anyproxy icon indicating copy to clipboard operation
anyproxy copied to clipboard

微信公众号五月底Anyproxy代理正常,现在不能解析https,显示验证失效

Open shinanL opened this issue 6 years ago • 11 comments

Plese fill the template when you reporting a new issue, thanks!

Which platform are you running AnyProxy

Mac

The version of the AnyProxy

4.1.0

Your expected behavior of AnyProxy

五月底我通过anyproxy能够拦截公众号文章https响应,看到明文信息。现在只能看到图片(也是https),没有文章文本信息。而且请求的第一个URL是进行验证的,我觉得是和这个有关,附上URL: https://mp.weixin.qq.com/mp/geticon?__biz=MjM5MzA0MTg2MA==&r=0.3363449561230647,html中说,“失效的验证页面”。 同时日志显示will forward to local https server 证书经过多次卸载重装确认是没有问题的。期待官方反馈。

The actual behavior of AnyProxy

不能解析公众号https文本信息

The log of the error

[AnyProxy Log][2019-09-24 15:35:02]: [internal https]proxy server for sina.cn established [AnyProxy ERROR][2019-09-24 15:35:02]: Error: read ECONNRESET [AnyProxy Log][2019-09-24 15:35:06]: received https CONNECT request mmbiz.qpic.cn [AnyProxy Log][2019-09-24 15:35:06]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:06]: [internal https]proxy server for mmbiz.qpic.cn established [AnyProxy ERROR][2019-09-24 15:35:06]: Error: read ECONNRESET [AnyProxy Log][2019-09-24 15:35:09]: received https CONNECT request mp.weixin.qq.com [AnyProxy Log][2019-09-24 15:35:09]: received https CONNECT request mp.weixin.qq.com [AnyProxy Log][2019-09-24 15:35:09]: received https CONNECT request mp.weixin.qq.com [AnyProxy Log][2019-09-24 15:35:09]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:09]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:09]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:09]: [internal https]proxy server for mp.weixin.qq.com established [AnyProxy Log][2019-09-24 15:35:09]: [internal https]proxy server for mp.weixin.qq.com established [AnyProxy Log][2019-09-24 15:35:09]: [internal https]proxy server for mp.weixin.qq.com established [AnyProxy ERROR][2019-09-24 15:35:09]: Error: read ECONNRESET [AnyProxy Log][2019-09-24 15:35:09]: received https CONNECT request mp.weixin.qq.com [AnyProxy Log][2019-09-24 15:35:09]: received https CONNECT request mp.weixin.qq.com [AnyProxy Log][2019-09-24 15:35:09]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:09]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:09]: [internal https]proxy server for mp.weixin.qq.com established [AnyProxy Log][2019-09-24 15:35:09]: [internal https]proxy server for mp.weixin.qq.com established [AnyProxy Log][2019-09-24 15:35:10]: received https CONNECT request mp.weixin.qq.com [AnyProxy Log][2019-09-24 15:35:10]: received request to: GET mp.weixin.qq.com/mp/jsreport?1=1&key=2&content=biz:MzU5NDM0MjEzNA==,mid:2247484669,uin:[key2]ajax_err&r=0.4475706874181671 [AnyProxy Log][2019-09-24 15:35:10]: received request to: GET mp.weixin.qq.com/mp/geticon?__biz=MzU5NDM0MjEzNA==&r=0.915468341363922 [AnyProxy Log][2019-09-24 15:35:10]: received request to: GET mp.weixin.qq.com/mp/jsmonitor?idkey=112287_0_1;112287_11_213;112287_10_1;112287_15_625;112287_14_1;112287_19_9;112287_18_1;112287_23_77;112287_22_1;112287_27_169;112287_26_1&t=0.6996393154013791 [AnyProxy Log][2019-09-24 15:35:10]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:10]: received https CONNECT request mp.weixin.qq.com [AnyProxy Log][2019-09-24 15:35:10]: received request to: GET mp.weixin.qq.com/mp/jsmonitor?idkey=112287_32_1 [AnyProxy Log][2019-09-24 15:35:10]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:30]: received https CONNECT request m.baidu.com [AnyProxy Log][2019-09-24 15:35:30]: received request to: GET developers.google.cn/generate_204 [AnyProxy Log][2019-09-24 15:35:30]: received request to: GET conn1.oppomobile.com/generate_204 [AnyProxy Log][2019-09-24 15:35:32]: will forward to local https server [AnyProxy Log][2019-09-24 15:35:32]: [internal https]proxy server for m.baidu.com established [AnyProxy ERROR][2019-09-24 15:35:32]: Error: read ECONNRESET

shinanL avatar Sep 24 '19 07:09 shinanL

我有时候也是这样 求解

wjmtgg avatar Sep 26 '19 07:09 wjmtgg

我也解析不到内容

mouday avatar Dec 20 '19 09:12 mouday

是不是node.js版本的问题?用8.X版本试下?我碰到的问题和你一样。不光是微信,微博的也不能解析。正在尝试安装低版本的NODE.JS,看能不能解决。

deuemcak avatar Dec 30 '19 01:12 deuemcak

好的,我试下。

---原始邮件--- 发件人: "deuemcak"[email protected] 发送时间: 2019年12月30日(周一) 上午9:42 收件人: "alibaba/anyproxy"[email protected]; 抄送: "Author"[email protected];"lightt105"[email protected]; 主题: Re: [alibaba/anyproxy] 微信公众号五月底Anyproxy代理正常,现在不能解析https,显示验证失效 (#519)

是不是node.js版本的问题?用8.X版本试下?

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub, or unsubscribe.

shinanL avatar Dec 30 '19 02:12 shinanL

解决了吗

andrew0213 avatar Mar 13 '20 03:03 andrew0213

我的是一直报 mp.weixin.qq.com 该网站的安全证书存在问题(可能由于设备系统时间不正确导致,请先校准设备系统时间) 错误弹窗,不知道是不是同样的问题?

leafney avatar Mar 20 '20 09:03 leafney

很抱歉这么久没有回复。因为改用了Appium自动化测试框架。 在今天上午用anyproxy的测试中,在打开微信访问链接的过程中确实有弹框提示需要校验系统时间,此时在Android右上角时间显示是正确的,但在Android设置“日期和时间”显示是北美的一个时区,于是对系统时间进行了校对改为GMT+08:00即中国标准时间,并对手机进行了重启。 经过以上步骤再次测试,没有校验系统时间的弹框出现,在微信里加载出页面信息后,anyproxy异常退出,如下截图所示,第一个报错应该是个warning,因为似乎没有什么影响,第二个错误直接导致程序退出。同样,做了对比实验,在浏览器打开百度链接的时候能够正常代理。


刘诗楠

北京邮电大学/研究生/网络空间安全学院

13353683931

北京

      ------------------ Original ------------------ From:  "Leafney"<[email protected]>; Date:  Fri, Mar 20, 2020 05:58 PM To:  "alibaba/anyproxy"<[email protected]>; Cc:  "lightt105"<[email protected]>; "Author"<[email protected]>; Subject:  Re: [alibaba/anyproxy] 微信公众号五月底Anyproxy代理正常,现在不能解析https,显示验证失效 (#519)

 

我的是一直报 mp.weixin.qq.com 该网站的安全证书存在问题(可能由于设备系统时间不正确导致,请先校准设备系统时间) 错误弹窗,不知道是不是同样的问题?

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub, or unsubscribe.

shinanL avatar Mar 23 '20 02:03 shinanL

很抱歉这么久没有回复。因为改用了Appium自动化测试框架。 在今天上午用anyproxy的测试中,在打开微信访问链接的过程中确实有弹框提示需要校验系统时间,此时在Android右上角时间显示是正确的,但在Android设置“日期和时间”显示是北美的一个时区,于是对系统时间进行了校对改为GMT+08:00即中国标准时间,并对手机进行了重启。 经过以上步骤再次测试,没有校验系统时间的弹框出现,在微信里加载出页面信息后,anyproxy异常退出,如下截图所示,第一个报错应该是个warning,因为似乎没有什么影响,第二个错误直接导致程序退出。同样,做了对比实验,在浏览器打开百度链接的时候能够正常代理。


刘诗楠

北京邮电大学/研究生/网络空间安全学院

18518969546

北京

      ------------------ Original ------------------ From:  "andrew0213"<[email protected]>; Date:  Fri, Mar 13, 2020 11:21 AM To:  "alibaba/anyproxy"<[email protected]>; Cc:  "lightt105"<[email protected]>; "Author"<[email protected]>; Subject:  Re: [alibaba/anyproxy] 微信公众号五月底Anyproxy代理正常,现在不能解析https,显示验证失效 (#519)

 

解决了吗

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub, or unsubscribe.

shinanL avatar Mar 23 '20 02:03 shinanL

上篇邮件回复有些错误,经过多次测试,每次出现ECONNRESET错误时会导致anyproxy退出,无论是在微信里还是在百度里,只是在微信里这个错误出现的特别快,导致程序退出的特别快。并且只在微信里弹出校验系统时间的弹框。 查了一下出现这个错误的原因是由于服务端先于客户端关闭连接,客户端未来得及同步状态,继续发送http请求所致。可以通过错误重试解决。不知道这部分是由使用者自己解决还是开源的你们解决? 另外有个小小的疑问,anyproxy.io官网为什么需要稳定的国际网络环境?我以为国内开源的软件应该支持国内访问,http://anyproxy.io/cn/ 也访问不了,ping anyproxy.io失败。因此我访问不了官网,无法查看日志位置把日志发送给你们。


刘诗楠

北京邮电大学/研究生/网络空间安全学院

13353683931

北京

      ------------------ Original ------------------ From:  "Leafney"<[email protected]>; Date:  Fri, Mar 20, 2020 05:58 PM To:  "alibaba/anyproxy"<[email protected]>; Cc:  "lightt105"<[email protected]>; "Author"<[email protected]>; Subject:  Re: [alibaba/anyproxy] 微信公众号五月底Anyproxy代理正常,现在不能解析https,显示验证失效 (#519)

 

我的是一直报 mp.weixin.qq.com 该网站的安全证书存在问题(可能由于设备系统时间不正确导致,请先校准设备系统时间) 错误弹窗,不知道是不是同样的问题?

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub, or unsubscribe.

shinanL avatar Mar 23 '20 03:03 shinanL

解决了的我来填个坑。 这个是 https 的 SSL pinning 问题。可以使用 Xposed + JustTruestMe 来突破SSL pinning

leafney avatar Mar 25 '20 02:03 leafney

好的,谢谢啦,我试一下

---原始邮件--- 发件人: "Leafney"[email protected] 发送时间: 2020年3月25日(周三) 上午10:01 收件人: "alibaba/anyproxy"[email protected]; 抄送: "Author"[email protected];"lightt105"[email protected]; 主题: Re: [alibaba/anyproxy] 微信公众号五月底Anyproxy代理正常,现在不能解析https,显示验证失效 (#519)

解决了的我来填个坑。 这个是 https 的 SSL pinning 问题。可以使用 Xposed + JustTruestMe 来突破SSL pinning

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub, or unsubscribe.

shinanL avatar Mar 25 '20 02:03 shinanL