
SOCKS4/SOCKS5를 HTTP/HTTPS/HTTP2/HTTP3 프록시로 변환하고 투명 TCP/UDP 리디렉션, ARP/NDP/DNS 스푸핑, 트래픽 스니핑 및 패킷 캡처를 지원하는 CLI MITM 프록시입니다. 순수 Go로 작성되었으며 libpcap이 필요하지 않습니다.

GoHPTS CLI 도구는 HTTP 클라이언트와 SOCKS5 프록시 서버 또는 여러 서버(체인) 사이의 다리 역할을 합니다. 로컬에서 HTTP 프록시로 수신 대기하며, 표준 HTTP 또는 HTTPS(CONNECT를 통한) 요청을 수락하고 SOCKS5 프록시를 통해 연결을 전달합니다. http-proxy-to-socks와 Proxychains에서 영감을 받았습니다.
가능한 사용 사례: Postman을 통해 외부 API에 연결해야 하지만, 이 API가 특정 원격 서버에서만 사용 가능한 경우입니다. 다음 명령어들이 이러한 작업을 수행하는 데 도움이 될 것입니다:
ssh를 통해 SOCKS5 프록시 서버 생성:```shell
ssh -D 1080 -Nf
`gohpts`로 HTTP-to-SOCKS5 연결 생성```shell
gohpts -s :1080 -l :8080
Postman의 프록시 구성에서 http 서버 지정
프록시 체인 기능
SOCKS4/SOCKS5 프록시의 strict, dynamic, random, round_robin 체인을 지원합니다
투명 프록시
redirect (SO_ORIGINAL_DST) 및 tproxy (IP_TRANSPARENT) 모드를 지원합니다
IPv4 및 IPv6 지원
IPv4-only, IPv6-only 또는 dual stack 모드로 동작합니다
TCP 및 UDP 투명 프록시
tproxy 및 tlocal (IP_TRANSPARENT)이 TCP 및 UDP 트래픽을 처리합니다
트래픽 스니핑
프록시는 HTTP 헤더, TLS 핸드셰이크, DNS 메시지 등을 파싱할 수 있습니다
ARP 스푸핑
ARP 스푸핑 방식을 사용하여 전체 서브넷을 프록시합니다
NDP 스푸핑
Router/Neighbor Advertisement 및 RDNSS 주입을 사용하여 IPv6 연결을 프록시합니다.
DNS 스푸핑
DNS 레코드 조작을 사용하여 클라이언트를 임의의 도메인으로 리디렉션합니다
패킷 캡처
트래픽을 txt/pcap/pcapng 파일로 캡처하고 Wireshark로 분석합니다
DNS 누출 방지
DNS 확인은 SOCKS5 서버 측에서 수행됩니다.
CONNECT 메서드 지원
HTTP CONNECT 터널링을 지원하여 HTTPS 및 기타 TCP 기반 프로토콜을 사용할 수 있습니다.
HTTP2/HTTP3 지원
최신 HTTP/2 및 HTTP/3 전송을 지원하여 TLS 1.3을 통한 효율적인 다중화 연결을 가능하게 합니다
네트워크 네임스페이스 지원
리스닝 소켓 및 아웃바운드 연결을 위한 사용자 정의 Linux 네트워크 네임스페이스를 지원합니다
트레일러 헤더 지원
HTTP 트레일러 헤더를 처리합니다
청크 전송 인코딩
청크 및 스트리밍 응답을 처리합니다
SOCKS5 인증 지원
SOCKS5 프록시에 대한 사용자 이름/비밀번호 인증을 지원합니다.
HTTP 인증 지원
HTTP 프록시 서버에 대한 사용자 이름/비밀번호 인증을 지원합니다.
경량 및 고속
최소한의 오버헤드와 효율적인 요청 처리를 위해 설계되었습니다.
크로스 플랫폼
모든 주요 운영 체제와 호환됩니다.
또는 paru를 사용하여: ```shell
paru -S gohpts
- [Releases](https://github.com/shadowy-pycoder/go-http-proxy-to-socks/releases) 페이지에서 사용 중인 플랫폼에 맞는 바이너리를 다운로드하세요: ```shell
GOHPTS_RELEASE=v1.15.6; wget -v https://github.com/shadowy-pycoder/go-http-proxy-to-socks/releases/download/$GOHPTS_RELEASE/gohpts-$GOHPTS_RELEASE-linux-amd64.tar.gz -O gohpts && tar xvzf gohpts && mv -f gohpts-$GOHPTS_RELEASE-linux-amd64 gohpts && ./gohpts -h
go install 명령을 사용하여 설치합니다 (Go 1.26 이상 필요): ```shell
CGO_ENABLED=0 go install -ldflags "-s -w" -trimpath github.com/shadowy-pycoder/go-http-proxy-to-socks/cmd/gohpts@latest
이 명령은 gohpts 바이너리를 $GOPATH/bin 디렉터리에 설치합니다.
[뒤로]```shell gohpts -h
/ | | | | | __ _ / ____|
| | __ ___ | || | |) | | | | (__
| | |_ |/ _ | __ | / | | _
| |__| | () | | | | | | | ) |
_|_/|| ||| || |___/
GoHPTS: HTTP(S) Proxy to SOCKS4/SOCKS5 proxy by shadowy-pycoder GitHub: https://github.com/shadowy-pycoder/go-http-proxy-to-socks Codeberg: https://codeberg.org/shadowy-pycoder/go-http-proxy-to-socks
Usage: gohpts [OPTIONS] OPTIONS: General: -h Show this help message and exit -v Show version and build information -D Run as a daemon (provide -logfile to see logs) -I Display list of network interfaces and exit -f Path to proxy configuration file in YAML format
Proxy: -l Address of HTTP proxy server (Default: "127.0.0.1:8080" for IPv4, "[::1]:8080" for IPv6) -s Address of SOCKS proxy server (Default: "127.0.0.1:1080" for IPv4 "[::1]:1080" for IPv6) -c Path to certificate PEM encoded file -k Path to private key PEM encoded file -U User for HTTP proxy (basic auth). This flag invokes prompt for password (not echoed to terminal) -u User for SOCKS proxy authentication. This flag invokes prompt for password (not echoed to terminal) -i Bind proxy to specific network interface (either by interface name or index) -4 Force IPv4 stack for TCP and UDP (Default: dual stack) -6 Force IPv6 stack for TCP and UDP (Default: dual stack) -socks4 Use SOCKS4/SOCKS4a protocol for upstream proxy and mixed server (default: SOCKS5/SOCKS5h) -nohttp Disable HTTP proxy server -nosocks Disable SOCKS upstream proxy -dns Use custom DNS server (Example: "8.8.8.8" or "2001:4860:4860::8888") -mixed Accept SOCKS connections on HTTP proxy server address
Logs: -d Show logs in DEBUG mode -j Show logs in JSON format -logfile Log file path (Default: stdout) -nocolor Disable colored output for logs (no effect if -j flag specified) -pprof Address of pprof server with profiling data
Sniffing: -sniff Enable traffic sniffing for HTTP and TLS -snifflog Sniffed traffic log file path (Default: the same as -logfile) -body Collect request and response body for HTTP traffic (credentials, tokens, etc)