Show HN: A local MitM proxy to control TLS fingerprints
A new local MITM proxy tool allows developers to manipulate TLS and HTTP/2 fingerprints to test WAF bot-detection systems. The tool enables granular control over headers, user agents, and TLS handshakes to simulate various client environments.
Why it matters
This tool provides security researchers and developers with a way to audit and improve the robustness of bot-detection mechanisms against sophisticated spoofing.
A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, User-Agent, and source IP headers — all from a single YAML config file.
A Chrome extension is included for toggling the proxy and switching fingerprint profiles directly from the browser toolbar without restarting the proxy.
Intended for authorized security testing of WAF bot-detection systems. Route curl, browsers, or Playwright through the proxy to observe how different fingerprint combinations are classified.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in