diff --git a/.gitignore b/.gitignore deleted file mode 100644 index e69de29..0000000 diff --git a/README-Fedora b/README-Fedora new file mode 100644 index 0000000..b7f10c2 --- /dev/null +++ b/README-Fedora @@ -0,0 +1,33 @@ +ProxyFuzz is a man-in-the-middle non-deterministic network fuzzer written in +Python. ProxyFuzz randomly changes (fuzzes) contents on the network traffic. +It supports TCP and UDP protocols and can also be configured to fuzz only one +side of the communication. ProxyFuzz is protocol agnostic so it can randomly +fuzz any network communication. + +ProxyFuzz is a good tool for quickly testing network protocols and provide with +basic proof of concepts. Using this tool you will be amazed by the poor quality +of software and you will see clients and servers dying upon unexpected input, +just be prepared to see the very weird behaviours. + +Syntax of ProxyFuzz: + + +ProxyFuzz 0.1, Simple fuzzing proxy by Rodrigo Marcos + +usage(): + +python3 proxyfuzz -l -r -p [options] + + [options] + + -w: Number of requests to send before start fuzzing + + -c: Fuzz only client side (both otherwise) + + -s: Fuzz only server side (both otherwise) + + -u: UDP protocol (otherwise TCP is used) + + -v: Verbose (outputs network traffic) + + -h: Help page diff --git a/proxyfuzz.py b/proxyfuzz.py new file mode 100644 index 0000000..2820943 --- /dev/null +++ b/proxyfuzz.py @@ -0,0 +1,263 @@ +#!/usr/bin/python3 +# Proxyfuzz - On the fly TCP and UDP network fuzzer +# Copyright (C) 2011 Rodrigo Marcos +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 3 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +# Proxyfuzz: a TCP and UDP proxy man-in-the-middle fuzzer +# v 0.1 +# By Rodrigo Marcos +# http://www.secforce.co.uk + +from twisted.protocols import portforward +from twisted.internet.protocol import DatagramProtocol +from twisted.internet import reactor +import getopt, sys +from random import randint, randrange + + +# UDP Proxy stuff + +class Client(DatagramProtocol): + def __init__(self, server, host, port): + self.server = server + self.host = host + self.port = port + + def startProtocol(self): + self.transport.connect(desthost, destport) + + def datagramReceived(self, data, host_port): + global verbose + global notuntil + global request + global testclient + + if testclient: + if request < notuntil: + request = request + 1 + else: + data = fuzz(data) + if verbose: + print("Server ------> Client") + print(data) + addr=(self.host, self.port) + self.server.transport.write(data, addr) + + +class Server(DatagramProtocol): + client = None + + def datagramReceived(self, data, host_port): + host, port = host_port + if not self.client or self.client.host != host or self.client.port != port: + self.client = Client(self, host, port) + reactor.listenUDP(0, self.client) + + global verbose + global notuntil + global request + global testserver + + if testserver: + if request < notuntil: + request = request + 1 + else: + data = fuzz(data) + if verbose: + print("Client ------> Server") + print(data) + addr=(desthost, destport) + self.client.transport.write(data, addr) + + +# TCP proxy stuff + +def server_dataReceived(self, data): + global verbose + global notuntil + global request + global testserver + + if testserver: + if request < notuntil: + request = request + 1 + else: + data = fuzz(data) + + if verbose: + print("Client ------> server") + print(data) + + portforward.Proxy.dataReceived(self, data) + + +portforward.ProxyServer.dataReceived = server_dataReceived + + +def client_dataReceived(self, data): + global verbose + global notuntil + global request + global testclient + + if testclient: + if request < notuntil: + request = request + 1 + else: + data = fuzz(data) + if verbose: + print("Server ------> Client") + print(data) + + portforward.Proxy.dataReceived(self, data) + + +portforward.ProxyClient.dataReceived = client_dataReceived + +overflowstrings = ["A" * 255, "A" * 256, "A" * 257, "A" * 420, "A" * 511, "A" * 512, "A" * 1023, "A" * 1024, "A" * 2047, + "A" * 2048, "A" * 4096, "A" * 4097, "A" * 5000, "A" * 10000, "A" * 20000, "A" * 32762, "A" * 32763, + "A" * 32764, "A" * 32765, "A" * 32766, "A" * 32767, "A" * 32768, "A" * 65534, "A" * 65535, + "A" * 65536, "%x" * 1024, "%n" * 1025, "%s" * 2048, "%s%n%x%d" * 5000, "%s" * 30000, "%s" * 40000, + "%.1024d", "%.2048d", "%.4096d", "%.8200d", "%99999999999s", "%99999999999d", "%99999999999x", + "%99999999999n", "%99999999999s" * 1000, "%99999999999d" * 1000, "%99999999999x" * 1000, + "%99999999999n" * 1000, "%08x" * 100, "%%20s" * 1000, "%%20x" * 1000, "%%20n" * 1000, "%%20d" * 1000, + "%#0123456x%08x%x%s%p%n%d%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%#0123456x%%x%%s%%p%%n%%d%%o%%u%%c%%h%%l%%q%%j%%z%%Z%%t%%i%%e%%g%%f%%a%%C%%S%%08x"] + + +def bitflipping(data): + l = len(data) + n = int(l * 7 / 100) # 7% of the bytes to be modified + + for i in range(0, n): # We change the bytes + r = randint(0, l - 1) + data = data[0:r] + str.encode(chr(randrange(0, 255))) + data[r + 1:] + return data + + +def bofinjection(data): + l = len(data) + r = randint(0, len(overflowstrings) - 1) + data = data[0:r] + str.encode(overflowstrings[r]) + data[r - l:] + return data + + +def fuzz(data): + r = randint(0, 5) + if r == 0: + data = bitflipping(data) + + r = randint(0, 5) + if r == 0: + data = bofinjection(data) + return data + + +def startudpproxy(): + reactor.listenUDP(localport, Server()) + reactor.run() + + +def starttcpproxy(): + reactor.listenTCP(localport, portforward.ProxyFactory(desthost, destport)) + reactor.run() + + +def usage(): + # print "###############################################################" + print('') + print("ProxyFuzz 0.1, Simple fuzzing proxy by Rodrigo Marcos") + print("http://www.secforce.co.uk") + print('') + print("usage():") + print('') + print("proxyfuzz -l -r -p [options]") + print('') + print(" [options]") + print(" -c: Fuzz only client side (both otherwise)") + print(" -s: Fuzz only server side (both otherwise)") + print(" -w: Number of requests to send before start fuzzing") + print(" -u: UDP protocol (otherwise TCP is used)") + print(" -v: Verbose (outputs network traffic)") + print(" -h: Help page") + + +verbose = False +notuntil = 0 +request = 0 +proto = "tcp" +localport = 0 +desthost = "" +destport = 0 +testclient = 1 +testserver = 1 + + +def main(): + global verbose + global notuntil + global proto + global localport + global desthost + global destport + global testclient + global testserver + + try: + opts, args = getopt.getopt(sys.argv[1:], "uvhcsl:r:p:w:", ["help"]) + except getopt.GetoptError: + usage() + sys.exit(2) + try: + for o, a in opts: + if o in ("-h", "--help"): + usage() + sys.exit() + if o == "-l": + localport = int(a) + if o == "-r": + desthost = a + if o == "-p": + destport = int(a) + if o == "-v": + verbose = True + if o == "-w": + notuntil = int(a) + if o == "-u": + proto = "udp" + if o == "-c": # Only client + testserver = 0 + if o == "-s": # Only server + testclient = 0 + + + except: + usage() + sys.exit(2) + + if testserver == 0 and testclient == 0: + usage() + sys.exit(2) + elif localport == 0 or desthost == "" or destport == 0: + usage() + sys.exit(2) + else: + if proto == "tcp": + starttcpproxy() + else: # UDP + startudpproxy() + + +if __name__ == "__main__": + main() diff --git a/proxyfuzz.spec b/proxyfuzz.spec new file mode 100644 index 0000000..80bcd5b --- /dev/null +++ b/proxyfuzz.spec @@ -0,0 +1,146 @@ +Name: proxyfuzz +Version: 20190404 +Release: 31%{?dist} +Summary: Man-in-the-middle non-deterministic network fuzzer + +# Automatically converted from old format: GPLv3+ - review is highly recommended. +License: GPL-3.0-or-later +URL: https://github.com/SECFORCE +Source0: proxyfuzz.py +Source1: README-Fedora + +BuildArch: noarch +Requires: python3-twisted +BuildRequires: python3-devel +%if 0%{?with_python3} +BuildRequires: python3-devel +%endif # if with_python3 + +#Patch0: make-executable.patch + +%description +ProxyFuzz is a man-in-the-middle non-deterministic network fuzzier written in +Python. ProxyFuzz randomly changes (fuzzes) contents on the network traffic. +It supports TCP and UDP protocols and can also be configured to fuzz only one +side of the communication. ProxyFuzz is protocol agnostic so it can randomly +fuzz any network communication. + +%prep +cp -p %{SOURCE0} . +cp -p %{SOURCE1} . +#%patch0 -p1 -b .make-executable + +%build + +%install +rm -rf $RPM_BUILD_ROOT +install -m 755 -p -d ${RPM_BUILD_ROOT}/%{_sbindir} +install -m 755 -p proxyfuzz.py ${RPM_BUILD_ROOT}/%{_sbindir}/proxyfuzz + + + +%files +%doc README-Fedora +%{_sbindir}/proxyfuzz + + +%changelog +* Thu Jul 16 2026 Fedora Release Engineering - 20190404-31 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild + +* Sat Jan 17 2026 Fedora Release Engineering - 20190404-30 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + +* Fri Jul 25 2025 Fedora Release Engineering - 20190404-29 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Sat Jan 18 2025 Fedora Release Engineering - 20190404-28 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Thu Jul 25 2024 Miroslav Suchý - 20190404-27 +- convert license to SPDX + +* Fri Jul 19 2024 Fedora Release Engineering - 20190404-26 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Fri Jan 26 2024 Fedora Release Engineering - 20190404-25 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sun Jan 21 2024 Fedora Release Engineering - 20190404-24 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Fri Jul 21 2023 Fedora Release Engineering - 20190404-23 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Fri Jan 20 2023 Fedora Release Engineering - 20190404-22 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Fri Jul 22 2022 Fedora Release Engineering - 20190404-21 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Fri Jan 21 2022 Fedora Release Engineering - 20190404-20 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Fri Jul 23 2021 Fedora Release Engineering - 20190404-19 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Wed Jan 27 2021 Fedora Release Engineering +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Tue Jul 28 2020 Fedora Release Engineering - 20190404-17 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Thu Jan 30 2020 Fedora Release Engineering - 20190404-16 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Sat Feb 02 2019 Fedora Release Engineering - 20110923-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Fri Jul 13 2018 Fedora Release Engineering - 20110923-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Fri Feb 09 2018 Fedora Release Engineering - 20110923-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Wed Feb 07 2018 Iryna Shcherbina - 20110923-10 +- Update Python 2 dependency declarations to new packaging standards + (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3) + +* Thu Jul 27 2017 Fedora Release Engineering - 20110923-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Sat Feb 11 2017 Fedora Release Engineering - 20110923-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Thu Feb 04 2016 Fedora Release Engineering - 20110923-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Thu Jun 18 2015 Fedora Release Engineering - 20110923-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Sat Jun 07 2014 Fedora Release Engineering - 20110923-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Sun Aug 04 2013 Fedora Release Engineering - 20110923-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Thu Feb 14 2013 Fedora Release Engineering - 20110923-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild + +* Sat Jul 21 2012 Fedora Release Engineering - 20110923-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild + +* Mon Jan 2 2012 Petr Sklenar 20110923-1 +- version changed +- released changed + +* Thu Oct 13 2011 Petr Sklenar 0.1-20110923 +- version changed +- spec file improved +- README-Fedora created + +* Wed Sep 7 2011 Petr Sklenar 1-2 +- make script being executable + +* Wed Aug 31 2011 Petr Sklenar 1-1 +- Initial commit