Skip to content

v1.12.0b (beta) – MITM Proxy & Ad‑Blocking

Pre-release
Pre-release

Choose a tag to compare

@33xception 33xception released this 27 Apr 14:31
· 6 commits to master since this release

v1.12.0b (beta) – MITM Proxy & Ad‑Blocking

This beta release introduces an optional MITM proxy that intercepts HTTPS traffic, decrypts it, forwards DoH queries to phantomd, and can inject an ad‑blocking script into web pages.

⚠️ This is a pre‑release – the MITM proxy is experimental. Any feedback on added features will be appreciated.


✨ Added

  • MITM proxy (Rust) – a standalone binary phantomd-mitm that:
    • Terminates TLS connections using a dynamically generated leaf certificate.
    • Detects DoH requests (POST /dns-query with application/dns-message) and forwards them to phantomd via a Unix socket.
    • Optionally injects a JavaScript snippet to remove common ad elements (configurable).
    • Forwards non‑DoH HTTPS traffic unchanged (or drops it, depending on forward_non_doh).
  • New [mitm] section in phantomd.conf – all options documented.
  • Installer now downloads pre‑compiled binaries for x86_64 and aarch64 from GitHub releases (fallback to source compilation only if download fails).

🛠️ Changed

  • installer.sh – added Rust toolchain only as fallback; by default downloads the binary.
  • GitHub Actions – builds phantomd-mitm on tag pushes and attaches binaries to the release.
  • core/dserver.py – added DoHSocketHandler to receive DNS queries from the proxy.
  • main.py – generates the TOML config for the proxy and manages the systemd service.

🧪 Testing (beta)

  • 142 Python tests all pass.

📦 Upgrading to v1.12.0b

  • Fresh install: ./installer.sh
  • Update existing installation: ./installer.sh --update
    Then edit /opt/phantomd/config/phantomd.conf and add the [mitm] section (see example below).
  • Enable MITM proxy:
    • Set enabled = true under [mitm] in the config.
    • Install the root CA certificate from /var/lib/phantomd-mitm/ca/ca.cert on all clients.
    • Redirect port 443 to the proxy using iptables (example provided in the README).
    • Restart phantomd: systemctl restart phantomd

Example configuration snippet

[mitm]
enabled = true
listen_ip = 0.0.0.0
listen_port = 8443
socket_path = /tmp/phantomd_doh.sock
ad_block_enabled = true
forward_non_doh = true
ca_dir = /var/lib/phantomd-mitm/ca
cert_cache_ttl = 3600```

### ⚠️ Known limitations
- Does not support HTTP/2 yet (only HTTP/1.1).
- Certificate pinning in some apps (e.g., banking, social media) will cause connection errors.
- High CPU usage under heavy load (Rust is fast, but still a proxy).
- Ad‑block injection is basic (removes elements by class/id) – not as complete as browser extensions.

**Full Changelog**: https://github.com/KianiDev/phantomd/compare/v.1.11.1...v1.12.0b