def socks_connect(self, connect_to): try: client_greet = socks.ClientGreeting( socks.VERSION.SOCKS5, [socks.METHOD.NO_AUTHENTICATION_REQUIRED]) client_greet.to_file(self.wfile) self.wfile.flush() server_greet = socks.ServerGreeting.from_file(self.rfile) server_greet.assert_socks5() if server_greet.method != socks.METHOD.NO_AUTHENTICATION_REQUIRED: raise socks.SocksError( socks.METHOD.NO_ACCEPTABLE_METHODS, "pathoc only supports SOCKS without authentication") connect_request = socks.Message( socks.VERSION.SOCKS5, socks.CMD.CONNECT, socks.ATYP.DOMAINNAME, connect_to, ) connect_request.to_file(self.wfile) self.wfile.flush() connect_reply = socks.Message.from_file(self.rfile) connect_reply.assert_socks5() if connect_reply.msg != socks.REP.SUCCEEDED: raise socks.SocksError(connect_reply.msg, "SOCKS server error") except (socks.SocksError, exceptions.TcpDisconnect) as e: raise PathocError(str(e))
def test_message_unknown_atyp(): raw = tutils.treader(b"\x05\x02\x00\x02\x7f\x00\x00\x01\xDE\xAD\xBE\xEF") with pytest.raises(socks.SocksError): socks.Message.from_file(raw) m = socks.Message(5, 1, 0x02, ("example.com", 5050)) with pytest.raises(socks.SocksError): m.to_file(BytesIO())
def __call__(self): try: # Parse Client Greeting client_greet = socks.ClientGreeting.from_file( self.client_conn.rfile, fail_early=True) client_greet.assert_socks5() if socks.METHOD.NO_AUTHENTICATION_REQUIRED not in client_greet.methods: raise socks.SocksError( socks.METHOD.NO_ACCEPTABLE_METHODS, "mitmproxy only supports SOCKS without authentication") # Send Server Greeting server_greet = socks.ServerGreeting( socks.VERSION.SOCKS5, socks.METHOD.NO_AUTHENTICATION_REQUIRED) server_greet.to_file(self.client_conn.wfile) self.client_conn.wfile.flush() # Parse Connect Request connect_request = socks.Message.from_file(self.client_conn.rfile) connect_request.assert_socks5() if connect_request.msg != socks.CMD.CONNECT: raise socks.SocksError( socks.REP.COMMAND_NOT_SUPPORTED, "mitmproxy only supports SOCKS5 CONNECT.") # We always connect lazily, but we need to pretend to the client that we connected. connect_reply = socks.Message( socks.VERSION.SOCKS5, socks.REP.SUCCEEDED, connect_request.atyp, # dummy value, we don't have an upstream connection yet. connect_request.addr) connect_reply.to_file(self.client_conn.wfile) self.client_conn.wfile.flush() except (socks.SocksError, exceptions.TcpException) as e: raise exceptions.Socks5ProtocolException( "SOCKS5 mode failure: %s" % repr(e)) self.server_conn.address = connect_request.addr layer = self.ctx.next_layer(self) try: layer() finally: if self.server_conn.connected(): self.disconnect()
def test_with_authentication(self): p = self.pathoc() with p.connect(): socks.ClientGreeting(socks.VERSION.SOCKS5, [socks.METHOD.USERNAME_PASSWORD]).to_file( p.wfile) socks.Message(socks.VERSION.SOCKS5, socks.CMD.BIND, socks.ATYP.DOMAINNAME, ("example.com", 8080)).to_file(p.wfile) p.wfile.flush() f = p.request( "get:/p/200" ) # the request doesn't matter, error response from handshake will be read anyway. assert f.status_code == 502 assert b"SOCKS5 mode failure" in f.content assert b"mitmproxy only supports SOCKS without authentication" in f.content
def test_no_connect(self): """ mitmproxy doesn't support UDP or BIND SOCKS CMDs """ p = self.pathoc() with p.connect(): socks.ClientGreeting( socks.VERSION.SOCKS5, [socks.METHOD.NO_AUTHENTICATION_REQUIRED]).to_file(p.wfile) socks.Message(socks.VERSION.SOCKS5, socks.CMD.BIND, socks.ATYP.DOMAINNAME, ("example.com", 8080)).to_file(p.wfile) p.wfile.flush() p.rfile.read(2) # read server greeting f = p.request( "get:/p/200" ) # the request doesn't matter, error response from handshake will be read anyway. assert f.status_code == 502 assert b"SOCKS5 mode failure" in f.content
def test_message_unknown_atyp(): raw = tutils.treader(b"\x05\x02\x00\x02\x7f\x00\x00\x01\xDE\xAD\xBE\xEF") tutils.raises(socks.SocksError, socks.Message.from_file, raw) m = socks.Message(5, 1, 0x02, tcp.Address(("example.com", 5050))) tutils.raises(socks.SocksError, m.to_file, BytesIO())