Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up

Automatic SSL Pinning for golang net/http client

License

NotificationsYou must be signed in to change notification settings

rustler47/SecureClient

Repository files navigation

Automatic SSL Pinning

Secure the standard net/http client withSSL pinning to prevent users from sniffing requests with aMan-In-The-Middle proxy

This package takes in a list of hosts and provides a function to create net/http clients with SSL Pinning.For best practices

pinner, err := SecureClient.New(hosts, requireAll, BadPinDetected)

Should be called on startup (typically in main()), and whenever a client is needed you may call

client, err := pinner.NewClient(proxy)

The SSL Pins only need to be generated once per program runmax, which is done inSecureClient.New().

Future plans include storing SSL Pins to file and updating them once a week or so. I'm pretty sure the pins shouldnt change for a good bit of time.

Example Usage

Example 1 - Seetests

Here is the output from example 1 on SNS.Example 1

The first test was done without any MITM sniffer and succeeded (unproxied, a valid connection).

The second test was done using Postman Request interceptor (the standard proxy onlocalhost:5555)

Example 2

package mainimport ("fmt""github.com/rustler47/SecureClient")func main() {fmt.Println("SSL Pinning test\n\n")MITMProxy  := "http://localhost:5555"hosts := []string{ "kith.com" }BadPinDetected := func(proxy string){fmt.Println("WARNING! Failed SSL pinning - Invalid cert detected\n", "Proxy:", proxy)}pinner, err := SecureClient.New(hosts, true, BadPinDetected)if err != nil { return }client, err := pinner.NewClient(MITMProxy)if err != nil { return }client.Get("https://kith.com")pause := make(chan bool, 1)<-pause}

Tips

BadPinDetected fires when the SSL pin is not matched, and passes in the proxy which triggered the bad connection. This is a perfect place to send a message to an API to flag the user and/or disable their key

References

tam7t/hpkp

About

Automatic SSL Pinning for golang net/http client

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages


[8]ページ先頭

©2009-2025 Movatter.jp