Mitmproxy 5.3
github.com
github.com
This release continues our attempts to become a bit more friendly to new users. Our docs now include a beginners guide created by our GSoC student this summer, which hopefully lowers the entry barrier a bit. We still want to improve this substantially, but hey here's a first iteration. :)
Happy to answer any questions!
Looks like a really powerful tool, must make time to learn more about it!
Basically the same things you would use Burp for, except mitmproxy has two important advantages:
1. Supports a SOCKS5 mode and has much better support for intercepting non-HTTP TCP traffic.
2. Easier to extend quickly via Python scripts.
Not really sure if an account/EULA is actually required for Burp, it's been a while since I looked at it. I just remember a window popping up on first run in my Kali VM, me looking at it and deciding to look for alternatives.
But we ended up switching to our mitm server since it's pretty easy to serve http and you just set http_proxy in all relevant application environments and you're done!
I would also recommend people look at Hetty which I just learned about this week. I have no connection to it. https://github.com/dstotijn/hetty/releases
1. This uses python to allow easy custom scripts. If they instead had wanted to offer the same functionality in a typed language, what would have been the easiest way to do that? Golang?
2. The docs are very cool - they have demo “videos” that actually have selectable text, I haven’t seen that before (via https://asciinema.org)
For mitmproxy that would be achieved like this: https://docs.mitmproxy.org/stable/concepts-certificates/
It's also very nice to intercept app traffic. Some use cert pinning, so the custom certificate won't work.
This will fail in some cases when the application is obfuscated or uses a non-standard pinning mechanism. In this case you can decompile the application to determine the methods used to accomplish the pinning and use frida (https://frida.re) directly in order to manually override them.
mitmproxy --mode reverse:http://example.com --tcp-hosts example.com
curl http://localhost:8080/
There's still quite a bit we want to improve on (e.g., our protocol detection currently fails for protocols that start with a server-side greeting), but the basic TCP viewing functionality is there. :)https://gitlab.com/wireshark/wireshark/-/wikis/TLS#using-the...
But it does look like a cool project.
Thank you so much for your work. What is the best way to donate to your project?
“Use the cloud,” they said.