A specialized Docker environment for analyzing, capturing, and decrypting MASQUE/QUIC protocol traffic.
This image comes pre-installed with Masque-Plusā , usque, tcpdump, and network utilities. It is configured to automatically export TLS Master Secrets, allowing for full decryption of QUIC traffic in Wireshark.
masque-plus and usque.tcpdump and curl.SSLKEYLOGFILE export for Wireshark analysis.docker pull tungns1207/masque-proxy
To start the container and mount your current directory to save capture files:
docker run --rm -it -p 1080:1080 -v "$(pwd):/data" --name masque-dump tungns1207/masque-dump:latest
š Usage Scenarios
Use this method to route your computer's browser traffic through the container.
Start the container using the command
docker run --rm -it -v "$(pwd):/data" --name masque-dump tungns1207/masque-dump:latest
Inside the container, run the tcpdump to capture and write to /data/capture.pcap:
tcpdump -i eth0 -w /data/capture.pcap
Set the TLS Key log path and run the masque-plus:
docker exec -it masque-dump bash
export SSLKEYLOGFILE=/data/TLS_keys.log
./masque-plus --endpoint 162.159.198.2:443
Use this method to generate traffic using curl inside the container.
Start the container using the command
docker run --rm -it -p 1080:1080 -v "$(pwd):/data" --name masque-dump tungns1207/masque-dump:latest
Start capture
tcpdump -i eth0 -w /data/capture.pcap
Set the TLS Key log path and run the masque-plus:
docker exec -it masque-dump bash
export SSLKEYLOGFILE=/data/TLS_keys.log
./masque-plus --endpoint 162.159.198.2:443
Generate traffic using curl:
curl -x socks5h://127.0.0.1:1080 https://www.google.com
curl -x socks5h://127.0.0.1:1080 https://ifconfig.me
Content type
Image
Digest
sha256:c1af23e57ā¦
Size
92.5 MB
Last updated
11 months ago
docker pull tungns1207/masque-proxy