Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Prox-Ez — 用于测试 Windows 身份验证机制的 HTTP/HTTPS 拦截代理,支持 NTLM、Kerberos、哈希传递、票据传递和中继攻击,并内置用于中间人攻击的证书生成功能。 | Kitploit
工具/GitHubGitHub/synacktiv/prox-ez
Web代理与拦截冒充工具横向移动后渗透利用渗透测试身份验证红队
GitHubsynacktiv/prox-ez

Prox-Ez

用于测试 Windows 身份验证机制的 HTTP/HTTPS 拦截代理,支持 NTLM、Kerberos、哈希传递、票据传递和中继攻击,并内置用于中间人攻击的证书生成功能。

查看仓库
11011263个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Prox-Ez:HTTP 认证的瑞士军刀

这个 HTTP 代理会代表你处理所有 HTTP 认证。

它支持 NTLM EPA(通道绑定和服务绑定)、Kerberos、哈希传递(pass-the-hash)、overpass-the-hash(密钥传递,pass-the-key)以及票据传递(pass-the-ticket,支持 TGT 和 TGS)。

相关文章:

  • 深入剖析 NTLM EPA 并构建一个 MitM 代理
  • Windows HTTP 认证研究(第二部分)

安装

  1. 安装依赖项
$ # In a venv
$ python3 -m venv venv
$ source venv/bin/activate
$ python3 -m pip install -r requirements.txt

或者你可以使用 pip/pipx 直接安装该项目

$ # With pip
$ pip3 install git+https://github.com/synacktiv/Prox-Ez
$ # With pipx
$ pipx install git+https://github.com/synacktiv/Prox-Ez
  1. 尽情享受吧。

用法

快速开始

像这样运行,它会在任何需要认证的网站上尝试使用凭据 mydomain/myusername:mypassword 进行认证:

python3 proxy.py -dc mydomain/myusername:mypassword

相同,但使用 NT 哈希代替密码:

python3 proxy.py -dc mydomain/myusername --hashes :31d6cfe0d16ae931b73c59d7e0c089c0

与 BurpSuite 配合使用

为了与 BurpSuite 配合使用:

  • 禁用 HTTP/2 支持:Project options -> HTTP -> HTTP/2 -> 取消勾选 Enable HTTP/2
  • 取消勾选 Set response header "Connection: close",因为 NTLM 对一个 TCP 连接进行认证:Proxy -> Options -> Miscellaneous -> 取消勾选 Set response header "Connection: close"。
  • 取消勾选 Set "Connection" header on incoming requests when using HTTP/1:Proxy -> Options -> Miscellaneous -> 取消勾选 Set "Connection" header on incoming requests when using HTTP/1

之后,你只需在 Burp 中指定一个上游代理,这样它就会在你无法认证的主机上使用这个代理:

  • 在 Project options -> Connections -> Upstream Proxy Servers 中点击 Add -> 指定导致 NTLM 认证问题的主机名、工具中配置的代理主机和端口,并将 Authentication type 设置为 None。
  • 如果启用了 SOCKS 代理,你可能还需要禁用它。

帮助

$ python3 proxy.py -h
usage: proxy.py [-h] [--listen-address LISTEN_ADDRESS] [--listen-port LISTEN_PORT] [--cacert CACERT] [--cakey CAKEY] [--cakey-pass CAKEY_PASS] [--certsdir CERTSDIR] [--singleprocess] [--debug] [--dump-keys DUMP_KEYS] [--creds CREDS]
                [--default-creds DEFAULT_CREDS] [--hashes HASHES] [--kerberos] [--dcip DCIP] [--spn SPN] [--spn-force-fqdn] [--no-epa]

Prox-Ez: The Swiss Army Knife of HTTP auth.

optional arguments:
  -h, --help            show this help message and exit
  --listen-address LISTEN_ADDRESS, -l LISTEN_ADDRESS
                        Address the proxy will be listening on, defaults to 127.0.0.1.
  --listen-port LISTEN_PORT, -p LISTEN_PORT
                        Port the proxy will be listening on, defaults to 3128.
  --cacert CACERT       Filepath to the CA certificate, defaults to ./cacert.pem. Will be created if it does not exists.
  --cakey CAKEY         Filepath to the CA private key, defaults to ./cakey.pem. Will be created if it does not exists.
  --cakey-pass CAKEY_PASS
                        CA private key passphrase.
  --certsdir CERTSDIR   Path to the directory the generated certificates will be stored in, defaults to /tmp/Prox-Ez. Will be created if it does not exists.
  --singleprocess, -sp  Do you want to be slowwwww ?! Actually useful during debug.
  --debug, -d           Increase debug output.
  --dump-keys DUMP_KEYS, -dk DUMP_KEYS
                        File to dump the SSL/TLS keys to. Useful when trying to debug. When this option is specified, --singleprocess is implied.
  --creds CREDS         Path to the credentials file, for instance: { "my.hostname.com": { "creds": "domain/user:password", "spn": "HTTP/anothername" }, "my.second.hostname.com": { "creds": "domain1/user1", "hashes": ":nthash1" } }
  --default-creds DEFAULT_CREDS, -dc DEFAULT_CREDS
                        Default credentials that will be used to authenticate.
  --hashes HASHES       Could be used instead of password. It is associated with the domain and username given via --default_creds. format: lmhash:nthash or :nthash.
  --kerberos, -k        Enable kerberos authentication instead of NTLM.
  --dcip DCIP           IP Address of the domain controller (only for kerberos).
  --spn SPN             Use the provided SPN when an SPN is needed. More details in the article.
  --spn-force-fqdn      Force the usage of the FQDN as the SPN instead of what was specified in the URL.
  --no-epa              Deactivate the NTLM EPA feature.

已知问题

  • 不支持 WebSocket。它会产生断言错误,例如:
DEBUG:Proxy.ProxyToServerHelper:Our state: MIGHT_SWITCH_PROTOCOL; their state: SEND_RESPONSE
[...]
    assert self.conn.our_state in [h11.DONE, h11.MUST_CLOSE, h11.CLOSED] and self.conn.their_state is h11.SEND_RESPONSE
AssertionError
下载工具