bk99.de entertain the web since 1997

Httptap: observing the HTTP(S) requests of local programs

Summary

Httptap shows the HTTP and HTTPS requests of any Linux program via an isolated, transparent network path. Every Linux network namespace has its own loopback interface. Httptap implements parts of IP, TCP and UDP in user space.

Ideas

  • A network namespace separates the examined process from the host network.
  • A TUN device routes all traffic into httptap's user space stack.
  • A transparent proxy reconstructs connections to the actual destination.
  • A temporary certificate authority enables HTTPS inspection of cooperating applications.
  • Daemonised children need continued proxying after the parent process exits.

Insights

  • Complete observation requires control over routing and trust at the same time.
  • Namespaces change the meaning of localhost for the processes examined.
  • TLS inspection is an intervention in trust, not just a network measurement.

Facts

  • The --no-exit option keeps traffic from daemonised processes reachable.

Recommendations

  • Only use httptap in controlled test environments with expendable credentials.
  • Take the separate localhost into account and remove temporary certificates after the analysis.

References

Read the original article

Search the Web Archive