CLI MITMプロキシで、SOCKS4/SOCKS5をHTTP/HTTPS/HTTP2/HTTP3プロキシに変換し、透過的なTCP/UDPリダイレクション、ARP/NDP/DNSスプーフィング、トラフィックスニッフィング、パケットキャプチャを備えています。Pure Go、libpcap不要。

GoHPTS CLIツールは、HTTPクライアントとSOCKS5プロキシサーバーまたは複数のサーバー(チェーン)の間のブリッジです。ローカルでHTTPプロキシとして待ち受け、標準のHTTPまたはHTTPS(CONNECT経由)リクエストを受け付け、SOCKS5プロキシを通じて接続を転送します。http-proxy-to-socksとProxychainsにインスパイアされています。
考えられるユースケース:Postman経由で外部APIに接続する必要があるが、そのAPIは特定のリモートサーバーからのみ利用可能な場合。以下のコマンドがそのようなタスクの実行に役立ちます:
ssh経由でSOCKS5プロキシサーバーを作成:```shell
ssh -D 1080 -Nf
`gohpts` で HTTP から SOCKS5 への接続を作成する```shell
gohpts -s :1080 -l :8080
Postman のプロキシ設定で http サーバーを指定する
プロキシチェーン機能
SOCKS4/SOCKS5 プロキシの strict、dynamic、random、round_robin チェーンをサポート
透過プロキシ
redirect (SO_ORIGINAL_DST) および tproxy (IP_TRANSPARENT) モードをサポート
IPv4 および IPv6 サポート
IPv4-only、IPv6-only、または dual stack モードで動作
TCP および UDP 透過プロキシ
tproxy および tlocal (IP_TRANSPARENT) が TCP および UDP トラフィックを処理
トラフィックスニッフィング
プロキシは HTTP ヘッダー、TLS ハンドシェイク、DNS メッセージなどを解析可能
ARP スプーフィング
ARP スプーフィング手法でサブネット全体をプロキシ
NDP スプーフィング
Router/Neighbor Advertisement および RDNSS インジェクションを使用して IPv6 接続をプロキシ。
DNS スプーフィング
DNS レコード操作によりクライアントを任意のドメインにリダイレクト
パケットキャプチャ
トラフィックを txt/pcap/pcapng ファイルにキャプチャし、Wireshark で分析
DNS リーク保護
DNS 解決は SOCKS5 サーバー側で実行されます。
CONNECT メソッドサポート
HTTP CONNECT トンネリングをサポートし、HTTPS やその他の TCP ベースプロトコルを可能にします。
HTTP2/HTTP3 サポート
最新の HTTP/2 および HTTP/3 トランスポートをサポートし、TLS 1.3 上で効率的な多重化接続を可能にします
ネットワーク名前空間サポート
リスニングソケットおよびアウトバウンド接続用のカスタム Linux ネットワーク名前空間をサポート
トレーラーヘッダーサポート
HTTP トレーラーヘッダーを処理
チャンク転送エンコーディング
チャンクおよびストリーミングレスポンスを処理
SOCKS5 認証サポート
SOCKS5 プロキシのユーザー名/パスワード認証をサポート。
HTTP 認証サポート
HTTP プロキシサーバーのユーザー名/パスワード認証をサポート。
軽量かつ高速
最小限のオーバーヘッドと効率的なリクエスト処理で設計。
クロスプラットフォーム
すべての主要なオペレーティングシステムと互換性があります。
または paru を使用する場合: ```shell
paru -S gohpts
- [Releases](https://github.com/shadowy-pycoder/go-http-proxy-to-socks/releases) ページからお使いのプラットフォーム用のバイナリをダウンロードしてください: ```shell
GOHPTS_RELEASE=v1.15.6; wget -v https://github.com/shadowy-pycoder/go-http-proxy-to-socks/releases/download/$GOHPTS_RELEASE/gohpts-$GOHPTS_RELEASE-linux-amd64.tar.gz -O gohpts && tar xvzf gohpts && mv -f gohpts-$GOHPTS_RELEASE-linux-amd64 gohpts && ./gohpts -h
go install コマンドを使用してインストールします(Go 1.26 以降が必要): ```shell
CGO_ENABLED=0 go install -ldflags "-s -w" -trimpath github.com/shadowy-pycoder/go-http-proxy-to-socks/cmd/gohpts@latest
これにより、gohpts バイナリが $GOPATH/bin ディレクトリにインストールされます。
[戻る]```shell gohpts -h
/ | | | | | __ _ / ____|
| | __ ___ | || | |) | | | | (__
| | |_ |/ _ | __ | / | | _
| |__| | () | | | | | | | ) |
_|_/|| ||| || |___/
GoHPTS: HTTP(S) Proxy to SOCKS4/SOCKS5 proxy by shadowy-pycoder GitHub: https://github.com/shadowy-pycoder/go-http-proxy-to-socks Codeberg: https://codeberg.org/shadowy-pycoder/go-http-proxy-to-socks
Usage: gohpts [OPTIONS] OPTIONS: General: -h Show this help message and exit -v Show version and build information -D Run as a daemon (provide -logfile to see logs) -I Display list of network interfaces and exit -f Path to proxy configuration file in YAML format
Proxy: -l Address of HTTP proxy server (Default: "127.0.0.1:8080" for IPv4, "[::1]:8080" for IPv6) -s Address of SOCKS proxy server (Default: "127.0.0.1:1080" for IPv4 "[::1]:1080" for IPv6) -c Path to certificate PEM encoded file -k Path to private key PEM encoded file -U User for HTTP proxy (basic auth). This flag invokes prompt for password (not echoed to terminal) -u User for SOCKS proxy authentication. This flag invokes prompt for password (not echoed to terminal) -i Bind proxy to specific network interface (either by interface name or index) -4 Force IPv4 stack for TCP and UDP (Default: dual stack) -6 Force IPv6 stack for TCP and UDP (Default: dual stack) -socks4 Use SOCKS4/SOCKS4a protocol for upstream proxy and mixed server (default: SOCKS5/SOCKS5h) -nohttp Disable HTTP proxy server -nosocks Disable SOCKS upstream proxy -dns Use custom DNS server (Example: "8.8.8.8" or "2001:4860:4860::8888") -mixed Accept SOCKS connections on HTTP proxy server address
Logs: -d Show logs in DEBUG mode -j Show logs in JSON format -logfile Log file path (Default: stdout) -nocolor Disable colored output for logs (no effect if -j flag specified) -pprof Address of pprof server with profiling data
Sniffing: -sniff Enable traffic sniffing for HTTP and TLS -snifflog Sniffed traffic log file path (Default: the same as -logfile) -body Collect request and response body for HTTP traffic (credentials, tokens, etc)