From 26f3a000dafa9aa6cc497eda657b99a1cb298a31 Mon Sep 17 00:00:00 2001 From: evilsocket Date: Fri, 9 Mar 2018 12:36:01 +0100 Subject: [PATCH] fix: forcing https urls to http if sslstrip is enabled (ref #154) --- modules/http_proxy_base_sslstriper.go | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/modules/http_proxy_base_sslstriper.go b/modules/http_proxy_base_sslstriper.go index d81f81b1..cdaf90bb 100644 --- a/modules/http_proxy_base_sslstriper.go +++ b/modules/http_proxy_base_sslstriper.go @@ -265,6 +265,11 @@ func (s *SSLStripper) Preprocess(req *http.Request, ctx *goproxy.ProxyCtx) (redi // preprocess request headers s.stripRequestHeaders(req) + // well ... + if req.URL.Scheme == "https" { + req.URL.Scheme = "http" + } + // handle stripped domains original := s.hosts.Unstrip(req.Host) if original != nil {