You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Mitmproxy拦截请求遇502错误及证书验证失败问题求助

Mitmproxy拦截请求遇502 Bad Gateway及证书验证失败的排查方案

在Kali Linux上使用Mitmproxy 10.2.2对目标网站做渗透测试,尝试拦截请求逆向分析后端API时,出现502 Bad Gateway错误,同时伴随附加错误:Certificate verify failed: self-signed certificate。已确认目标服务器可正常访问,尝试过重新导入Firefox CA证书、处理CORS问题、检查服务器日志配置,但问题未解决。

相关请求/响应信息

Status 502 Bad Gateway
Version HTTP/2
Transferred 267 B (170 B size)
Referrer Policy strict-origin-when-cross-origin
Request Priority Highest
    
Request Headers:
content-type    text/html
server  mitmproxy 10.2.2
X-Firefox-Spdy  h2
    
Response Headers:
Accept  application/json, text/plain, */*
Accept-Encoding gzip, deflate, br
Accept-Language en-US,en;q=0.5
Connection  keep-alive
Content-Length  227
Content-Type application/json
Host -----------
Origin  https://-------
Referer https://-------/--/---
Sec-Fetch-Dest  empty
Sec-Fetch-Mode  cors
Sec-Fetch-Site  same-origin
TE  trailers
User-Agent  Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0

排查与解决建议

  • 确认Mitmproxy CA证书系统级信任:Firefox导入证书仅覆盖浏览器层面,Mitmproxy自身连接目标服务器时需系统信任CA证书。在Kali上执行:
    sudo cp ~/.mitmproxy/mitmproxy-ca-cert.pem /usr/local/share/ca-certificates/mitmproxy.crt
    sudo update-ca-certificates
    
    执行完成后重启Mitmproxy。
  • 跳过证书验证测试兼容性:部分服务器会对代理连接做证书链验证限制,尝试用--ssl-insecure参数临时跳过验证:
    mitmproxy --ssl-insecure
    
    若问题解决,说明是目标服务器证书链配置问题,可进一步导出目标完整证书链导入Mitmproxy信任池。
  • 禁用HTTP/2强制使用HTTP/1.1:目标使用HTTP/2,Mitmproxy对部分HTTP/2特性可能存在兼容性问题,尝试强制降级协议:
    mitmproxy --no-http2
    
  • 检查代理配置完整性:确认Firefox的HTTP、HTTPS代理均指向127.0.0.1:8080,无代理规则遗漏或目标网站被排除的情况。
  • 查看Mitmproxy详细日志:启动时增加日志级别,定位具体错误节点:
    mitmproxy -v
    
    重点关注证书验证、目标连接失败相关的日志条目。
  • 同步系统时间:证书验证依赖正确的系统时间,执行以下命令检查并同步:
    timedatectl status
    timedatectl set-ntp true
    

内容的提问来源于stack exchange,提问作者Bemnet16

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 07:35:03