Sinisterly
Configuring and using Proxychains - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Computers (https://sinister.li/Forum-Computers)
+--- Forum: Networking (https://sinister.li/Forum-Networking)
+---- Forum: Anonymity (https://sinister.li/Forum-Anonymity)
+---- Thread: Configuring and using Proxychains (/Thread-Configuring-and-using-Proxychains)



Configuring and using Proxychains - Megamente - 07-09-2013

Maintaining privacy on the Internet is the kind of thing that not only criminals want. Many people do not like the idea that any other people connected to the Internet can track them and find even their geographic location.

With that in mind various designs were created trying to improve privacy on the Internet, like Tor. Although I think Tor is an excellent project, in this post I'll talk about another tool that I like more and think more versatile: Proxychains.

In this post you will learn the theory of operation of Proxychains, how to configure and use it.

Theory

The theory of how Proxychains works is extremely simple: using multiple proxies, your package goes through a pre-defined path for you in the configuration (as we shall see) before reaching the destination. The more proxy servers exist between you and the target, the harder it is to track your real IP. But what is a proxy server?

The proxy server acts as a gateway between you and your destination. Imagine the following scenario: your machine is configured to use a proxy and you want to access any website. Your machine will send the request to the proxy server; the proxy in turn will "catch" the site and only then will pass the data to your machine, showing the site in the browser. In the end, who accesses the site (from the point of view of the host that hosts it) is the proxy server and not your machine.
[Image: proxy.png]

The secret is to use multiple proxies before finally connecting to the final destination. Imagine the following scenario: Proxychains was configured to use three proxies: p1, p2 and p3. So when you want to access a site, the request first goes to the proxy p1, then to p2, p3, and finally reaches the destination. In logs the IP destination that will appear is the IP of the proxy p3, not the IP that was assigned to your machine by your ISP. This works for any protocol as long as you indicate to the software that he should use proxychains. Therefore, accessing a site via HTTP, FTP, scan it (using Nmap i.e), a download, can be done anonymously.


NOTE: It is recommended that you use proxies from different countries and, if possible, servers that are administered by different people. Thus, the screening process is MUCH more complicated. It is also recommended to use about 4 or 5 different proxies.




However, not everything is perfect. There are some disadvantages to using a chain of proxies (not necessarily with proxychains, but with any kind of software):
• No matter how many proxies you use, you will never get 100% anonymous on the internet. Using a chain of proxies only complicates the process of tracking;
• open proxy servers usually last a short time (a few weeks). That is, you'll have to keep searching for new proxies to use often. Furthermore, when using a chain you will need to test each of its proxies to find out which of them "died";
• obviously the use of proxies has a performance impact, affecting him negatively. The more proxies involved, the greater can be the impact.


Configuring proxychains

Open up the terminal and: gedit /etc/proxychains.conf
[Image: proxychains.png]

All configuration is done through the proxychains “/etc /proxychains.conf”. Here, every aspect of the software can be customized so that it meets your needs. Here, I will review the options available in the file and give a brief description of what they do.

• dynamic_chain: Enabling this option causes the proxychains obey the order of the proxies in the list you provided (we will see how to do this later) connecting each of them and jumping proxies that are not responding. In my opinion it is the best option.
• strict_chain: Forces proxychains use all proxies in the order they were entered in the list. If a proxy is no longer responding, the process will terminate and an error is returned to the application.
• random_chain: When this option is active, the proxies are randomly selected and used for the connection. The amount of proxies is defined by the selected option "chain_len."


IMPORTANT: Only one of these options can be uncommented at a time!

After setting the options properly, you must enter the IPs of proxies to be used. This should be done below the line "[ProxyList]" in the following format:

<release the socks> <IP <port>

I.E

socks5 1.2.3.4 1234

You can enter as many proxies you want, one per line in the format described above.

By default, proxychains has an input for Tor installed on the local machine. If you do not want to use the Tor network, simply comment out the line like this:
# Socks4 127.0.0.1 9050

And we are ready! You can also remove the line, but remember to add other proxies for you to use!

To use proxychains, just call it in the terminal followed by the program you want to run, i.e:
Code:
root@bt:~# proxychains firefox


Scanning hosts anonymously with Nmap and proxychains

In order to achieve complete anonymity while scanning a host, proxychains is as good as it gets because it can tunnel the Nmap scan. In other words, you feed an application to proxychains, in this case Nmap, and it uses Tor or any other proxy for the scan. ProxyChains allows you to use SSH, Telnet, VNC, FTP and other network application from behind HTTP (HTTPS) and SOCKS (4/5) proxy servers. Proxychains allows TCP and DNS tunneling through proxies. Be aware that Proxychains only tunnels TCP and DNS; in other words, avoid using UDP and host discovering through ICMP (ping). The “-sTV” options tells nmap to do a full TCP connect and Version Detection, “-PN” tells nmap not to ping the remote host, “-n” not to resolve any dns records, and finally, “-p” options for the ports.


Code:
root@bt:~# proxychains nmap -sTV -PN -n -p21,22,25,80 64.13.134.52 ProxyChains-3.1 (http://proxychains.sf.net) Starting Nmap 5.35DC1 ( http://nmap.org ) at 2010-10-03 20:12 EDT |S-chain|-<>-127.0.0.1:9050-<><>-64.13.134.52:25-<--timeout |S-chain|-<>-127.0.0.1:9050-<><>-64.13.134.52:22-<><>-OK RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 |S-chain|-<>-127.0.0.1:9050-<><>-64.13.134.52:21-<--timeout |S-chain|-<>-127.0.0.1:9050-<><>-64.13.134.52:80-<><>-OK RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 |S-chain|-<>-127.0.0.1:9050-<><>-64.13.134.52:22-<><>-OK |S-chain|-<>-127.0.0.1:9050-<><>-64.13.134.52:80-<><>-OK Nmap scan report for 64.13.134.52 Host is up (12s latency). PORT STATE SERVICE VERSION 21/tcp closed ftp 22/tcp open ssh OpenSSH 4.3 (protocol 2.0) 25/tcp closed smtp 80/tcp open http Apache httpd 2.2.3 ((CentOS)) Service detection performed. Please report any incorrect results at http://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 44.64 seconds


And that’s it! Hope you all enjoyed this tutorial!



RE: Configuring and using Proxychains - lady_godiva - 07-22-2013

Nice one, nowadays it is not so easy to find a good proxychains configuration. Another good usage is Tor + Proxychains.

Please notice that another disadvantage of proxy usage is that you are assuming that the proxy is realiable and won't sniff you traffic because a proxy can actually see all you data. This is why using Tor which implements Onion Routing would be a better solution than normal proxies.


RE: Configuring and using Proxychains - lady_godiva - 07-22-2013

Nice one, nowadays it is not so easy to find a good proxychains configuration. Another good usage is Tor + Proxychains.

Please notice that another disadvantage of proxy usage is that you are assuming that the proxy is realiable and won't sniff you traffic because a proxy can actually see all you data. This is why using Tor which implements Onion Routing would be a better solution than normal proxies.


RE: Configuring and using Proxychains - lady_godiva - 07-22-2013

Nice one, nowadays it is not so easy to find a good proxychains configuration. Another good usage is Tor + Proxychains.

Please notice that another disadvantage of proxy usage is that you are assuming that the proxy is realiable and won't sniff you traffic because a proxy can actually see all you data. This is why using Tor which implements Onion Routing would be a better solution than normal proxies.