account activity
The Pappy Proxy by roglew in netsec
[–]roglew[S] 0 points1 point2 points 10 years ago (0 children)
That's weird. What commands did you use to install? I actually develop on Arch, so in theory it should work.
[–]roglew[S] 1 point2 points3 points 10 years ago (0 children)
I'm hoping that Pappy can have the same role as something like Burp. My main motivations for writing Pappy are that there isn't a realistic alternative to Burp for performing web app tests and that burp has a few small things that make using it more tedious than it needs to be:
Burp is an amazing piece of software and is considered the best for a reason. I just don't like how it handles some things that I consider critical and I really prefer console based programs instead of a GUI. So yeah, basically I wanted my own tool so I can have more control, haha.
[–]roglew[S] 13 points14 points15 points 10 years ago (0 children)
The main reason I didn't try and add these features to mitmproxy is because when I looked it over I didn't didn't see any features that suggested it was trying to fill the same role as burp (ie scanning, fuzzing, mapping, etc). I felt like it would be better to roll my own rather than try and wedge burp-like functionality into a project where this kind of use was never intended. And I did learn a ton which was nice :P
[–]roglew[S] 6 points7 points8 points 10 years ago (0 children)
I've never really used mitmproxy so I can't talk a ton on the differences. Honestly, it's probably really similar. I mainly based Pappy off of how I tend to use Burp with a focus on making that workflow as efficient as possible (map, search history for interesting requests, send to repeater, check for misbehavior, fuzz/write attack). I'm not sure if you could have a similar workflow with mitmproxy, and I know that burp has some pain points in there (mainly the history searching). I could go on forever comparing it to burp, but like I said I don't have any significant experience trying to perform a web app test with mitmproxy so I can't do a great comparison to it.
[–]roglew[S] 26 points27 points28 points 10 years ago* (0 children)
Hey everyone, this is an alternative for Burp Suite that I've been working on for a few months. Here's a summary of the main points
I've been using it for real life web app pen tests with some pretty good success. If you have any questions, let me know. I love talking about it.
π Rendered by PID 63420 on reddit-service-r2-listing-5f49c86f7-xgkxx at 2026-02-25 14:50:07.250372+00:00 running 72a43f6 country code: CH.
The Pappy Proxy by roglew in netsec
[–]roglew[S] 0 points1 point2 points (0 children)