What is ProxyTunnel?
ProxyTunnel is a command-line tool that allows you to create TCP tunnels through HTTP/HTTPS proxy servers. It is particularly useful for bypassing network restrictions, forwarding ports, and establishing encrypted connections when direct access is blocked.
Key Features:
- Creates encrypted tunnels via HTTP/HTTPS proxies.
- Supports SOCKS, CONNECT, and HTTP proxy methods.
- Useful for bypassing firewalls and accessing restricted services.
- Can be used with SSH, VPNs, and other tunneling protocols.
How ProxyTunnel Works
ProxyTunnel works by encapsulating TCP traffic inside HTTP requests, allowing it to pass through proxy servers that only permit web traffic. It uses the HTTP CONNECT method to establish a tunnel, which is then used to forward traffic to the desired destination.
Basic Workflow:
- Client sends an HTTP
CONNECTrequest to the Proxy Server. - The Proxy Server establishes a TCP connection to the Target Server.
- Once the tunnel is established, all traffic between the Client and Target Server is relayed through the proxy.
Installation
ProxyTunnel is pre-installed in Kali Linux. If not, install it using:
Bash
sudo apt update && sudo apt install proxytunnelBasic Usage Examples
Example 1: Basic SSH Tunneling via HTTP Proxy
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22-p: Proxy server address and port.-d: Destination (target) server and port.
Example 2: Using Authentication
Bash
proxytunnel -p proxy.example.com:8080 -u username -P password -d target.example.com:22-u: Proxy username.-P: Proxy password.
Example 3: Using HTTPS Proxy
Bash
proxytunnel -p proxy.example.com:443 -e -d target.example.com:22-e: Enables SSL/TLS encryption for the proxy connection.
Advanced Usage
Example 4: Dynamic Port Forwarding (SOCKS Proxy)
Bash
proxytunnel -p proxy.example.com:8080 -r 127.0.0.1:1080 -d target.example.com:22-r: Binds a local SOCKS proxy (useful with tools likeproxychains).
Example 5: Bypassing Deep Packet Inspection (DPI)
Bash
proxytunnel -p proxy.example.com:443 -H "Host: innocent-site.com" -d target.example.com:22-H: Adds a fake HTTPHostheader to evade detection.
Example 6: Chaining Proxies
Bash
proxytunnel -p proxy1.example.com:8080 -a proxy2.example.com:3128 -d target.example.com:22-a: Specifies an additional proxy (proxy chaining).
Command-Line Options
| Option | Description |
|---|---|
-p <proxy:port> | Proxy server address and port |
-d <host:port> | Destination server and port |
-u <username> | Proxy username |
-P <password> | Proxy password |
-e | Enable SSL/TLS encryption |
-H <header> | Add custom HTTP headers |
-r <host:port> | Bind to a local port (SOCKS proxy) |
-a <proxy:port> | Use an additional proxy |
-v | Verbose mode (debugging) |
-q | Quiet mode (suppress output) |
1. Basic Proxy Tunneling
Standard HTTP Proxy Connection
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22-p: Specifies the proxy server (host:port)-d: Specifies the destination server (host:port)
With Proxy Authentication
Bash
proxytunnel -p proxy.example.com:8080 -P user:pass -d target.example.com:22-P: Provides proxy credentials inuser:passwordformat
2. SSL/TLS Encryption Options
Encrypt Proxy-to-Destination Traffic
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:443 -e-e: Encrypts traffic between proxy and destination
Encrypt Client-to-Proxy Traffic
Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:22 -E-E: Uses SSL between client and proxy (HTTPS proxy)
Full End-to-End Encryption
Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:443 -E -e3. Advanced Proxy Configurations
Proxy Chaining (Two Proxies)
Bash
proxytunnel -p proxy1.example.com:8080 -r proxy2.example.com:3128 -d target.example.com:22-r: Specifies a remote proxy for chaining
NTLM Authentication
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:80 -N -t DOMAIN-N: Enables NTLM authentication-t: Specifies NTLM domain
4. SSL Certificate Handling
Disable Certificate Verification
Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:443 -E -z-z: Skips SSL certificate verification
Custom CA Certificate
Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:443 -E -C /path/to/cacert.pem-C: Specifies custom CA certificate file/directory
5. Network & Protocol Options
Force IPv4/IPv6
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -4 # IPv4
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -6 # IPv6Custom Host Header
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:80 -o "example.com"-o: Overrides Host header (useful for SNI/domain fronting)
6. Authentication & Credential Files
Credentials from File
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -F /path/to/creds.txt-F: File containing credentials inuser:passwordformat
7. Debugging & Verbosity
Verbose Mode
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -v-v: Increases verbosity for debugging
Quiet Mode
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -q-q: Suppresses non-error messages
8. Special Use Cases
ASF Bugzilla 29744 Workaround
Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:22 -E -W-W: Disables SSL after CONNECT (for buggy proxies)
Client Certificate Authentication
Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:443 -E -c cert.pem -k key.pem-c: Client SSL certificate-k: Client SSL key
9. Daemon & Service Modes
Run as Standalone Daemon
Bash
proxytunnel -a 127.0.0.1:8888 -p proxy.example.com:8080 -d target.example.com:22-a: Binds to local port as a forwarding service
Inetd Mode
Bash
proxytunnel -i -p proxy.example.com:8080 -d target.example.com:22-i: Runs in inetd-compatible mode
10. Practical Examples
SSH Through Corporate Proxy
Bash
ssh -o "ProxyCommand=proxytunnel -p proxy.corp.com:8080 -d %h:%p" user@server.example.comHTTP Tunneling with Custom Headers
Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:80 \
-H "X-Forwarded-For: 1.2.3.4" -H "User-Agent: Mozilla/5.0"SOCKS Proxy Creation
Bash
proxytunnel -a 127.0.0.1:1080 -p proxy.example.com:8080 -d any:any- Creates a local SOCKS proxy on port 1080
Real-World Use Cases
1. Bypassing Corporate Firewalls
- Access SSH, RDP, or other restricted services via an HTTP proxy.
2. Secure Remote Access
- Tunnel traffic through a trusted proxy to avoid exposing direct connections.
3. Penetration Testing
- Evade network monitoring while performing security assessments.
4. Circumventing Censorship
- Access blocked websites by tunneling through an allowed proxy.
Troubleshooting Tips
Issue 1: Connection Refused by Proxy
- Verify proxy credentials (
-u,-P). - Check if the proxy supports
CONNECTmethod.
Issue 2: SSL/TLS Handshake Failures
- Use
-efor HTTPS proxies. - Ensure the proxy certificate is trusted.
Issue 3: Slow Performance
- Try a different proxy server.
- Disable verbose mode (
-q) to reduce overhead.
Issue 4: Proxy Blocks Non-HTTP Traffic
- Use
-Hto disguise traffic as legitimate HTTP requests.