Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid MITM: How to retrieve decrypted data?

    Scheduled Pinned Locked Moved Cache/Proxy
    squidmitmman-in-the-middtlsssl
    5 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zll
      last edited by

      Since the whole point of MITM is to look at the data going by, I'm a bit surprised that there doesn't seem to be an obvious way to retrieve the decrypted payload. What am I missing here? Is this buried somewhere in the web GUI? (The Diagnostics->Payload capture facility does not decrypt the data.)

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        It's decrypted for processing by squid, not for logging/dumping the content in a general way. It gets passed to things like squidGuard for URL matching or clamav for content checking.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • Z
          zll
          last edited by

          That's interesting. I can definitely see the utility of URL matching and filtration. But my problem, as they say, is different. I'm trying to crack the protocol that one of my desktop apps is using to communicate with a remote server. Since the data obviously gets decrypted (to facilitate the URL matching), there must be a way to get at it somehow... Perhaps there is a pfSense package that does this?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            No, there is no package for that. You would have to find or make some kind of c-icap processing program to dig at the data.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • Z
              zll
              last edited by

              Thanks for the info. Astounding is what this is. :-)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.