Skip to content

Fix --proxy being ignored, add --tor - #106

Open
IPedrax wants to merge 1 commit into
Alfredredbird:mainfrom
IPedrax:feat/proxy-tor
Open

IPedrax wants to merge 1 commit into
Alfredredbird:mainfrom
IPedrax:feat/proxy-tor

Conversation

@IPedrax

@IPedrax IPedrax commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

-p/--proxy is parsed and documented but it never reaches a request. Nothing in the codebase reads args.proxy, and no call passes proxies= to requests. scan_site() even takes an args parameter and never touches it. So a scan run with -p goes out over your own connection while looking like it's proxied, and nothing tells you. The example in --help (-p http://127.0.0.1:8080) doesn't work either.

That also blocks "Tor Searching" on the roadmap, because there's nothing to hang it on.

Rather than add a proxies parameter to every function that makes a request, and to logo() because it calls motd(), I set it once in modules.py and each outbound call reads it: scan_site, check_update, motd, get_header_file. The webscraper's Chrome gets the same proxy as a launch flag.

This sits on top of the accuracy change that just merged, so it also routes that change's per-hit control request through the proxy. Without that, --tor would send the scan over Tor while the control request went out on the real connection.

-tr/--tor points at socks5h://127.0.0.1:9050. The h is deliberate: DNS resolves on the Tor side, so the hostnames being checked never hit the local resolver. Chrome gets plain socks5:// instead, because it resolves through the SOCKS proxy itself and rejects the socks5h spelling. If --tor is passed and nothing is listening on 9050, it exits once with a message instead of failing on every site in the list.

Tested on the same username each time:

  • no proxy: 85 accounts
  • dead proxy on 127.0.0.1:9999: 0
  • SOCKS5 through a remote host over ssh -D: 81
  • --tor: 77

Before this change the dead proxy run still found all 85, which is how you can tell the flag was never read. The SOCKS5 and Tor runs find fewer because some sites refuse connections from datacenter and Tor exit addresses.

One thing I left alone: send_webhook() in files.py still posts directly. Sending someone's own webhook through Tor seemed more likely to break it than help, but I'll change it if you'd rather it followed the proxy too.

-p/--proxy was parsed and documented, but it never reached a request.
Nothing read args.proxy, and no call passed proxies= to requests.
scan_site() even took an args parameter that it never looked at. So a
scan with -p went out over the user's own connection while it looked
like it was proxied, and nothing said otherwise.

I set the proxy once in modules.py and every outbound call reads it
from there: scan_site, its control request, check_update, motd and
get_header_file. That was simpler than adding a parameter to each of
them and to logo(), which is where motd() gets called from. The
webscraper's Chrome gets the same proxy as a launch flag.

The control request is the second fetch the accuracy check makes per
candidate hit. It landed in a separate change, so it needs proxying
here too, or --tor would send the scan through Tor while that one
request went out over the real connection.

-tr/--tor points at socks5h://127.0.0.1:9050. The h matters. It keeps
DNS on the Tor side, so the hostnames being checked never reach the
local resolver. Chrome gets plain socks5:// instead, since it resolves
through the SOCKS proxy on its own and won't accept the socks5h
spelling. If nothing is listening on 9050 it now exits once with a
message, rather than failing on every site in the list.

Tested on one username throughout: 85 accounts with no proxy, 0
through a dead proxy, 81 over SOCKS5 to a remote host via ssh -D, and
77 over Tor. Before this change the dead proxy run still found all 85.
That is how you can tell the flag was never read. The SOCKS5 and Tor
runs find fewer, because some sites refuse connections from datacenter
and Tor exit addresses.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant