proxytunnel: A tool that tunnels HTTPS traffic through an HTTP proxy

proxytunnel A tool that tunnels HTTPS traffic through an HTTP proxy

What is ProxyTunnel?

ProxyTunnel is a command-line tool that allows you to create TCP tunnels through HTTP/HTTPS proxy servers. It is particularly useful for bypassing network restrictions, forwarding ports, and establishing encrypted connections when direct access is blocked.

Key Features:

  • Creates encrypted tunnels via HTTP/HTTPS proxies.
  • Supports SOCKS, CONNECT, and HTTP proxy methods.
  • Useful for bypassing firewalls and accessing restricted services.
  • Can be used with SSH, VPNs, and other tunneling protocols.

How ProxyTunnel Works

ProxyTunnel works by encapsulating TCP traffic inside HTTP requests, allowing it to pass through proxy servers that only permit web traffic. It uses the HTTP CONNECT method to establish a tunnel, which is then used to forward traffic to the desired destination.

Basic Workflow:

  1. Client sends an HTTP CONNECT request to the Proxy Server.
  2. The Proxy Server establishes a TCP connection to the Target Server.
  3. Once the tunnel is established, all traffic between the Client and Target Server is relayed through the proxy.

Installation

ProxyTunnel is pre-installed in Kali Linux. If not, install it using:

Bash
sudo apt update && sudo apt install proxytunnel

Basic Usage Examples

Example 1: Basic SSH Tunneling via HTTP Proxy

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22
  • -p: Proxy server address and port.
  • -d: Destination (target) server and port.

Example 2: Using Authentication

Bash
proxytunnel -p proxy.example.com:8080 -u username -P password -d target.example.com:22
  • -u: Proxy username.
  • -P: Proxy password.

Example 3: Using HTTPS Proxy

Bash
proxytunnel -p proxy.example.com:443 -e -d target.example.com:22
  • -e: Enables SSL/TLS encryption for the proxy connection.

Advanced Usage

Example 4: Dynamic Port Forwarding (SOCKS Proxy)

Bash
proxytunnel -p proxy.example.com:8080 -r 127.0.0.1:1080 -d target.example.com:22
  • -r: Binds a local SOCKS proxy (useful with tools like proxychains).

Example 5: Bypassing Deep Packet Inspection (DPI)

Bash
proxytunnel -p proxy.example.com:443 -H "Host: innocent-site.com" -d target.example.com:22
  • -H: Adds a fake HTTP Host header to evade detection.

Example 6: Chaining Proxies

Bash
proxytunnel -p proxy1.example.com:8080 -a proxy2.example.com:3128 -d target.example.com:22
  • -a: Specifies an additional proxy (proxy chaining).

Command-Line Options

OptionDescription
-p <proxy:port>Proxy server address and port
-d <host:port>Destination server and port
-u <username>Proxy username
-P <password>Proxy password
-eEnable SSL/TLS encryption
-H <header>Add custom HTTP headers
-r <host:port>Bind to a local port (SOCKS proxy)
-a <proxy:port>Use an additional proxy
-vVerbose mode (debugging)
-qQuiet mode (suppress output)

1. Basic Proxy Tunneling

Standard HTTP Proxy Connection

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22
  • -p: Specifies the proxy server (host:port)
  • -d: Specifies the destination server (host:port)

With Proxy Authentication

Bash
proxytunnel -p proxy.example.com:8080 -P user:pass -d target.example.com:22
  • -P: Provides proxy credentials in user:password format

2. SSL/TLS Encryption Options

Encrypt Proxy-to-Destination Traffic

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:443 -e
  • -e: Encrypts traffic between proxy and destination

Encrypt Client-to-Proxy Traffic

Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:22 -E
  • -E: Uses SSL between client and proxy (HTTPS proxy)

Full End-to-End Encryption

Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:443 -E -e

3. Advanced Proxy Configurations

Proxy Chaining (Two Proxies)

Bash
proxytunnel -p proxy1.example.com:8080 -r proxy2.example.com:3128 -d target.example.com:22
  • -r: Specifies a remote proxy for chaining

NTLM Authentication

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:80 -N -t DOMAIN
  • -N: Enables NTLM authentication
  • -t: Specifies NTLM domain

4. SSL Certificate Handling

Disable Certificate Verification

Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:443 -E -z
  • -z: Skips SSL certificate verification

Custom CA Certificate

Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:443 -E -C /path/to/cacert.pem
  • -C: Specifies custom CA certificate file/directory

5. Network & Protocol Options

Force IPv4/IPv6

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -4  # IPv4
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -6  # IPv6

Custom Host Header

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:80 -o "example.com"
  • -o: Overrides Host header (useful for SNI/domain fronting)

6. Authentication & Credential Files

Credentials from File

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -F /path/to/creds.txt
  • -F: File containing credentials in user:password format

7. Debugging & Verbosity

Verbose Mode

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -v
  • -v: Increases verbosity for debugging

Quiet Mode

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:22 -q
  • -q: Suppresses non-error messages

8. Special Use Cases

ASF Bugzilla 29744 Workaround

Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:22 -E -W
  • -W: Disables SSL after CONNECT (for buggy proxies)

Client Certificate Authentication

Bash
proxytunnel -p proxy.example.com:443 -d target.example.com:443 -E -c cert.pem -k key.pem
  • -c: Client SSL certificate
  • -k: Client SSL key

9. Daemon & Service Modes

Run as Standalone Daemon

Bash
proxytunnel -a 127.0.0.1:8888 -p proxy.example.com:8080 -d target.example.com:22
  • -a: Binds to local port as a forwarding service

Inetd Mode

Bash
proxytunnel -i -p proxy.example.com:8080 -d target.example.com:22
  • -i: Runs in inetd-compatible mode

10. Practical Examples

SSH Through Corporate Proxy

Bash
ssh -o "ProxyCommand=proxytunnel -p proxy.corp.com:8080 -d %h:%p" user@server.example.com

HTTP Tunneling with Custom Headers

Bash
proxytunnel -p proxy.example.com:8080 -d target.example.com:80 \
  -H "X-Forwarded-For: 1.2.3.4" -H "User-Agent: Mozilla/5.0"

SOCKS Proxy Creation

Bash
proxytunnel -a 127.0.0.1:1080 -p proxy.example.com:8080 -d any:any
  • Creates a local SOCKS proxy on port 1080

Real-World Use Cases

1. Bypassing Corporate Firewalls

  • Access SSH, RDP, or other restricted services via an HTTP proxy.

2. Secure Remote Access

  • Tunnel traffic through a trusted proxy to avoid exposing direct connections.

3. Penetration Testing

  • Evade network monitoring while performing security assessments.

4. Circumventing Censorship

  • Access blocked websites by tunneling through an allowed proxy.

Troubleshooting Tips

Issue 1: Connection Refused by Proxy

  • Verify proxy credentials (-u, -P).
  • Check if the proxy supports CONNECT method.

Issue 2: SSL/TLS Handshake Failures

  • Use -e for HTTPS proxies.
  • Ensure the proxy certificate is trusted.

Issue 3: Slow Performance

  • Try a different proxy server.
  • Disable verbose mode (-q) to reduce overhead.

Issue 4: Proxy Blocks Non-HTTP Traffic

  • Use -H to disguise traffic as legitimate HTTP requests.

Total
0
Shares

Leave a Reply

Previous Post

proxychains4: A tool for forcing network connections to go through proxy servers

Next Post
ptunnel: A tool to create a tunnel over ICMP for bypassing firewalls

ptunnel: A tool to create a tunnel over ICMP for bypassing firewalls

Related Posts