Mr.Trunk · @mrtrunk
5 followers · 11116 posts · Server dromedary.seedoubleyou.me

SecurityOnline: mitmproxy v10.0 releases: An interactive TLS-capable intercepting HTTP proxy securityonline.info/mitmproxy/

#webvulnerabilityanalysis #mitmproxy

Last updated 1 year ago

Adam ♿ · @voltagex
416 followers · 1719 posts · Server aus.social

Any experts here? I'd like to learn properly, I think.

I am trying to set up a transparent proxy on a VM to analyse traffic from other VMs.

forum.openwrt.org/t/transparen

#openwrt #firewall #netfilter #iptables #proxy #mitmproxy

Last updated 1 year ago

Matthias Eberl · @rufposten
4128 followers · 2699 posts · Server social.tchncs.de

In case anyone is trying to get a root certificate to work on Android 11 (for analysing traffic with eg. ):

This now seems to be the only working solution (except using ).
gist.github.com/pwlin/8a0d01e6

Later in that thread someone describes how it is possible to install the certificate permanently in the android system using .

#mitmproxy #magisk #workedforme #twrp

Last updated 1 year ago

kurth · @kurth
91 followers · 1460 posts · Server social.tchncs.de

since certain (cough) sites harden examing their network traffic in the chrome*and*firefox developer tools by means of some sort of targeted scripted ressource exhaustion, came on screen again. great tool for intercepting https traffic, python, reasonably performant even on lower end hardware

#mitmproxy

Last updated 1 year ago

po̊lættïx · @polettix
70 followers · 1378 posts · Server octodon.social

I purchased ProxyMan for my Mac with their generous student discount because it's cheaper than Burp Suite, and I can't/don't use my work licenses for self-directed research and academia.

It's nice. The UI/UX is intuitive and macOS-like, making it stand out for me against the likes of mitmproxy, Burp, and ZAP. It took a handful of straightforward in-app clicks to set the system proxy, trust their root CA certificate for specific domains, and pass-thru everything else.

My license also unlocked premium features for their mobile app, which I just learned of but am now interested in checking out. I'm glad there's still room for competition in the MITM space.

#ProxyMan #proxy #mitm #mitmproxy #burp #burpsuite #owasp #zap

Last updated 2 years ago

Underfl0w · @Underfl0w
41 followers · 25 posts · Server infosec.exchange

Published a blog on a my experience with new functionally. It helped me to quickly find an insecure S3 bucket being used by one of the apps I use on my iPhone. Check it out:
underfl0w.com/mitmproxy-iphone

#mitmproxy #wireguard #security #hacking #bugbounty

Last updated 2 years ago

Sasha · @ferrata
415 followers · 1346 posts · Server hachyderm.io

about , interactive HTTPS proxy

mitmproxy.org/

#til #mitmproxy

Last updated 2 years ago

Does anyone know how agent-based systems work? I mean where you have an agent running on your desktop, and it monitors connections being made, and then forces the client to connect to a local proxy agent listening on a port on the desktop? Thinks like GTB or Umbrella SWG?

These things will listen on a port. If you open your browser and make a connection, they will either skip the connection (based on rules) in which case the browser connects normally. Or if the agent does not "skip" your browser will be forced to connect to a port on the local agent instead. The local agent then makes the connection to the real website.

I don't quite get where they hook in for redirect that connection. Is that within the OS?

#proxy #windows #cisco #umbrella #mitmproxy

Last updated 2 years ago

Armin Preiml · @apreiml
25 followers · 18 posts · Server fosstodon.org

Shout-out to . It does not only have a great terminal UI, but also the docs are awesome.

Took me around 10 minutes from installation to intercepting API requests of an Android App on a rooted device.

#mitmproxy

Last updated 2 years ago

Ilias :verified_flashing: · @DM_Ronin
122 followers · 272 posts · Server mstdn.social

My work sometimes require a bit of Linux-based operations, particularly with tcpdump, tshark and openssl (in future maybe mitmproxy).

So I'm incredibly lucky to have this exceptional zine by @b0rk for free (thanks to ENUSEC 2021 contest) which saved me a lot of googling, and simply it's a very nice looking tutorial :ablobcathappypaws:

#network #Programming #FreeSoftware #FOSS #Linux #Tech #mitmproxy

Last updated 2 years ago

Victor Jalencas :verified: · @victor
45 followers · 35 posts · Server hachyderm.io

I'm using / mitmdump with some custom scripts to mess with cookies.

But after a few hours of running, it always runs out of file descriptors and requests start to fail, so I have to kill the process and start it again.

Seeing as is the epitome of stability, I was wondering if there is an equivalent tool that fulfills the same needs. That is, a proxy with which I can manipulate requests and their responses on their way out/in.

KTHXBAI

#mitmproxy #rustlang

Last updated 2 years ago

· @data0
60 followers · 145 posts · Server fosstodon.org

9 is here and the new mode is huge! Makes on mobile devices a whole lot easier.

mitmproxy.org/posts/releases/m

#mitmproxy #wireguard #debugging

Last updated 2 years ago

aeris 🏳️‍🌈 · @aeris
2513 followers · 47055 posts · Server social.imirhil.fr

@lucius @Fritange Là comme ça ne servira pas à grand chose.
Je dirais plutôt +, en bloquant les apps une à une et en regardant qui tag dessus !

#mitmproxy #afwall

Last updated 5 years ago

Matthias Eberl · @rufposten
3431 followers · 2236 posts · Server social.tchncs.de

Unheimlich, mal live zu sehen, wie oft ein normales Android im unbenutzten Zustand an Google telefoniert.

#mitmproxy

Last updated 6 years ago

Eliot Bendinelli · @bendineliot
97 followers · 328 posts · Server mamot.fr

Si vous aimez voir ce que vos apps préférées partage comme données Privacy International à rendu public son toolkit pour analyser des applications sous Android (d'une façon un peu différente de @exodus ): privacyinternational.org/node/

et au programme, y'a de quoi s'amuser.

#vm #mitmproxy

Last updated 6 years ago