
Ratched는 침투 테스트를 목적으로 하는 투명 중간자(MITM) TLS 프록시입니다.
ratched는 TLS 연결을 가로채는 Man-in-the-Middle(MitM) 프록시입니다. Linux iptables REDIRECT 대상과 함께 사용하도록 설계되었습니다. 가로챌 모든 연결은 로컬 ratched 포트로 리디렉션될 수 있습니다. SO_ORIGINAL_DST 소켓 옵션을 통해 ratched는 원래 대상(iptables 패킷 변조 전)을 확인하고 원래 대상에 대한 연결을 설정하려고 시도합니다.
다른 MitM 소프트웨어와 차별화되는 점은 다음과 같습니다.
ratched는 모든 트래픽을 무차별적으로 가로채지 않습니다. 특히, 먼저 TLS 클라이언트가 ClientHello를 보낼 때까지 기다렸다가 ratched가 이를 파싱하고 서버 이름 표시 TLS 확장(SNI)을 기준으로 대상의 가로채기 여부를 결정합니다. 이는 가상 호스팅을 사용하지만 특정 호스트 이름에 대한 연결만 가로채려는 경우에 특히 유용합니다.
ratched는 비밀번호만 스니핑하기 위한 것이 아니라, 트래픽을 PCAPNG 파일에 덤프합니다. PCAPNG 파일 형식은 연결에 주석(특히 SNI 확장에 표시된 호스트 이름)을 추가할 수 있고, 이름 확인 정보를 캡처 파일에 포함시킬 수 있기 때문에 선택되었습니다(대상 IP 주소를 SNI 확장의 호스트 이름에 매핑).
ratched는 가로채는 각 SNI에 대해 개별 구성을 제공합니다. 여기에는 지원 그룹(이전의 "지원되는 타원 곡선"), 암호 스위트, 클라이언트 및 서버 측의 특정 TLS 버전이 포함되며, 가로채는 호스트별로 사용자 정의 인증서/키를 지정할 수 있습니다.
ratched는 클라이언트 인증서에 대한 광범위한 지원을 제공하며, 클라이언트 인증서에 대한 자동 위조 기능도 제공합니다(반대 방향의 위조된 서버 인증서와 유사).
ratched는 OCSP 스테이플링을 지원하며, 클라이언트가 상태 요청 TLS 확장을 보낼 때 긍정적인 OCSP 응답을 자동으로 위조할 수 있습니다.
ratched가 라우팅 머신(예시에서는 포트 9999)에서 수신 대기 중이면, 캡처하려는 트래픽을 지정하는 iptables 항목을 추가하기만 하면 됩니다. 예를 들어, 192.168.1.7에서 포트 443에 연결하려는 모든 트래픽을 가로채려면 다음을 사용하십시오:
# iptables -t nat -A PREROUTING -p tcp -s 192.168.1.7 --dport 443 -j REDIRECT --to-ports 9999
포트 443으로 향하는 모든 트래픽을 가로채려면 다음을 사용하십시오:
# iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-ports 9999
라우터 역할을 하며 로컬로 들어오는 트래픽을 가로채려면 REDIRECT 대신 DNAT 대상을 사용하십시오. 예:
# iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 443 -j DNAT --to 192.168.123.1:9999
여기서 eth1은 트래픽을 가로채는 인터페이스이고, 192.168.123.1은 로컬 인터페이스 IP 주소입니다.
도움말 페이지는 매우 명확해야 합니다:
usage: ratched [-c path] [-f hostname:port] [--single-shot] [--dump-certs]
[--keyspec keyspec] [--initial-read-timeout secs]
[--mark-forged-certificates] [--no-recalculate-keyids]
[--daemonize] [--logfile file] [--flush-logs] [--crl-uri uri]
[--ocsp-uri uri] [--write-memdumps-into-files]
[--use-ipv6-encapsulation] [-l hostname:port]
[-d key=value[,key=value,...]] [-i hostname[,key=value,...]]
[--pcap-comment comment] [-o filename] [-v]
ratched - TLS connection router that performs a man-in-the-middle attack
optional arguments:
-c path, --config-dir path
Configuration directory where the default root CA
certificate, CA keypair and server keypair are stored.
Defaults to ~/.config/ratched
-f hostname:port, --local-fwd hostname:port
When local connection to listening port is made, the
connection is discarded by default. Specifying this
option makes ratched forward to the given
hostname/port combination instead. Useful for testing
the proxy without the iptables REDIRECT.
--single-shot Only handle a single connection and terminate directly
after. Useful for debugging purposes.
--dump-certs Print created certificates for each intercepted
connection in the log file. Note that in many cases
you will also need to increase the log level to at
least DEBUG in order to see certificates.
--keyspec keyspec Specification for the private keys that should be
used. Can be either in the form "rsa:bitlen" or
"ecc:curvename". Valid choices, therefore, would be,
for example, "rsa:1024" or "ecc:secp256r1". Defaults
to rsa:2048
--initial-read-timeout secs
Specifies the amount of time in seconds (as a floating
point number) that ratched waits for the client to
provide its ClientHello before giving up. The default
is 1.0 secs.
--mark-forged-certificates
Include an OU=ratched entry to the subjects of all
created certificates (including dynamically forged
client certificates) for easy debugging.
--no-recalculate-keyids
When forging client certificates, by default the
subject and authority key identifiers are removed and
recreated to fit the actually used key ids. With this
option, they're used as-is (i.e., the key identifier
metadata will not fit the actually used keys). This
option might expose bugs in certain frameworks which
regard these identifiers as trusted information.
--daemonize Do not run in foreground mode, but in the background
as a daemon.
--logfile file Instead of logging to stderr, redirect logs to given
file.
--flush-logs Flush logfile after each call to logmsg(). Decreases
performance, but gives line-buffered logs.
--crl-uri uri Encode the given URI into the CRL Distribution Point
X.509 extension of server certificates.
--ocsp-uri uri Encode the given URI into the Authority Info Access
X.509 extension of server certificates as the OCSP
responder URI.
--write-memdumps-into-files
When dumping a piece of memory in the log, also output
its binary equivalent into a file called
hexdump_####.bin, where #### is an ascending number.
Useful for debugging of internal data structures.
--use-ipv6-encapsulation
For writing the PCAPNG file format, usually IPv4 is
emulated. This has the drawback that when one IPv4
endpoint serves multiple servers via the TLS Server
Name Indication extension, they cannot be
differentiated by their hostname. With this parameter,
ratched wraps the packets in IPv4-in-IPv6 emulation
and assigns different IPv6 addresses for different
server names, thus enabling accurate name resolution.
-l hostname:port, --listen hostname:port
Specify the address and port that ratched is listening
on. Defaults to 127.0.0.1:9999.
-d key=value[,key=value,...], --defaults key=value[,key=value,...]
Specify the server and client connection parameters
for all hosts that are not explicitly listed via a
--intercept option. Arguments are given in a key=value
fashion; valid arguments are shown below.
-i hostname[,key=value,...], --intercept hostname[,key=value,...]
Intercept only a specific host name, as indicated by
the Server Name Indication inside the ClientHello. Can
be specified multiple times to include interception or
more than one host. Additional arguments can be
specified in a key=value fashion to further define
interception parameters for that particular host.
--pcap-comment comment
Store a particular piece of information inside the
PCAPNG header as a comment.
-o filename, --outfile filename
Specifies the PCAPNG file that the intercepted traffic
is written to. Mandatory argument.
-v, --verbose Increase logging verbosity.
The arguments which are valid for the --intercept argument are as follows:
intercept=[opportunistic|mandatory|forward|reject]
Specifies the mode that ratched should act in for
this particular connection. Opportunistic TLS
interception is the default; it means that TLS
interception is tried first. Should it fail, however
(because someone tries to send non-TLS traffic), it
falls back to 'forward' mode (i.e., forwarding all
data unmodified). Mandatory TLS interception means
that if no TLS interception is possible, the
connection is terminated. 'forward', as explained,
simply forwards everything unmodified. 'reject'
closes the connection altogether, regardless of the
type of seen traffic.
s_tlsversions=versions
Colon-separated string that specifies the acceptable
TLS version for the ratched server component. Valid
elements are ssl2, ssl3, tls10, tls11, tls12, tls13.
Defaults to tls10:tls11:tls12.
s_reqclientcert=bool Ask all connecting clients to the server side of the
TLS proxy for a client certificate. If not
replacement certificate (at least certfile and
keyfile) is given, forge all metadata of the incoming
certificate. If a certfile/keyfile is given, this
option is implied.
s_send_rot=bool By default, the ratched TLS server does not include
its own root of trust (RoT) CA certificate in the
server certificates list. With this option, it is
added to the certificates sent to its peer.
s_certfile=filename Specifies an X.509 certificate in PEM format that
should be used by ratched as the server certificate.
By default, this certificate is automatically
generated. Must be used in conjunction with
s_keyfile.
s_keyfile=filename Specifies the private key for the given server
certificate, in PEM format.
s_chainfile=filename Specifies the X.509 certificate chain that is to be
sent to the client, in PEM format.
s_cacert=filename The X.509 CA certificate that issues server
certificates, in PEM format.
s_cakey=filename The X.509 CA certificate key that signs server
certificates, in PEM format.
s_ciphers=ciphers The cipher suite string that the ratched TLS server
uses.
s_groups=groups The key agreement 'supported groups' string (formerly
known as 'elliptic curves') that the ratched TLS
server uses.
s_sigalgs=algs The key agreement 'signature algorithms' string which
the ratched TLS server uses.
s_ocsp=bool Respond to clients requesting an OCSP status request
by sending an OCSP ticket as a response. Enabled by
default.
c_tlsversions=versions
Colon-separated string that specifies the acceptable
TLS version for the ratched client component. Valid
elements are ssl2, ssl3, tls10, tls11, tls12, tls13.
Defaults to tls10:tls11:tls12.
c_certfile=filename Specifies an X.509 certificate in PEM format that
should be used by ratched as a client certificate. It
will only be used when the connecting client also
provided a client certificate. Must be used in
conjunction with c_keyfile.
c_keyfile=filename The private key for the given client certificate, in
PEM format.
c_chainfile=filename The X.509 certificate chain that is to be sent to the
server, in PEM format.
c_ciphers=ciphers The cipher suite string that the ratched TLS client
uses.
c_groups=groups The key agreement 'supported groups' string (formerly
known as 'elliptic curves') that the ratched TLS
client uses.
c_sigalgs=algs The key agreement 'signature algorithms' string which
the ratched TLS client uses.
examples:
$ ratched -o output.pcapng
Open up local port 9999 and listen for incoming connections, intercept
all TLS traffic and write output into given capture file.
$ ratched -f google.com:443 -o output.pcapng
Same as before, but redirect all traffic of which the destination cannot
be determined (e.g., local connections to port 9999) to google.com on
port 443.
$ ratched -vvv --dump-certs -o output.pcapng
Be much more verbose during interception and also print out forged
certificates in the log.
$ ratched --defaults intercept=forward -intercept --intercept www.johannes-bauer.com -o output.pcapng
Do not generally intercept connections (but rather forward all traffic
unmodified) except for connections with Server Name Indication
www.johannes-bauer.com, on which interception is performed.
$ ratched --intercept www.johannes-bauer.com,s_reqclientcert=true -o output.pcapng
Generally do not request client certificates from connecting peers
except for connections with Server Name Indication www.johannes-
bauer.com, where clients are sent a CertificateRequest TLS message. If
clients do not provide a client certificate, just use regular TLS
interception. If they do provide a client certificate, forge all client
certificate metadata and use the forged client certificate in the
connection against the real server.
$ ratched --intercept www.johannes-bauer.com,c_certfile=joe.crt,c_keyfile=joe.key -o output.pcapng
Same as before, but for connections to johannes-bauer.com, do not forge
client certificates, but always use the given client certificate and key
(joe.crt / joe.key) for authentication against the server.
$ ratched --keyspec ecc:secp256r1 --ocsp-uri http://www.ocsp-server.com -o output.pcapng
Choose secp256r1 instead of RSA-2048 for all used certificates and
encode an OCSP Responder URI into those forged certificates as well.
$ ratched --initial-read-timeout 5.0 --default intercept=mandatory -o output.pcapng
Wait five seconds for connecting clients to send a valid ClientHello
message. If after five seconds nothing is received or if unknown (non-
TLS) traffic is received, terminate the connection instead of performing
unmodified forwarding.
"ratched"라는 이름은 "뻐꾸기 둥지 위로 날아간 새"의 간호사 래치드(Ratched)를 암시합니다. 이 도구를 사용하여 사람들을 감시한다면, 당신은 완전한 쓰레기이며 권력을 남용하는 것입니다. 영화를 꼭 보시기 바랍니다. ratched를 책임감 있게 사용하여 인프라의 보안을 향상시키는 데 사용하고, 약화시키지 마십시오. 스파이 목적의 TLS 가로채기는 비열하고 위험합니다.
ratched는 최소 OpenSSL v1.1이 필요합니다.
ratched는 GNU GPL-3 라이선스에 따라 배포됩니다.