Release of the HTTPS analyzer Mitmproxy 11 with HTTP/3 support

The release of the Mitmproxy 11 project has been announced, which enhances the toolkit for intercepting traffic within connections established via HTTPS with capabilities for inspection, modification, and traffic replay. The primary purpose of Mitmproxy is to facilitate traffic monitoring in corporate systems and diagnose issues, such as identifying hidden network activity of applications. The project's source code is written in Python and is distributed under the MIT license.

To analyze HTTPS traffic, Mitmproxy is deployed on a transit node, where it intercepts client requests and relays them as requests sent by itself to the target. server. During a client session, Mitmproxy establishes a regular HTTPS connection with the requested server while creating a fake connection to the client on behalf of the target server with a spoofed SSL certificate generated on-the-fly. Incoming traffic from the client is redirected to the target server, and the received responses are relayed back to the client.

Release of the HTTPS analyzer Mitmproxy 11 with HTTP/3 support

To redirect traffic through Mitmproxy, several methods are supported, such as specifying the Mitmproxy address as an HTTP proxy in browser settings, operating as a SOCKS5 proxy, using it as a reverse proxy in front of an HTTP server, and establishing a transparent pass-through using packet filtering rules or routing wrapping. To prevent the spoofed certificate used for the client connection from triggering security warnings in the browser, users are advised to install the Mitmproxy root certificate, which can be done manually or by visiting a special host mitm.it in the browser.

Release of the HTTPS analyzer Mitmproxy 11 with HTTP/3 support

Mitmproxy supports HTTP/2, HTTP/3, Websockets, normalizing packet order in the stream, connecting handler scripts for on-the-fly traffic modification, saving requests for further replay, generating for TLS certificates for intercepted sessions, cleaning up modification time headers to disable client-side caching, reverse proxy mode to redirect traffic to the server, blocklists for filtering specific requests, selective request forwarding (including serving local files in response), and modifying content and headers based on regular expressions. For traffic analysis, a command-line utility similar to tcpdump called mitmdump and a web interface called mitmweb are provided.

Release of the HTTPS analyzer Mitmproxy 11 with HTTP/3 support
Release of the HTTPS analyzer Mitmproxy 11 with HTTP/3 support

A key improvement in the new version is full support for the HTTP/3 protocol, which uses the QUIC (Quick UDP Internet Connections) protocol as its transport for HTTP/2 (QUIC is an overlay on the UDP protocol that supports multiplexing multiple connections and provides encryption methods equivalent to TLS/SSL). In Mitmproxy, HTTP/3 can be used for both transparent traffic interception and operation as a reverse proxy. HTTP/3 interception has been tested in Firefox, Chrome, and various versions of cURL.

Other notable changes in the new branch relate to enhanced DNS support in the context of placing DNS records for HTTPS and ECH (Encrypted Client Hello). The new version adds support for requesting DNS records other than A/AAAA (for example, in ECH, encryption public key information is transmitted in HTTPSSVC DNS records). An ECH key cleaning mode has been added from HTTPS records in DNS. The DNS library has been transitioned to Hickory, developed in Rust and supported by the Let’s Encrypt project. Support for DNS-over-TCP has been added. An option to disable processing settings from /etc/hosts has been implemented.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster