Compare commits
48 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2d9588a73a | ||
|
|
220270b17a | ||
|
|
ccb7e36330 | ||
|
|
a917e60b3d | ||
|
|
3b56561b1d | ||
|
|
d42bd3575a | ||
|
|
70991afa89 | ||
|
|
b60ef75ace | ||
|
|
2c5e2ef8dd | ||
|
|
453d2f6712 | ||
|
|
65881aad92 | ||
|
|
36c7cd88bd | ||
|
|
5a7d2a2134 | ||
|
|
f7f4020534 | ||
|
|
8a380cf32e | ||
|
|
f7efb0971b | ||
|
|
aca2e5bf33 | ||
|
|
315dcc9be1 | ||
|
|
46dbc07176 | ||
|
|
cae60a5c67 | ||
|
|
618621f42f | ||
|
|
b082022bf4 | ||
|
|
09061f64b8 | ||
|
|
353352c2e5 | ||
|
|
7c8d3edaf2 | ||
|
|
4cc3dd5c55 | ||
|
|
b7e3e33212 | ||
|
|
ad19ca1e23 | ||
|
|
62a14b15db | ||
|
|
570f51b516 | ||
|
|
9be1a40e45 | ||
|
|
a14477598a | ||
|
|
02a27b31c8 | ||
| 097eb0d4a5 | |||
|
|
9f8927f835 | ||
|
|
81552d4c8f | ||
|
3c90abb02f |
|||
|
|
44dea1ee94 | ||
|
|
950b64c454 | ||
|
|
c68bb9fdd9 | ||
|
|
608898a20b | ||
|
|
725ff2cd22 | ||
|
|
625c7209d8 | ||
|
|
c2e99f2aee | ||
|
|
d111410f59 | ||
|
|
cc32c31ace | ||
|
|
db0c8b1266 | ||
|
|
0a5818e995 |
4 changed files with 442 additions and 0 deletions
0
.gitignore
vendored
0
.gitignore
vendored
33
README-Fedora
Normal file
33
README-Fedora
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
ProxyFuzz is a man-in-the-middle non-deterministic network fuzzer written in
|
||||
Python. ProxyFuzz randomly changes (fuzzes) contents on the network traffic.
|
||||
It supports TCP and UDP protocols and can also be configured to fuzz only one
|
||||
side of the communication. ProxyFuzz is protocol agnostic so it can randomly
|
||||
fuzz any network communication.
|
||||
|
||||
ProxyFuzz is a good tool for quickly testing network protocols and provide with
|
||||
basic proof of concepts. Using this tool you will be amazed by the poor quality
|
||||
of software and you will see clients and servers dying upon unexpected input,
|
||||
just be prepared to see the very weird behaviours.
|
||||
|
||||
Syntax of ProxyFuzz:
|
||||
|
||||
|
||||
ProxyFuzz 0.1, Simple fuzzing proxy by Rodrigo Marcos
|
||||
|
||||
usage():
|
||||
|
||||
python3 proxyfuzz -l -r -p [options]
|
||||
|
||||
[options]
|
||||
|
||||
-w: Number of requests to send before start fuzzing
|
||||
|
||||
-c: Fuzz only client side (both otherwise)
|
||||
|
||||
-s: Fuzz only server side (both otherwise)
|
||||
|
||||
-u: UDP protocol (otherwise TCP is used)
|
||||
|
||||
-v: Verbose (outputs network traffic)
|
||||
|
||||
-h: Help page
|
||||
263
proxyfuzz.py
Normal file
263
proxyfuzz.py
Normal file
|
|
@ -0,0 +1,263 @@
|
|||
#!/usr/bin/python3
|
||||
# Proxyfuzz - On the fly TCP and UDP network fuzzer
|
||||
# Copyright (C) 2011 Rodrigo Marcos
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU General Public License as published by
|
||||
# the Free Software Foundation, either version 3 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
#
|
||||
# Proxyfuzz: a TCP and UDP proxy man-in-the-middle fuzzer
|
||||
# v 0.1
|
||||
# By Rodrigo Marcos
|
||||
# http://www.secforce.co.uk
|
||||
|
||||
from twisted.protocols import portforward
|
||||
from twisted.internet.protocol import DatagramProtocol
|
||||
from twisted.internet import reactor
|
||||
import getopt, sys
|
||||
from random import randint, randrange
|
||||
|
||||
|
||||
# UDP Proxy stuff
|
||||
|
||||
class Client(DatagramProtocol):
|
||||
def __init__(self, server, host, port):
|
||||
self.server = server
|
||||
self.host = host
|
||||
self.port = port
|
||||
|
||||
def startProtocol(self):
|
||||
self.transport.connect(desthost, destport)
|
||||
|
||||
def datagramReceived(self, data, host_port):
|
||||
global verbose
|
||||
global notuntil
|
||||
global request
|
||||
global testclient
|
||||
|
||||
if testclient:
|
||||
if request < notuntil:
|
||||
request = request + 1
|
||||
else:
|
||||
data = fuzz(data)
|
||||
if verbose:
|
||||
print("Server ------> Client")
|
||||
print(data)
|
||||
addr=(self.host, self.port)
|
||||
self.server.transport.write(data, addr)
|
||||
|
||||
|
||||
class Server(DatagramProtocol):
|
||||
client = None
|
||||
|
||||
def datagramReceived(self, data, host_port):
|
||||
host, port = host_port
|
||||
if not self.client or self.client.host != host or self.client.port != port:
|
||||
self.client = Client(self, host, port)
|
||||
reactor.listenUDP(0, self.client)
|
||||
|
||||
global verbose
|
||||
global notuntil
|
||||
global request
|
||||
global testserver
|
||||
|
||||
if testserver:
|
||||
if request < notuntil:
|
||||
request = request + 1
|
||||
else:
|
||||
data = fuzz(data)
|
||||
if verbose:
|
||||
print("Client ------> Server")
|
||||
print(data)
|
||||
addr=(desthost, destport)
|
||||
self.client.transport.write(data, addr)
|
||||
|
||||
|
||||
# TCP proxy stuff
|
||||
|
||||
def server_dataReceived(self, data):
|
||||
global verbose
|
||||
global notuntil
|
||||
global request
|
||||
global testserver
|
||||
|
||||
if testserver:
|
||||
if request < notuntil:
|
||||
request = request + 1
|
||||
else:
|
||||
data = fuzz(data)
|
||||
|
||||
if verbose:
|
||||
print("Client ------> server")
|
||||
print(data)
|
||||
|
||||
portforward.Proxy.dataReceived(self, data)
|
||||
|
||||
|
||||
portforward.ProxyServer.dataReceived = server_dataReceived
|
||||
|
||||
|
||||
def client_dataReceived(self, data):
|
||||
global verbose
|
||||
global notuntil
|
||||
global request
|
||||
global testclient
|
||||
|
||||
if testclient:
|
||||
if request < notuntil:
|
||||
request = request + 1
|
||||
else:
|
||||
data = fuzz(data)
|
||||
if verbose:
|
||||
print("Server ------> Client")
|
||||
print(data)
|
||||
|
||||
portforward.Proxy.dataReceived(self, data)
|
||||
|
||||
|
||||
portforward.ProxyClient.dataReceived = client_dataReceived
|
||||
|
||||
overflowstrings = ["A" * 255, "A" * 256, "A" * 257, "A" * 420, "A" * 511, "A" * 512, "A" * 1023, "A" * 1024, "A" * 2047,
|
||||
"A" * 2048, "A" * 4096, "A" * 4097, "A" * 5000, "A" * 10000, "A" * 20000, "A" * 32762, "A" * 32763,
|
||||
"A" * 32764, "A" * 32765, "A" * 32766, "A" * 32767, "A" * 32768, "A" * 65534, "A" * 65535,
|
||||
"A" * 65536, "%x" * 1024, "%n" * 1025, "%s" * 2048, "%s%n%x%d" * 5000, "%s" * 30000, "%s" * 40000,
|
||||
"%.1024d", "%.2048d", "%.4096d", "%.8200d", "%99999999999s", "%99999999999d", "%99999999999x",
|
||||
"%99999999999n", "%99999999999s" * 1000, "%99999999999d" * 1000, "%99999999999x" * 1000,
|
||||
"%99999999999n" * 1000, "%08x" * 100, "%%20s" * 1000, "%%20x" * 1000, "%%20n" * 1000, "%%20d" * 1000,
|
||||
"%#0123456x%08x%x%s%p%n%d%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%#0123456x%%x%%s%%p%%n%%d%%o%%u%%c%%h%%l%%q%%j%%z%%Z%%t%%i%%e%%g%%f%%a%%C%%S%%08x"]
|
||||
|
||||
|
||||
def bitflipping(data):
|
||||
l = len(data)
|
||||
n = int(l * 7 / 100) # 7% of the bytes to be modified
|
||||
|
||||
for i in range(0, n): # We change the bytes
|
||||
r = randint(0, l - 1)
|
||||
data = data[0:r] + str.encode(chr(randrange(0, 255))) + data[r + 1:]
|
||||
return data
|
||||
|
||||
|
||||
def bofinjection(data):
|
||||
l = len(data)
|
||||
r = randint(0, len(overflowstrings) - 1)
|
||||
data = data[0:r] + str.encode(overflowstrings[r]) + data[r - l:]
|
||||
return data
|
||||
|
||||
|
||||
def fuzz(data):
|
||||
r = randint(0, 5)
|
||||
if r == 0:
|
||||
data = bitflipping(data)
|
||||
|
||||
r = randint(0, 5)
|
||||
if r == 0:
|
||||
data = bofinjection(data)
|
||||
return data
|
||||
|
||||
|
||||
def startudpproxy():
|
||||
reactor.listenUDP(localport, Server())
|
||||
reactor.run()
|
||||
|
||||
|
||||
def starttcpproxy():
|
||||
reactor.listenTCP(localport, portforward.ProxyFactory(desthost, destport))
|
||||
reactor.run()
|
||||
|
||||
|
||||
def usage():
|
||||
# print "###############################################################"
|
||||
print('')
|
||||
print("ProxyFuzz 0.1, Simple fuzzing proxy by Rodrigo Marcos")
|
||||
print("http://www.secforce.co.uk")
|
||||
print('')
|
||||
print("usage():")
|
||||
print('')
|
||||
print("proxyfuzz -l <localport> -r <remotehost> -p <remoteport> [options]")
|
||||
print('')
|
||||
print(" [options]")
|
||||
print(" -c: Fuzz only client side (both otherwise)")
|
||||
print(" -s: Fuzz only server side (both otherwise)")
|
||||
print(" -w: Number of requests to send before start fuzzing")
|
||||
print(" -u: UDP protocol (otherwise TCP is used)")
|
||||
print(" -v: Verbose (outputs network traffic)")
|
||||
print(" -h: Help page")
|
||||
|
||||
|
||||
verbose = False
|
||||
notuntil = 0
|
||||
request = 0
|
||||
proto = "tcp"
|
||||
localport = 0
|
||||
desthost = ""
|
||||
destport = 0
|
||||
testclient = 1
|
||||
testserver = 1
|
||||
|
||||
|
||||
def main():
|
||||
global verbose
|
||||
global notuntil
|
||||
global proto
|
||||
global localport
|
||||
global desthost
|
||||
global destport
|
||||
global testclient
|
||||
global testserver
|
||||
|
||||
try:
|
||||
opts, args = getopt.getopt(sys.argv[1:], "uvhcsl:r:p:w:", ["help"])
|
||||
except getopt.GetoptError:
|
||||
usage()
|
||||
sys.exit(2)
|
||||
try:
|
||||
for o, a in opts:
|
||||
if o in ("-h", "--help"):
|
||||
usage()
|
||||
sys.exit()
|
||||
if o == "-l":
|
||||
localport = int(a)
|
||||
if o == "-r":
|
||||
desthost = a
|
||||
if o == "-p":
|
||||
destport = int(a)
|
||||
if o == "-v":
|
||||
verbose = True
|
||||
if o == "-w":
|
||||
notuntil = int(a)
|
||||
if o == "-u":
|
||||
proto = "udp"
|
||||
if o == "-c": # Only client
|
||||
testserver = 0
|
||||
if o == "-s": # Only server
|
||||
testclient = 0
|
||||
|
||||
|
||||
except:
|
||||
usage()
|
||||
sys.exit(2)
|
||||
|
||||
if testserver == 0 and testclient == 0:
|
||||
usage()
|
||||
sys.exit(2)
|
||||
elif localport == 0 or desthost == "" or destport == 0:
|
||||
usage()
|
||||
sys.exit(2)
|
||||
else:
|
||||
if proto == "tcp":
|
||||
starttcpproxy()
|
||||
else: # UDP
|
||||
startudpproxy()
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
146
proxyfuzz.spec
Normal file
146
proxyfuzz.spec
Normal file
|
|
@ -0,0 +1,146 @@
|
|||
Name: proxyfuzz
|
||||
Version: 20190404
|
||||
Release: 31%{?dist}
|
||||
Summary: Man-in-the-middle non-deterministic network fuzzer
|
||||
|
||||
# Automatically converted from old format: GPLv3+ - review is highly recommended.
|
||||
License: GPL-3.0-or-later
|
||||
URL: https://github.com/SECFORCE
|
||||
Source0: proxyfuzz.py
|
||||
Source1: README-Fedora
|
||||
|
||||
BuildArch: noarch
|
||||
Requires: python3-twisted
|
||||
BuildRequires: python3-devel
|
||||
%if 0%{?with_python3}
|
||||
BuildRequires: python3-devel
|
||||
%endif # if with_python3
|
||||
|
||||
#Patch0: make-executable.patch
|
||||
|
||||
%description
|
||||
ProxyFuzz is a man-in-the-middle non-deterministic network fuzzier written in
|
||||
Python. ProxyFuzz randomly changes (fuzzes) contents on the network traffic.
|
||||
It supports TCP and UDP protocols and can also be configured to fuzz only one
|
||||
side of the communication. ProxyFuzz is protocol agnostic so it can randomly
|
||||
fuzz any network communication.
|
||||
|
||||
%prep
|
||||
cp -p %{SOURCE0} .
|
||||
cp -p %{SOURCE1} .
|
||||
#%patch0 -p1 -b .make-executable
|
||||
|
||||
%build
|
||||
|
||||
%install
|
||||
rm -rf $RPM_BUILD_ROOT
|
||||
install -m 755 -p -d ${RPM_BUILD_ROOT}/%{_sbindir}
|
||||
install -m 755 -p proxyfuzz.py ${RPM_BUILD_ROOT}/%{_sbindir}/proxyfuzz
|
||||
|
||||
|
||||
|
||||
%files
|
||||
%doc README-Fedora
|
||||
%{_sbindir}/proxyfuzz
|
||||
|
||||
|
||||
%changelog
|
||||
* Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-31
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
|
||||
|
||||
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-30
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
|
||||
|
||||
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-29
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
|
||||
|
||||
* Sat Jan 18 2025 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-28
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
|
||||
|
||||
* Thu Jul 25 2024 Miroslav Suchý <msuchy@redhat.com> - 20190404-27
|
||||
- convert license to SPDX
|
||||
|
||||
* Fri Jul 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-26
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
|
||||
|
||||
* Fri Jan 26 2024 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-25
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
|
||||
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-24
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
|
||||
* Fri Jul 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-23
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
|
||||
|
||||
* Fri Jan 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-22
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
|
||||
|
||||
* Fri Jul 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-21
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
|
||||
|
||||
* Fri Jan 21 2022 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-20
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
|
||||
|
||||
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-19
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
|
||||
|
||||
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org>
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
|
||||
|
||||
* Tue Jul 28 2020 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-17
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
|
||||
|
||||
* Thu Jan 30 2020 Fedora Release Engineering <releng@fedoraproject.org> - 20190404-16
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
|
||||
|
||||
* Sat Feb 02 2019 Fedora Release Engineering <releng@fedoraproject.org> - 20110923-13
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
|
||||
|
||||
* Fri Jul 13 2018 Fedora Release Engineering <releng@fedoraproject.org> - 20110923-12
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
|
||||
|
||||
* Fri Feb 09 2018 Fedora Release Engineering <releng@fedoraproject.org> - 20110923-11
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
|
||||
|
||||
* Wed Feb 07 2018 Iryna Shcherbina <ishcherb@redhat.com> - 20110923-10
|
||||
- Update Python 2 dependency declarations to new packaging standards
|
||||
(See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)
|
||||
|
||||
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 20110923-9
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
|
||||
|
||||
* Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 20110923-8
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
|
||||
|
||||
* Thu Feb 04 2016 Fedora Release Engineering <releng@fedoraproject.org> - 20110923-7
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
|
||||
|
||||
* Thu Jun 18 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 20110923-6
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
|
||||
|
||||
* Sat Jun 07 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 20110923-5
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
|
||||
|
||||
* Sun Aug 04 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 20110923-4
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
|
||||
|
||||
* Thu Feb 14 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 20110923-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
|
||||
|
||||
* Sat Jul 21 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 20110923-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
|
||||
|
||||
* Mon Jan 2 2012 Petr Sklenar <psklenar at, redhat.com> 20110923-1
|
||||
- version changed
|
||||
- released changed
|
||||
|
||||
* Thu Oct 13 2011 Petr Sklenar <psklenar at, redhat.com> 0.1-20110923
|
||||
- version changed
|
||||
- spec file improved
|
||||
- README-Fedora created
|
||||
|
||||
* Wed Sep 7 2011 Petr Sklenar <psklenar at, redhat.com> 1-2
|
||||
- make script being executable
|
||||
|
||||
* Wed Aug 31 2011 Petr Sklenar <psklenar at, redhat.com> 1-1
|
||||
- Initial commit
|
||||
Loading…
Add table
Add a link
Reference in a new issue