# proxy — on-device HTTPS MITM (appproxy) Host CLI plus the Android binary that MITMs phone HTTPS, so a capture can see license URLs, manifests and auth headers. ```text apps/proxy/ proxyctlcmd/ host CLI, hosted by bin/drm as `drm proxy` device/ linux/arm64 MITM source (module: appproxy) rteproxy-ca.crt MITM CA (subject hash 6c3578b4) ``` The process name on the phone is **`appproxy`**. Some on-disk names still say `rteproxy-*`, and those paths are still read, so an already-provisioned phone keeps working. ## Build ```bash go -C apps/cli build -o ../../bin/drm . # host CLI ./bin/drm proxy build # cross-compile the device binary ``` `proxy build` compiles `device/` for linux/arm64 into `apps/proxy/proxy-android-arm64` and copies it to `bin/proxy-android-arm64`. ## Use ```bash # trust the MITM CA (needs Magisk; mounts into the system store) ./bin/drm proxy install-ca --reinject ./bin/drm proxy reinject-ca # mount only, CA already pushed # structured capture proxy ./bin/drm proxy start --install-ca --reinject ./bin/drm proxy stop # record everything while you explore an unknown app ./bin/drm proxy discover --install-ca --reinject ./bin/drm proxy discover --force-stop # so it inherits the CA mount # pull artifacts without re-running, and release the phone ./bin/drm proxy pull ./bin/drm proxy clear-proxy ``` Always clear the proxy when done, or the phone keeps pointing at a dead listener. ### Transparent mode (UK VPN OK — no Wi‑Fi HTTP proxy) Root `iptables` redirects only one app’s TCP/443 into on-device `appproxy`. The phone can stay on NordVPN UK; nothing sets `http_proxy`. ```bash # leave UK VPN connected on the phone, then: ./bin/drm proxy transparent --package bbc.iplayer.android --reinject # open the app / play — Ctrl+C stops iptables and pulls files ``` Writes on device (adb-readable): ```text /data/local/tmp/capture//cap.json /data/local/tmp/capture//traffic.jsonl /data/local/tmp/capture//appproxy.log ``` Pull anytime: ```bash adb pull /data/local/tmp/capture/bbc.iplayer.android ./bbc-cap ``` Force-stop the target app once after CA reinject so it inherits the Magisk CA mount. The device binary cannot read an app module's values file, so a module's manifest-scoring hosts are passed to it as flags (`--match`, `--score-host`, `--score-deny`). `drm capture` does this automatically. ## Artifacts | File | What | |---|---| | `appproxy_traffic.jsonl` / `traffic.jsonl` | every HTTP(S) request/response (discover / transparent) | | `appproxy_cap.json` / `cap.json` | structured mpd / license / auth / pssh when detected | | `appproxy.log` | tagged lines: `[MPD]` `[LIC]` `[PSSH]` `[MAN]` `[TPROXY]` | Pulled into `outputs/discover//` or `outputs/transparent//`. ## Device paths | Remote | Role | |---|---| | `/data/local/tmp/appproxy` | binary | | `/data/local/tmp/appproxy_cap.json` | structured capture (proxy mode) | | `/data/local/tmp/capture//` | transparent out-dir (cap + traffic + log) | | `/data/local/tmp/tproxy_iptables.sh` | UID REDIRECT helper | | `/data/local/tmp/6c3578b4.0` | system CA hash file | | Wi‑Fi `http_proxy` | used only in classic proxy mode — **not** in transparent mode | **Full guide: [docs/capture.md](../../docs/capture.md)** — CA troubleshooting and how to mine a discover dump.