Skip to content

Repository files navigation

BREACH

NOTE: This repository is fixed by me and i used 3.12.8 as the python version. The project has evolved in the Rupture tool, so make sure to check this out if you are interested in the research on the BREACH attack.

Description

Tools to execute BREACH attacks.

ScriptDescription
breach.pyThe main script that starts the attack.
connect.pyMitM proxy that sniffs TLS Packets, defragments TLS records and dumps header and payload.
parse.pyScript that parses the lengths sniffed over the network and decides how the attack should continue.
hillclimbing.pyScript that creates the parameters needed by evil.js.
iolibrary.pyLibrary with useful function for I/O communication with the user.
sniff.pyNetwork sniffer that provides Ethernet level (and above) packet information.
index.htmlMinimal HTML page that contains the evil js.
evil.jsJavascript that parses parameters needed from a file created by hillclimbing.py (and is in the same directory as evil.js and index.html) and issues requests on the endpoint.
config.ymlYAML configuration file.

Disclaimer

The above code was created for the needs of my thesis at the School of Electrical and Computer Engineering of the National Technical University of Athens. Please do not use for malicious purposes!

License

The content of this project is licensed under the Creative Commons Attribution 4.0 license and the source code is licensed under the MIT license.

About

Tool to execute BREACH attack.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages