forked from mitmproxy/mitmproxy
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge branch 'master' of ssh.github.com:cortesi/mitmproxy
- Loading branch information
Showing
15 changed files
with
90 additions
and
24 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -10,3 +10,7 @@ body { | |
.nowrap { | ||
white-space: nowrap; | ||
} | ||
|
||
h1 { | ||
line-height: 1.1; | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,54 @@ | ||
This walkthrough illustrates how to set up transparent proxying with mitmproxy. We use VirtualBox VMs with an Ubuntu proxy machine in this example, but the general principle can be applied to other setups. | ||
|
||
1. **Configure VirtualBox Network Adapters for the proxy machine** | ||
The network setup is simple: `internet <--> proxy vm <--> (virtual) internal network`. | ||
For the proxy machine, *eth0* represents the outgoing network. *eth1* is connected to the internal network that will be proxified, using a static ip (192.168.3.1). | ||
<hr>VirtualBox configuration: | ||
<img src="@!urlTo('tutorials/transparent-dhcp/step1_vbox_eth0.png')!@"/><br><br> | ||
<img src="@!urlTo('tutorials/transparent-dhcp/step1_vbox_eth1.png')!@"/> | ||
<br>Proxy VM: | ||
<img src="@!urlTo('tutorials/transparent-dhcp/step1_proxy.png')!@"/> | ||
<hr> | ||
2. **Configure DHCP and DNS** | ||
We use dnsmasq to provide DHCP and DNS in our internal network. | ||
Dnsmasq is a lightweight server designed to provide DNS (and optionally DHCP and TFTP) services to a small-scale | ||
network. | ||
|
||
- Before we get to that, we need to fix some Ubuntu quirks: | ||
**Ubuntu >12.04** runs an internal dnsmasq instance (listening on loopback only) by default | ||
<a href="https://www.stgraber.org/2012/02/24/dns-in-ubuntu-12-04/">[1]</a>. For our use case, this needs to be | ||
disabled by changing <br>`dns=dnsmasq` to `#dns=dnsmasq` in */etc/NetworkManager/NetworkManager.conf* | ||
and running `sudo restart network-manager` afterwards. | ||
- Now, dnsmasq can be be installed and configured: | ||
`sudo apt-get install dnsmasq` | ||
Replace */etc/dnsmasq.conf* with the following configuration: | ||
<pre>\# Listen for DNS requests on the internal network | ||
interface=eth1 | ||
\# Act as a DHCP server, assign IP addresses to clients | ||
dhcp-range=192.168.3.10,192.168.3.100,96h | ||
\# Broadcast gateway and dns server information | ||
dhcp-option=option:router,192.168.3.1 | ||
dhcp-option=option:dns-server,192.168.3.1 | ||
</pre> | ||
Apply changes: | ||
`sudo service dnsmasq restart` | ||
<hr> | ||
Your proxied machine's network settings should now look similar to this: | ||
<img src="@!urlTo('tutorials/transparent-dhcp/step2_proxied_vm.png')!@"/> | ||
<hr> | ||
|
||
3. **Set up traffic redirection to mitmproxy** | ||
To redirect traffic to mitmproxy, we need to add two iptables rules: | ||
<pre class="terminal"> | ||
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 \ | ||
-j REDIRECT --to-port 8080 | ||
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 443 \ | ||
-j REDIRECT --to-port 8080 | ||
</pre> | ||
|
||
4. If required, <a href="@!urlTo('ssl.html')!@">install the mitmproxy | ||
certificates on the test device</a>. | ||
|
||
5. Finally, we can run <code>mitmproxy -T</code>. | ||
The proxied machine cannot to leak any data outside of HTTP or DNS requests. | ||
|
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters