Overview
Python Multi Threaded Tor Proxy,
Did you ever want to be at two different places at the same time?
When I asked myself this question, I actually started developing this solution in my mind.
While performing penetration tests there are often problems caused by security devices that block the "attacking" IP.
This really annoyed me, so I wrote a script to supply a solution for this problem.
With a large number of IP addresses performing the attacks, better results are guaranteed - especially when attempting attacks to bypass Web Application Firewalls, Brute-Force type attacks and many more.
[Blackhat Asia] https://www.blackhat.com/asia-17/arsenal.html#pymultitor
[Owasp-IL Presentation] https://www.owasp.org/images/3/3d/OWASPIL-2016-02-02_PyMultiTor_TomerZait.pdf
[DigitalWhisper Article (Hebrew)] http://www.digitalwhisper.co.il/files/Zines/0x2E/DW46-3-PyMultitor.pdf
Installation
Prerequisites
- Python 3.6+.
- mitmproxy (https://mitmproxy.com/).
- tor.
- On Ubuntu / Kali,
sudo apt install -y tor - On Centos,
sudo yum install -y tor - On Fedora,
sudo dnf install -y tor - On Windows,
- download tor expert bundle: https://www.torproject.org/download/tor/
- insert tor to your path environment:
{tor-win32-*_path}\Tor - if you don't know how remember tor.exe path and use
--tor-cmdargument on pymultitor (for example:pymultitor --tor-cmd "c:\Pentest\Web\tor-win32-0.2.9.9\Tor\tor.exe")
- On MacOS,
brew install tor
- On Ubuntu / Kali,
From pip
pip3 install pymultitor
You may need to use sudo, depending on your Python installation.
From Source
git clone https://github.com/realgam3/pymultitor.git
cd pymultitor
# Install python dependencies.
# Depending on your setup, one or both of these may require sudo.
pip3 install -r requirements.txt
python3 setup.py install
# Confirm that everything works
pymultitor --help
Bug reports on installation issues are welcome!
Usage
Basic Usage
- Run
pymultitor --on-string "Your IP Address Blocked". - On your script use proxy (
http://127.0.0.1:8080).
When the stringYour IP Address Blockedwill present in the response content, you will exit from another IP address.
Command Line Flags
See --help for the complete list, but in short:
Usage: pymultitor [-h] [-v] [-lh LISTEN_HOST] [-lp LISTEN_PORT] [-s] [-i] [-d]
[-p PROCESSES] [-c CMD] [--on-count ON_COUNT]
[--on-string ON_STRING] [--on-regex ON_REGEX] [--on-rst]
# When To Change IP Address
--on-count Change IP Every x Requests (Resources Also Counted).
--on-string Change IP When String Found On The Response Content.
--on-regex Change IP When Regex Found On The Response Content.
--on-rst Change IP When Connection Closed With TCP RST.
Release files for PyMultitor 3.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| PyMultitor-3.1.0.tar.gz | 6.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| PyMultitor-3.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.7 kB
Release files / PyMultitor-3.1.0.tar.gz
| Download URL | PyMultitor-3.1.0.tar.gz |
|---|---|
| Size | 6.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
141a986d95f1d363adb8093aa8662c57603b254906a1f16211a5309e1727b303
|
|
BLAKE2b-256 checksum How to use checksums |
fa8c3d00219af610ad61114220fc034d6b8cb4efe9c5d69621a526ec3467b829
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/40.6.2 requests-toolbelt/0.9.1 tqdm/4.40.0 CPython/3.7.2
|
Release files / PyMultitor-3.1.0-py3-none-any.whl
| Download URL | PyMultitor-3.1.0-py3-none-any.whl |
|---|---|
| Size | 19.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0cd4f042c74c9af82a450076cb5af5686e66016b058ebe1626e861e8da2d13cb
|
|
BLAKE2b-256 checksum How to use checksums |
d67dac702ee44a6ad3f7cdc59ff82aa0fb3fff4d5fdaf1fd605f99a7add3908c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/40.6.2 requests-toolbelt/0.9.1 tqdm/4.40.0 CPython/3.7.2
|