Httptap: observing the HTTP(S) requests of local programs
Summary
Httptap shows the HTTP and HTTPS requests of any Linux program via an isolated, transparent network path. Every Linux network namespace has its own loopback interface. Httptap implements parts of IP, TCP and UDP in user space.
Ideas
- A network namespace separates the examined process from the host network.
- A TUN device routes all traffic into httptap's user space stack.
- A transparent proxy reconstructs connections to the actual destination.
- A temporary certificate authority enables HTTPS inspection of cooperating applications.
- Daemonised children need continued proxying after the parent process exits.
Insights
- Complete observation requires control over routing and trust at the same time.
- Namespaces change the meaning of localhost for the processes examined.
- TLS inspection is an intervention in trust, not just a network measurement.
Facts
- The
--no-exitoption keeps traffic from daemonised processes reachable.
Recommendations
- Only use httptap in controlled test environments with expendable credentials.
- Take the separate localhost into account and remove temporary certificates after the analysis.
References
Links to the original source and the Web Archive open in a new tab.