Mitmproxy 7.0
mitmproxy.org
mitmproxy.org
I'm slightly too much of a GUI person to use it in a "explorative" phase, then I'm more a fan of Charles/Proxyman, but whenever I wanna modify the traffic or do some scripting to i.e log certain traffic, I reach for Mitmproxy.
There is a subscription for Pro features, but most users don't need it - you can do most things common use cases need (all interception & inspection, manual traffic rewriting, almost everything that doesn't need advanced configuration) with just the free version. It's also 100% open-source, even the paid bits.
That said, imo subscriptions provide lots of benefits as a model for both sides. Basically by aligning how much value users get with how much they pay - cheap for quick use, expensive for extensive heavy use, strong incentive to fix bugs & support existing users instead of chasing the next shiny launch.
I hear your point about approvals anyway. If subscriptions are impossible, I can do one-off indefinite licenses - send me an email at tim@httptoolkit.tech
That is the thing missing from Charles for our QA folks.
It is highly annoying to have to hook the iOS app up to Xcode just to be able to see the wss traffic when tracking down a bug.
Tracked here: https://github.com/httptoolkit/httptoolkit/issues/36. You can subscribe to the GH issue for updates if you're interested.
The newer "Fiddler Everywhere" might also be able to do it, possibly even better, but I dislike the UI and I'm used to Classic so I've stuck to that.
I get what you mean about aligning incentives. I do want to support devs in a way that these types of projects are sustainable, but the way other products shut off access to your stuff once you stop paying make subscription models an unnecessary risk. Having a free tier like yours really helps.
Generally I try to buy the tool and three years of support upfront. Otherwise I'm at risk of it being deleted because we can't have software if it doesn't have a support contract 'in case there are bugs'. These rules are written by cretins in 'IT' and accountants.
Anyway, put the bit about flexible licencing on your order page.
This is specifically to prevent mitm attacks on the app.
You have to get the APK and mess with the manifest to bypass that. And bypassing pinning is even more difficult.
Edit: pimterry below me explains it better: https://news.ycombinator.com/item?id=27857429
I find this a problem because MITM isn't always bad. It can be used for inspecting apps for tracking and other malicious practices by app makers.
I was unaware of this as I do little interaction with Android. TIL.
And yes, I do appreciate being able to MITM all kinds of apps, especially ones that talk to a device I own to be able to add functionality/integrations not supported by the manufacturer.
I also see the benefit of preventing MITM, in our case, it is because we intentionally offload logic onto the client to simplify GDPR/CCPA compliance(can't store what you don't collect) among other design decisions which mean a malicious client could circumvent rulesets we have in place.
Note that your HTTP certificate pinning is easily bypassed on both Android and iOS by a determined actor. A malicious client will circumvent rulesets you have in place. If you do not validate client inputs, you will be exploited.
Indeed, it doesn't really differ that much from DRM. It's an attempt by the author of the software to impose control over the user, preventing them from using the software how they see fit.
If I've trusted my own root, and you've decided you wont trust anything on my root, I now need to take steps to disable the certificate validation routines completely on my device, in order to bypass your restrictions.
I get that there are cases where it's extremely valuable (and in some cases, required by regulators) to enforce certificate pinning, e.g. mobile banking apps, but there are plenty of cases where it's just bullshit DRM (e.g. gym app that performs unauthenticated requests to an https endpoint to retrieve occupancy stats on each of the chain's gyms).
In the latter case, all I wanted was to track how busy the gym was over time, so I could adjust my schedule to enable me to go when the gym was quiet. I couldn't be bothered to jailbreak my iphone and install nabla-c0d3/ssl-kill-switch2, so instead I quit my gym and switched to one that was less stupid.
I agree. That is why there is still serverside enforcement, but performance tuning is heavily cache based and many client request strategies are specifically designed to not bust the cache and cause a high latency call.
Also, in our case, the app is the product. I'm not very positive on it's market fit, so you may never hear of it if it launches to a fizzle, as I suspect is a large probability.
The venue's network admin said they weren't filtering anything outbound to the Internet. We could access websites from the iPad just fine. Same w/ Facebook, Youtube, etc.
I put up Mitmproxy, an adhoc Wi-Fi network on a second Wi-Fi NIC, a DHCP server, and iptables NAT on my laptop. I set the iPad to use my adhoc SSID and my machine as an explicit HTTP proxy. My intention was to snoop on the traffic to determine what Mevo was using for criteria to consider being "connected".
For whatever reason the Mevo app just started working in this configuration. I ended up sticking a spare Wi-Fi router and a PC w/ Mitmproxy installed in the venue for the duration of the event. I never did figure out what the Mevo app didn't like about the venue's network.
This looks to cover it pretty well: https://www.guardsquare.com/blog/leveraging-infoplist-based-...
I had fun reverse engineering app APIs a few years back, but I looked into it again more recently and found that Android has started pinning certificates by default even on apps that didn't pin anything themselves. I also had trouble getting my custom certificate to be used at all, when it used to be pretty easy.
Can Frida still bypass pinning, even this new default one, or is it done at OS level?
* By default, all modern Android apps only trust CA system certificates, and on a normal device you cannot change those.
* You can change system certificates on rooted devices and most (but not all) emulators.
* Apps can opt-in to trusting user-installed CA certificates within their manifest config, but almost all don't.
If you're on a non-rooted device, the only way to MITM traffic is by modifying the application itself, so that it opts into trusting your cert. You can either inject Frida-Gadget to do that, do it manually, or use https://github.com/shroudedcode/apk-mitm which tries to do it automatically (but it's a bit hit & miss whether it works).
If you're on an emulator/rooted device, it's totally possible, see https://httptoolkit.tech/blog/intercepting-android-https/#in... for how that works.
That's separate to explicit certificate pinning. That's also possible on Android (with some standard config settings, or manually in code) although it's got much less popular I think since the defaults were tightened up. In that case you do usually need Frida, and it's generally easiest to just use a rooted device. I wrote a blog post about exactly how to do that last week: https://httptoolkit.tech/blog/frida-certificate-pinning/#how...
Sure you can. It's in a settings pane, Settings -> Security -> Encryption and Credentials -> Install a certificate.
MDM profiles can also install certificates.
There's pretty much zero possibility of this being removed as a feature as it is essential to a wide variety of corporate environments.
This was changed back in 2016, the original announcement post has some good details: https://android-developers.googleblog.com/2016/07/changes-to...
Enterprises can add certificates to the system store I believe, but only as part of the initial provisioning of the device, and only for enterprise-managed devices.
There's some management modes which don't require that but they don't offer the ability to install system certs.
I've been on a crusade the past few years to try and get my self-signed CA onto "smart" devices in my home, but with some it's difficult or I risk damaging expensive hardware.
I've tried various ARP poisoning techniques and such in the past with limited success.
1. Getting the IoT traffic to your proxy machine. As you say this is fairly trivial when you can set a proxy, but a bit tricky otherwise as you need to run mitmproxy in transparent mode (https://docs.mitmproxy.org/stable/concepts-modes/). With some luck you can set a custom gateway on your device which simplifies the setup, otherwise you need to have the capability to set iptables rules on the router. I personally have a small $20 OpenWRT router dedicated for that. Alternatively you can run your own DNS server and point everything to mitmproxy. v7 now also supports SNI/host-header based proxying! The good news is that this setup is the same for all your devices and once it works, it works.
2. Getting the device to trust your (personal) mitmproxy CA cert. This one really depends on the particular IoT device and may involve some serious reverse-engineering if you are unlucky. I wish there would be a more of a "I should be able to inspect my own traffic" movement, but it's a tricky problem to solve.
The second part is the challenge, and for some devices I've been unable to embed my own CA. I was hoping there was a proxy trick or some magic sauce I was missing. Perhaps where DHCP could automatically configure clients with a (insecure) proxy or something along those lines?
Nope, you're not missing anything.
I'm working on a similar problem (https://github.com/elahd/esp2ino/issues/16) with a project I maintain to sideload IoT device firmware (https://github.com/elahd/esp2ino).
I've been using both mitmproxy and IOXY (https://github.com/NVISOsecurity/IOXY), an intercepting proxy made specifically for MQTT. IOXY is a small, less mature project, but it's definitely worth checking out as a compliment to mitmproxy. Many devices managed via AWS IoT phone home over MQTT and, my limited experience aside, it looks like many don't bother validating certificates when authenticating over this protocol.
Suppose I have set an interception filter and I am viewing a live packet. I am about to edit it, etc.
But when a new packet arrives, the text UI moves to the new packet! I have lost the packet that I was looking a few seconds ago.
Is this an issue in mitmproxy or am doing things the wrong way?
Any plans for a recommended shortcut setup again?
Not writing 30 characters for copy body of a POST request, but fast key bindings.
If you have specific feedback about where the keyboard UX sucks I'd be happy if you could open an issue on GitHub so that we can take a closer look!
The setup is: A client (dev machine or pipeline) running tests that communicate to a Windows VM that hosts the app under test. The client RPCs to call automation APIs on the host/server.
However I couldn't get both communicating and using mitmproxy to observe traffic to work at the same time.
I used to do all my rewrite via a proxy but it stopped being particularly useful when https became almost universal.
Edit. Typo.
Anyone interested in sharing use-cases where it has helped you?
Development:
- Debug your own apps/devices (which do not come with Chrome Devtools).
- Simple Python scripts to replace/inject website content. (https://docs.mitmproxy.org/stable/addons-overview/)
- Capture a web page/API and then replay the responses offline. (https://docs.mitmproxy.org/stable/overview-features/#server-...).
- Replay requests for testing. (https://docs.mitmproxy.org/stable/overview-features/#client-...)
Privacy:
- Figure out what your Covid app is sending out (https://seancoates.com/blogs/how-i-helped-fix-canadas-covid-...)
- Look at how evil IoT devices for pets are (https://www.nytimes.com/2018/12/11/realestate/spying-on-the-...)
- Generally find more evil stuff (https://mitmproxy.org/publications/)
Security:
- Reverse-engineering custom binary protocols is never fun, but with mitmproxy you can at least write custom contentviews to dissect stuff. (https://github.com/mitmproxy/mitmproxy/blob/main/examples/ad...)
- Fiddle with generic TLS-protected TCP streams. (https://github.com/mitmproxy/mitmproxy/blob/main/examples/ad...)
- Dump TLS master secrets for WireShark. (https://docs.mitmproxy.org/stable/howto-wireshark-tls/)
Even if we don't need to manipulate the data, it's a very useful tool for watching requests go back and forth.
One that sticks out in my mind is trying to receive Slack webhooks in Mattermost. I was unaware of Slack’s new BlockKit message format until I saw what was being sent. Then I wrote a simple python script to transform the payload, all within mitmproxy. It’s not the most efficient long term solution, but the fact I could diagnose and resolve the issue with a single tool, all within a few hours of first discovering it, was very satisfying.
Here’s the result for anyone interested (warning: it’sa quick hack, not a polished/maintained project)
https://github.com/thinkmassive/mattermost-webhook-slack-pro...
Edit: this doesn’t use TLS at all. I understand that’s probably the primary use case for the tool, but I thought this was a cool example of other ways it can be useful too.
Thank you for your work, @mhils & the team. Enjoy your moments of glory on HN :)
The biggest problem was the server only syncing the player position every second or so which means my middleware has can only provide exact calculations when I stand still. Solving this would require reading the process memory but that is exactly what I wanted to avoid :/