPF.
- Tokumei-no-hito 1y agonew to this program as well but looks really nice. i think it is still a proxy though unless I’m missing something (beyond the name lol). [here's a section on macos dealing with certs](https://mitmproxy.org/posts/local-capture/macos/ https://mitmproxy.org/posts/local-capture/macos/)
- beaugunderson 1y agohere is one example: https://github.com/gojue/ecapture https://github.com/gojue/ecapture in short, you can hook calls within SSL libraries (like OpenSSL)
- stavros 1y agoSure, but that very much depends on the application, no? What if it's statically linked its SSL lib?
- beaugunderson 1y agoyou wanted to know how people are bypassing the need for a certificate with eBPF, that is how