Hostile 92% rust 53 installs Download

abyss-mitm 1.0.2

TLS interception and MITM

“TLS interception and HTTP stream handling for the Abyss runtime”

Duplicate Content-Length desync probe in sourceDuplicate Content-Length headers in source

Evidence

imports http::uri::Authority lines 1–21
1//! Explicit HTTP proxy request decoding and normalization.
2//!
3//! The broker listener owns accepted sockets, target resolution, and proxy
4//! responses. This module only consumes the first bounded HTTP/1.1 request head,
5//! validates explicit-proxy semantics, and returns the target plus bytes that
6//! must be replayed into the shared MITM pipeline. `CONNECT` payload bytes are
7//! preserved unchanged, while absolute-form HTTP requests are rewritten to
8//! origin form and stripped of proxy-only credentials and headers.
9
10use std::{fmt, io, net::IpAddr, str, time::Duration};
11
12use http::{Uri, uri::Authority};
13use thiserror::Error;
14use tokio::{
15 io::{AsyncRead, AsyncReadExt as _},
16 time,
17};
18
19const HEADER_READ_CHUNK_BYTES: usize = 1024;
20const MAX_EXPLICIT_PROXY_HEADERS: usize = 64;
21const …
Contains an unbounded block loop lines 361–364
361:34… h_capacity(HEADER_READ_CHUNK_BYTES.min(self.max_header_bytes));
362 loop {
363 // Stop as soon as the HTTP head terminator is present. Any bytes
364 // after it are preserved so the MITM …
Network destination assigned from call lines 545–552
545:17… rr(invalid_target(raw, "port must not be zero"));
546 }
547 let host =
548 normalize_target_host(authority.host()).map_err(|reason| invalid_target(raw, reason))?;
549 Ok(TargetAuthority { host, port })
550}
551
552/// Normalizes the h …
Multiple standard HTTP request lines in source lines 973–986
973 async fn rejects_ambiguous_absolute_http_framing() {
974 let error = decode_once(
975 concat!(
976 "POST http://api.example.com/ HTTP/1.1\r\n",
977 "Host: api.example.com\r\n",
978 "Content-Length: 4\r\n",
979 "Transfer-Encoding: chunked\r\n",
980 "\r\n"
981 )
⋯5 lines
Duplicate Content-Length headers in source lines 994–1009
994:16… cat!(
995 "POST http://api.example.com/ HTTP/1.1\r\n",
996 "Host: api.example.com\r\n",
997 "Content-Length: 3\r\n",
998 "Content-Length: 4\r\n",
999 "\r\n"
1000 ),
1001 concat!(
1002 "POST http://api.example.com/ HTTP/1.1\r\n",
1003 "Host: api.example.com\r\n",
1004 "Transfer-Encoding: chunked, gzip\r\n",
⋯5 lines

Showing the top 5 files — 7 more files (68 regions) not shown.

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.