Exemple #1
0
    def socks_connect(self, connect_to):
        try:
            client_greet = socks.ClientGreeting(
                socks.VERSION.SOCKS5,
                [socks.METHOD.NO_AUTHENTICATION_REQUIRED])
            client_greet.to_file(self.wfile)
            self.wfile.flush()

            server_greet = socks.ServerGreeting.from_file(self.rfile)
            server_greet.assert_socks5()
            if server_greet.method != socks.METHOD.NO_AUTHENTICATION_REQUIRED:
                raise socks.SocksError(
                    socks.METHOD.NO_ACCEPTABLE_METHODS,
                    "pathoc only supports SOCKS without authentication")

            connect_request = socks.Message(
                socks.VERSION.SOCKS5,
                socks.CMD.CONNECT,
                socks.ATYP.DOMAINNAME,
                connect_to,
            )
            connect_request.to_file(self.wfile)
            self.wfile.flush()

            connect_reply = socks.Message.from_file(self.rfile)
            connect_reply.assert_socks5()
            if connect_reply.msg != socks.REP.SUCCEEDED:
                raise socks.SocksError(connect_reply.msg, "SOCKS server error")
        except (socks.SocksError, exceptions.TcpDisconnect) as e:
            raise PathocError(str(e))
Exemple #2
0
def test_message_unknown_atyp():
    raw = tutils.treader(b"\x05\x02\x00\x02\x7f\x00\x00\x01\xDE\xAD\xBE\xEF")
    with pytest.raises(socks.SocksError):
        socks.Message.from_file(raw)

    m = socks.Message(5, 1, 0x02, ("example.com", 5050))
    with pytest.raises(socks.SocksError):
        m.to_file(BytesIO())
Exemple #3
0
    def __call__(self):
        try:
            # Parse Client Greeting
            client_greet = socks.ClientGreeting.from_file(
                self.client_conn.rfile, fail_early=True)
            client_greet.assert_socks5()
            if socks.METHOD.NO_AUTHENTICATION_REQUIRED not in client_greet.methods:
                raise socks.SocksError(
                    socks.METHOD.NO_ACCEPTABLE_METHODS,
                    "mitmproxy only supports SOCKS without authentication")

            # Send Server Greeting
            server_greet = socks.ServerGreeting(
                socks.VERSION.SOCKS5, socks.METHOD.NO_AUTHENTICATION_REQUIRED)
            server_greet.to_file(self.client_conn.wfile)
            self.client_conn.wfile.flush()

            # Parse Connect Request
            connect_request = socks.Message.from_file(self.client_conn.rfile)
            connect_request.assert_socks5()
            if connect_request.msg != socks.CMD.CONNECT:
                raise socks.SocksError(
                    socks.REP.COMMAND_NOT_SUPPORTED,
                    "mitmproxy only supports SOCKS5 CONNECT.")

            # We always connect lazily, but we need to pretend to the client that we connected.
            connect_reply = socks.Message(
                socks.VERSION.SOCKS5,
                socks.REP.SUCCEEDED,
                connect_request.atyp,
                # dummy value, we don't have an upstream connection yet.
                connect_request.addr)
            connect_reply.to_file(self.client_conn.wfile)
            self.client_conn.wfile.flush()

        except (socks.SocksError, exceptions.TcpException) as e:
            raise exceptions.Socks5ProtocolException(
                "SOCKS5 mode failure: %s" % repr(e))

        self.server_conn.address = connect_request.addr

        layer = self.ctx.next_layer(self)
        try:
            layer()
        finally:
            if self.server_conn.connected():
                self.disconnect()
Exemple #4
0
    def test_with_authentication(self):
        p = self.pathoc()
        with p.connect():
            socks.ClientGreeting(socks.VERSION.SOCKS5,
                                 [socks.METHOD.USERNAME_PASSWORD]).to_file(
                                     p.wfile)
            socks.Message(socks.VERSION.SOCKS5, socks.CMD.BIND,
                          socks.ATYP.DOMAINNAME,
                          ("example.com", 8080)).to_file(p.wfile)

            p.wfile.flush()
            f = p.request(
                "get:/p/200"
            )  # the request doesn't matter, error response from handshake will be read anyway.
        assert f.status_code == 502
        assert b"SOCKS5 mode failure" in f.content
        assert b"mitmproxy only supports SOCKS without authentication" in f.content
Exemple #5
0
    def test_no_connect(self):
        """
        mitmproxy doesn't support UDP or BIND SOCKS CMDs
        """
        p = self.pathoc()
        with p.connect():
            socks.ClientGreeting(
                socks.VERSION.SOCKS5,
                [socks.METHOD.NO_AUTHENTICATION_REQUIRED]).to_file(p.wfile)
            socks.Message(socks.VERSION.SOCKS5, socks.CMD.BIND,
                          socks.ATYP.DOMAINNAME,
                          ("example.com", 8080)).to_file(p.wfile)

            p.wfile.flush()
            p.rfile.read(2)  # read server greeting
            f = p.request(
                "get:/p/200"
            )  # the request doesn't matter, error response from handshake will be read anyway.
        assert f.status_code == 502
        assert b"SOCKS5 mode failure" in f.content
Exemple #6
0
def test_message_unknown_atyp():
    raw = tutils.treader(b"\x05\x02\x00\x02\x7f\x00\x00\x01\xDE\xAD\xBE\xEF")
    tutils.raises(socks.SocksError, socks.Message.from_file, raw)

    m = socks.Message(5, 1, 0x02, tcp.Address(("example.com", 5050)))
    tutils.raises(socks.SocksError, m.to_file, BytesIO())