v1.12.0b (beta) – MITM Proxy & Ad‑Blocking
Pre-release
Pre-release
v1.12.0b (beta) – MITM Proxy & Ad‑Blocking
This beta release introduces an optional MITM proxy that intercepts HTTPS traffic, decrypts it, forwards DoH queries to phantomd, and can inject an ad‑blocking script into web pages.
✨ Added
- MITM proxy (Rust) – a standalone binary
phantomd-mitmthat:- Terminates TLS connections using a dynamically generated leaf certificate.
- Detects DoH requests (
POST /dns-querywithapplication/dns-message) and forwards them to phantomd via a Unix socket. - Optionally injects a JavaScript snippet to remove common ad elements (configurable).
- Forwards non‑DoH HTTPS traffic unchanged (or drops it, depending on
forward_non_doh).
- New
[mitm]section inphantomd.conf– all options documented. - Installer now downloads pre‑compiled binaries for
x86_64andaarch64from GitHub releases (fallback to source compilation only if download fails).
🛠️ Changed
installer.sh– added Rust toolchain only as fallback; by default downloads the binary.- GitHub Actions – builds
phantomd-mitmon tag pushes and attaches binaries to the release. core/dserver.py– addedDoHSocketHandlerto receive DNS queries from the proxy.main.py– generates the TOML config for the proxy and manages the systemd service.
🧪 Testing (beta)
- 142 Python tests all pass.
📦 Upgrading to v1.12.0b
- Fresh install:
./installer.sh - Update existing installation:
./installer.sh --update
Then edit/opt/phantomd/config/phantomd.confand add the[mitm]section (see example below). - Enable MITM proxy:
- Set
enabled = trueunder[mitm]in the config. - Install the root CA certificate from
/var/lib/phantomd-mitm/ca/ca.certon all clients. - Redirect port 443 to the proxy using iptables (example provided in the README).
- Restart phantomd:
systemctl restart phantomd
- Set
Example configuration snippet
[mitm]
enabled = true
listen_ip = 0.0.0.0
listen_port = 8443
socket_path = /tmp/phantomd_doh.sock
ad_block_enabled = true
forward_non_doh = true
ca_dir = /var/lib/phantomd-mitm/ca
cert_cache_ttl = 3600```
### ⚠️ Known limitations
- Does not support HTTP/2 yet (only HTTP/1.1).
- Certificate pinning in some apps (e.g., banking, social media) will cause connection errors.
- High CPU usage under heavy load (Rust is fast, but still a proxy).
- Ad‑block injection is basic (removes elements by class/id) – not as complete as browser extensions.
**Full Changelog**: https://github.com/KianiDev/phantomd/compare/v.1.11.1...v1.12.0b