{"id":13387354,"url":"https://github.com/denandz/glorp","last_synced_at":"2026-01-14T12:10:29.120Z","repository":{"id":43497800,"uuid":"299002453","full_name":"denandz/glorp","owner":"denandz","description":"A CLI-based HTTP intercept and replay proxy","archived":false,"fork":false,"pushed_at":"2025-09-24T03:15:02.000Z","size":12801,"stargazers_count":263,"open_issues_count":6,"forks_count":16,"subscribers_count":5,"default_branch":"master","last_synced_at":"2025-09-24T05:26:26.849Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/denandz.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-09-27T10:00:17.000Z","updated_at":"2025-09-24T03:15:05.000Z","dependencies_parsed_at":"2023-02-10T02:46:30.142Z","dependency_job_id":"0eff4c00-e25f-4384-83a1-44365a074af1","html_url":"https://github.com/denandz/glorp","commit_stats":null,"previous_names":[],"tags_count":8,"template":false,"template_full_name":null,"purl":"pkg:github/denandz/glorp","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/denandz%2Fglorp","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/denandz%2Fglorp/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/denandz%2Fglorp/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/denandz%2Fglorp/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/denandz","download_url":"https://codeload.github.com/denandz/glorp/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/denandz%2Fglorp/sbom","scorecard":{"id":333843,"data":{"date":"2025-08-11","repo":{"name":"github.com/denandz/glorp","commit":"3f3de3d6ae99f06bd2693d40bf418868c3d1d19c"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.1,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":1,"reason":"Found 2/16 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":3,"reason":"4 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.1.7 not signed: https://api.github.com/repos/denandz/glorp/releases/135620762","Warn: release artifact v0.1.6 not signed: https://api.github.com/repos/denandz/glorp/releases/132963387","Warn: release artifact v0.1.5 not signed: https://api.github.com/repos/denandz/glorp/releases/61111028","Warn: release artifact v0.1.4 not signed: https://api.github.com/repos/denandz/glorp/releases/54382384","Warn: release artifact v0.1.3 not signed: https://api.github.com/repos/denandz/glorp/releases/40799540","Warn: release artifact v0.1.7 does not have provenance: https://api.github.com/repos/denandz/glorp/releases/135620762","Warn: release artifact v0.1.6 does not have provenance: https://api.github.com/repos/denandz/glorp/releases/132963387","Warn: release artifact v0.1.5 does not have provenance: https://api.github.com/repos/denandz/glorp/releases/61111028","Warn: release artifact v0.1.4 does not have provenance: https://api.github.com/repos/denandz/glorp/releases/54382384","Warn: release artifact v0.1.3 does not have provenance: https://api.github.com/repos/denandz/glorp/releases/40799540"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Pinned-Dependencies","score":3,"reason":"dependency not pinned by hash detected -- score normalized to 3","details":["Warn: containerImage not pinned by hash: Dockerfile:1","Warn: containerImage not pinned by hash: Dockerfile:7: pin your Docker image by updating alpine:latest to alpine:latest@sha256:4bcff63911fcb4448bd4fdacec207030997caf25e9bea4045fa6c8c44de311d1","Info:   1 out of   1 goCommand dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 17 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T04:12:43.022Z","repository_id":43497800,"created_at":"2025-08-18T04:12:43.022Z","updated_at":"2025-08-18T04:12:43.022Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28419561,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T10:47:48.104Z","status":"ssl_error","status_checked_at":"2026-01-14T10:46:19.031Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-30T12:01:16.303Z","updated_at":"2026-01-14T12:10:29.114Z","avatar_url":"https://github.com/denandz.png","language":"Go","funding_links":[],"categories":["开源类库","Open source library","Weapons","Go"],"sub_categories":["网络","The Internet","Tools"],"readme":"# GLORP\n\nGlorp is an HTTP intercept proxy, allowing the inspection and replaying of HTTP requests. The layout and flow was designed to function similar to Portswigger's Burp Proxy and Repeater tabs. The proxy functionality is done using [Google's Martian](https://github.com/google/martian), UI is done with [TView](https://github.com/rivo/tview).\n\nThe idea is to provide a CLI based tool for when you wanna-look-at-this-thing-real-quick and not fire up yet another full-fat container/vm/whatever with Burp and so forth.\n\n![page switching](./gif/glorp.gif)\n\n## Install\n\nInstall can be done with `git clone` and `go build/install`, or by using one of the binaries available on the releases page.\n\nIf you'd like to patch the `net/http` header casing problems, you can enable the included overlay to overwrite the relevant part of `net/http`. Note, this has been tested on `go1.23` and `go1.24 on Linux:\n\n```\ngo build -overlay overlay.23.json\n```\n\nIf you're on golang `1.22`, use `overlay.22.json`.\n\nAlternatively, to run under docker, clone this repository and:\n\n```\ndocker build -tglorp .\ndocker run -p 8080:8080 --rm -it glorp\n```\n\n## Command Line Flags\n\n```\nUsage of ./glorp:\n  -addr string\n    \tThe bind address, default 0.0.0.0\n  -cert string\n    \tPath to a CA Certificate\n  -help\n    \tShow help\n  -key string\n    \tPath to the CA cert's private key\n  -port uint\n    \tListen port for the proxy, default 8080\n  -proxy string\n    \tdownstream proxy to use in URI format. example: socks5://127.0.0.1:9050. empty means no downstream proxy\n  -v int\n    \tlog level\n```\n\n### Using a custom CA\n\nYou'll probably want to specify a CA file, so you can load this into your browser/mobile device/operating system/whatever. The easiest way to spin up your own CA for use in Glorp is as follows:\n\n```\nopenssl genrsa -out ca.key 2048\nopenssl req -x509 -new -nodes -key ca.key -sha256 -days 1825 -out ca.crt -subj '/CN=GlorpCA' -addext \"keyUsage=critical,digitalSignature,keyCertSign,cRLSign\"\n```\n\n*Remember to set a common-name*. Without a common-name, some platforms like iOS don't play nice. Then, launch glorp:\n\n```\ndoi@buzdovan:~/go/src/glorp$ ./glorp -cert ca.crt -key ca.key\n```\n\n## UI Usage\n\nKey | View | Details\n--|--|--\ntab | All | Go to next element (window, button, etc) in the page\nshift+tab | All | Go to previous element in the page\nctrl-c | All | Exit Glorp\nctrl-n | All | Go the next page\nctrl-p | All | Go to the previous page\nctrl-r | Proxy/Replay | Send item to the replayer\nctrl-s | Proxy/Replay - highlighted request/response | Save item to file\ng      | Proxy | Go to first entry in the proxy table\nG      | Proxy | Go to last entry in the proxy table\n/      | Proxy | Enter a search-filter regex to filter proxy entries by URL\nctrl-e | Proxy - highlighted request/response | Open the request/response data in `view`\nctrl-b | Replay | Create a new blank replay item - useful for assembling requests from scratch\nctrl-d | Replay | Delete replay item\nctrl-e | Replay - highlighted request/response | Edit request in `vi`, responses will open with `view`\nctrl-x | Replay | Rename replay item\nctrl-g | Replay | Send the request\n\n\nCtrl-N and Ctrl-P cycle between the different pages, Tab/Shift+tab is used to cycle between each item within a page.\n\n### Proxy Page\n\nThe proxy page shows incoming requests. If you select the last item (bottom item), then the view will follow new requests.\n\n### Sitemap Page\n\nThe sitemap shows the various URLs and hosts that have been accessed via the proxy. You can navigate the list and hit `enter` to drill down further. This only shows URLs and does not support request/response data in the sitemap view yet.\n\n### Replay Page\n\nIn the proxy page, hit `ctrl-r` on an entry and it will be sent to the replay page, where you can modify the request and re-issue it. If you hit `ctrl-r` in the Replay page, it'll duplicated the current item.\n\nThe replays support a history of your sent data. As you modify requests and send them, the history will grow. You can go back and view the previous requests. Editing a previous request that has a response will automatically create a new history entry so you don't lose your old request data.\n\n#### Editing\n\nHighlight the request text box and hit `ctrl-e`. This will open the request in VI and let you edit it. \n\nPro-tip for content length: If you highlight your modified request body in visual mode (`v`) and then hit `g`-\u003e`ctrl+g` it will show you how many bytes are selected, and you can update the content-length header accordingly.\n\n#### Sending Requests\n\nThe current replay request can be sent by either hitting the `Go` button or using `ctrl-g`.\n\nIf the `AutoSend` checkbox is selected, then after the request is edited it will be automatically sent.\n\n#### Using an external editor\n\nThe highlight-\u003e`ctrl-e`-\u003eedit in VI-\u003eexit VI-\u003esend flow is admittedly clunky, so Glorp also supports using an external editor. If you enable the `Ext. Editor` check box, the request is spooled out to a temporary file. Any edits to this file are picked up by Glorp. This can be combined with auto-send and auto-content-length updating.\n\nNote: The temp file is removed when `Ext. Editor` is unchecked. If you do not uncheck this, Glorp will not clean up the temp file for you.\n\nEnabling `Ext. Editor` should show you the filename to edit:\n\n![ext-editor](./gif/ext-editor.png)\n\nYou can then open that file with any editor and changes will auto-load into Glorp:\n\n![replayer](./gif/replayer.gif)\n\nYou can have multiple external editors open; however, only the one currently focused in glorp will auto-send.\n\n### Log Page\n\nThis is the general log info page and takes no user input. Glorp is set up such that any call to `log.Println` or similar will end up in this view. \n\n### Save/Load Page\n\nThis one should hopefully be self explanatory. Lets you save and load all the proxy entries and replay entries. Writes out to a JSON file or reads in a JSON file. WARNING: Loading will delete all existing proxy and replay entries, rather than append to them.\n\n## Transparent Proxying\n\nGlorp does not support transparent proxying, but squid does :D Rather than build this logic into Glorp, I figure run a squid proxy and forward it through. The squid config should look like:\n\n```\nacl all src 0.0.0.0/0\nhttp_access allow all\n\nhttp_port 3128 \nhttp_port 3080 intercept\nhttps_port 3443 ssl-bump intercept \\\n  cert=\u003cPATH TO KEY AND CERT IN ONE PEM\u003e \\\n  generate-host-certificates=on dynamic_cert_mem_cache_size=4MB\n\nsslcrtd_program /usr/local/squid/libexec/security_file_certgen -s /var/lib/ssl_db -M 4MB\nacl step1 at_step SslBump1\nssl_bump peek step1\nssl_bump bump all\n\n# forward to glorp\ncache_peer 127.0.0.1 parent 8080 0 no-query default\nnever_direct allow all\nsslproxy_cert_error allow all\nsslproxy_flags DONT_VERIFY_PEER\nsslproxy_cert_error allow all\nsslproxy_flags DONT_VERIFY_PEER\n```\n\nUse iptables to hijack the connection:\n\n```\niptables -t nat -A PREROUTING -i enp1s0 -p tcp --dport 80 -j REDIRECT --to-port 3080\niptables -t nat -A PREROUTING -i enp1s0 -p tcp --dport 443 -j REDIRECT --to-port 3443\niptables -t nat -A POSTROUTING -o enp1s0 -j MASQUERADE\n```\n\nSquid can be built with the following dockerfile:\n\n```\n# docker run --net=host -it --rm -v $PWD:/etc/squid sq1 /usr/local/squid/sbin/squid -N -f /etc/squid/squid.conf\n# Net host saves some docker iptables headaches, should probably document how to do that properly...\nFROM debian:latest\n\nWORKDIR /opt/\n\nRUN apt update \nRUN apt upgrade -y\nRUN apt install -y automake libtool build-essential libssl-dev git ca-certificates\n\n## clone and build squid\nRUN git clone https://github.com/squid-cache/squid \u0026\u0026 cd squid \u0026\u0026 autoreconf -i\nRUN cd /opt/squid \u0026\u0026 ./configure --prefix=/usr/local/squid --with-openssl --enable-ssl-crtd\nRUN cd /opt/squid \u0026\u0026 make -j4 \u0026\u0026 make install\n\n# sort the log file dir perms and create the ssl junk\nRUN chown nobody /usr/local/squid/var/logs/\nRUN /usr/local/squid/libexec/security_file_certgen -c -s /var/lib/ssl_db -M 4MB\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdenandz%2Fglorp","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdenandz%2Fglorp","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdenandz%2Fglorp/lists"}