proxy-bypass.md (3891B)
1 --- 2 title: "Proxy Bypass" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/evasion/proxy-bypass.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/proxy-bypass.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Proxy Bypass 12 13 > An HTTP proxy server acts as an intermediary between a client (like a web browser) and a web server. It processes client requests for web resources, fetches them from the destination server, and returns them to the client. 14 15 ## Summary 16 17 * [Methodology](#methodology) 18 * [Discover Proxy Configuration](#discover-proxy-configuration) 19 * [PAC Proxy](#pac-proxy) 20 * [Common Bypass](#common-bypass) 21 * [References](#references) 22 23 ## Methodology 24 25 ### Discover Proxy Configuration 26 27 * Windows, in the registry key `DefaultConnectionSettings` 28 29 ```ps1 30 Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings 31 Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer 32 ``` 33 34 * Windows: 35 36 ```ps1 37 netsh winhttp show proxy 38 ``` 39 40 * Linux, in the environment variables `http_proxy` and `https_proxy` 41 42 ```ps1 43 env 44 cat /etc/profile.d/proxy.conf 45 ``` 46 47 ### PAC Proxy 48 49 PAC (Proxy Auto-Configuration) is a method to automatically determine whether web traffic should go through a proxy server. It uses a .pac file that contains a JavaScript function called `FindProxyForURL(url, host)`. 50 51 * proxy.pac 52 * wpad.dat 53 54 **Example**: 55 56 ```ps1 57 function FindProxyForURL(url, host) { 58 if (dnsDomainIs(host, '.example.com')) { 59 return 'DIRECT'; 60 } 61 return 'PROXY proxy.example.com:8080'; 62 } 63 ``` 64 65 **Tools**: 66 67 * [PortSwigger - Proxy Auto Config](https://portswigger.net/bappstore/7b3eae07aa724196ab85a8b64cd095d1) - This extension automatically configures Burp upstream proxies to match desktop proxy settings. This includes support for Proxy Auto-Config (PAC) scripts. 68 69 ### Common Bypass 70 71 * Try several way to reach the Internet 72 * IP address 73 * Domain categorized in Health/Finance 74 75 * Use another proxy reachable in the same environment 76 77 * Weak regular expression for URL can be abused to bypass the proxy configuration 78 79 ```ps1 80 user:pass@domain/endpoint?parameter#hash 81 e.g: microsoft.com:microsoft.com@microsoft.com.evil.com/microsoft.com?microsoft.com#microsoft.com 82 ``` 83 84 * Trusted Websites: [Living Off Trusted Sites (LOTS) Project](https://lots-project.com/) 85 * Amazon Cloud: AWS endpoints 86 * Microsoft Cloud: Azure endpoints 87 * Google Cloud: GCP endpoints 88 * live.sysinternals.com 89 90 * User-Agents 91 * Tools related User-Agent: curl, python, powershell 92 93 ```ps1 94 User-Agent: curl/8.11.0 95 User-Agent: python-requests/2.32.3 96 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; fr-FR) WindowsPowerShell/5.1.26100.2161 97 ``` 98 99 * Platform related User-Agent: Android/iOS/Tablet 100 101 ```ps1 102 Mozilla/5.0 (Linux; Android 14; Pixel 9 Build/AD1A.240905.004; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/129.0.6668.78 Mobile Safari/537.36 [FB_IAB/FB4A;FBAV/484.0.0.63.83;IABMV/1;] 103 Mozilla/5.0 (iPhone; CPU iPhone OS 18_0_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 [FBAN/FBIOS;FBAV/485.1.0.45.110;FBBV/665337277;FBDV/iPhone17,1;FBMD/iPhone;FBSN/iOS;FBSV/18.0.1;FBSS/3;FBCR/;FBID/phone;FBLC/it_IT;FBOP/80] 104 ``` 105 106 * Domain Fronting 107 * Protocols 108 * TCP 109 * Websocket (HTTP) 110 * DNS Exfiltration 111 112 ## References 113 114 * [Proxy managed by enterprise? No problem! Abusing PAC and the registry to get burpin’ - Thomas Grimée - August 17, 2021](https://blog.nviso.eu/2021/08/17/proxy-managed-by-enterprise-no-problem-abusing-pac-and-the-registry-to-get-burpin/) 115 * [Proxy: Internal Proxy - MITRE ATT&CK - March 14, 2020](https://attack.mitre.org/versions/v16/techniques/T1090/001/)