MITM Proxy - How to intercept user requests in reverse proxy mode from inside/outside Web Application Server

Viewed 1670

I am new to mitm. https://mitmproxy.org/

AppServer1 (A windows 2016 server) has our IIS website application (WebApp1) running (its running fine without any problems currently). I have added an SSL certificate as well, and it is loading fine without any issues.Chrome shows that it is trusted ("Connection is secure" when navigating from inside and outside AppServer1 server but "within the LAN". So far we havnt allowed access to internet users as of yet until the app is completely ready.)

We have a business requirement where

  • we need to intercept all traffic/requests from users from outide AppServer1
  • and send them to another application that we created (UserRequestDashboardApp),
  • and ALSO we need mitm to send it to WebApp1 as well.

I have read the articles multiple times and from what I understand, reverse proxy mode is the correct option to for our requirement.

WebApp1 is running on url - customappservice1.com, port - 443

I then started mitm (version 4.0.4) with the following CMD command

.\mitmdump -p 8080 --mode reverse:https://customappservice1.com

I get the status proxy server listening at http://*:8080

I dont seem to see any traffic in the terminal when I type customappservice1.com on AppServer1 chrome browser or any server browser outside AppServer1. The WebApp1 pages load fine from outside and inside AppServer1 server but no traffic at all on the terminal

Can anyone please help me to capture the traffic on the terminal as an initial step before sending the traffic/requests to UserRequestDashboardApp AND WebApp1?

I have tried running mitm normally and it works fine(I can see traffic/requests fine in the terminal)

  • I launched mitm in CMD (It says Proxy Server listening at http://*:8080)
  • I set the
    • Windows server proxy to = localhost
    • Port = 8080
1 Answers

Did you try configuring your requests to use the mitmproxy's address ?

Also, web browsers may have use a separate proxy configuration from the operating system's. So you may try configuring Chrome's proxy settings.

Related