From 440fdd26061a0ad3c238f962a5acd0f6f258d556 Mon Sep 17 00:00:00 2001 From: lwthiker Date: Sun, 3 Jul 2022 12:08:41 +0300 Subject: [PATCH] Add impersonation support for Firefox 102 --- README.md | 1 + browsers.json | 10 + firefox/curl_ff102 | 22 ++ firefox/patches/curl-impersonate.patch | 424 +++++++++++++++---------- tests/signatures/firefox.yaml | 88 +++++ tests/test_impersonate.py | 9 + 6 files changed, 378 insertions(+), 176 deletions(-) create mode 100755 firefox/curl_ff102 diff --git a/README.md b/README.md index 3be0f2e..0d12763 100644 --- a/README.md +++ b/README.md @@ -38,6 +38,7 @@ The following browsers can be impersonated. | ![Firefox](https://raw.githubusercontent.com/alrra/browser-logos/main/src/firefox/firefox_24x24.png "Firefox") | 95 | 95.0.2 | Windows 10 | `ff95` | [curl_ff95](firefox/curl_ff95) | | ![Firefox](https://raw.githubusercontent.com/alrra/browser-logos/main/src/firefox/firefox_24x24.png "Firefox") | 98 | 98.0 | Windows 10 | `ff98` | [curl_ff98](firefox/curl_ff98) | | ![Firefox](https://raw.githubusercontent.com/alrra/browser-logos/main/src/firefox/firefox_24x24.png "Firefox") | 100 | 100.0 | Windows 10 | `ff100` | [curl_ff100](firefox/curl_ff100) | +| ![Firefox](https://raw.githubusercontent.com/alrra/browser-logos/main/src/firefox/firefox_24x24.png "Firefox") | 102 | 102.0 | Windows 10 | `ff102` | [curl_ff102](firefox/curl_ff102) | | ![Safari](https://github.com/alrra/browser-logos/blob/main/src/safari/safari_24x24.png "Safari") | 15.3 | 16612.4.9.1.8 | MacOS Big Sur | `safari15_3` | [curl_safari15_3](chrome/curl_safari15_3) | This list is also available in the [browsers.json](browsers.json) file. diff --git a/browsers.json b/browsers.json index 3346fec..d711075 100644 --- a/browsers.json +++ b/browsers.json @@ -101,6 +101,16 @@ "binary": "curl-impersonate-ff", "wrapper_script": "curl_ff100" }, + { + "name": "ff102", + "browser": { + "name": "firefox", + "version": "102.0", + "os": "win10" + }, + "binary": "curl-impersonate-ff", + "wrapper_script": "curl_ff102" + }, { "name": "safari15_3", "browser": { diff --git a/firefox/curl_ff102 b/firefox/curl_ff102 new file mode 100755 index 0000000..c810652 --- /dev/null +++ b/firefox/curl_ff102 @@ -0,0 +1,22 @@ +#!/usr/bin/env bash + +# Find the directory of this script +dir=${0%/*} + +# The list of ciphers can be obtained by looking at the Client Hello message in +# Wireshark, then converting it using the cipherlist array at +# https://github.com/curl/curl/blob/master/lib/vtls/nss.c +"$dir/curl-impersonate-ff" \ + --ciphers aes_128_gcm_sha_256,chacha20_poly1305_sha_256,aes_256_gcm_sha_384,ecdhe_ecdsa_aes_128_gcm_sha_256,ecdhe_rsa_aes_128_gcm_sha_256,ecdhe_ecdsa_chacha20_poly1305_sha_256,ecdhe_rsa_chacha20_poly1305_sha_256,ecdhe_ecdsa_aes_256_gcm_sha_384,ecdhe_rsa_aes_256_gcm_sha_384,ecdhe_ecdsa_aes_256_sha,ecdhe_ecdsa_aes_128_sha,ecdhe_rsa_aes_128_sha,ecdhe_rsa_aes_256_sha,rsa_aes_128_gcm_sha_256,rsa_aes_256_gcm_sha_384,rsa_aes_128_sha,rsa_aes_256_sha \ + -H 'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0' \ + -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8' \ + -H 'Accept-Language: en-US,en;q=0.5' \ + -H 'Accept-Encoding: gzip, deflate, br' \ + -H 'Upgrade-Insecure-Requests: 1' \ + -H 'Sec-Fetch-Dest: document' \ + -H 'Sec-Fetch-Mode: navigate' \ + -H 'Sec-Fetch-Site: none' \ + -H 'Sec-Fetch-User: ?1' \ + -H 'TE: Trailers' \ + --http2 --false-start --compressed \ + "$@" diff --git a/firefox/patches/curl-impersonate.patch b/firefox/patches/curl-impersonate.patch index 48eef26..3ccaa71 100644 --- a/firefox/patches/curl-impersonate.patch +++ b/firefox/patches/curl-impersonate.patch @@ -215,183 +215,35 @@ index 769363941..6e2f1b829 100644 libcurlu_la_SOURCES = $(CSOURCES) $(HHEADERS) CHECKSRC = $(CS_$(V)) +diff --git a/lib/Makefile.inc b/lib/Makefile.inc +index 3e9ddec12..fb883832d 100644 +--- a/lib/Makefile.inc ++++ b/lib/Makefile.inc +@@ -157,6 +157,7 @@ LIB_CFILES = \ + idn_win32.c \ + if2ip.c \ + imap.c \ ++ impersonate.c \ + inet_ntop.c \ + inet_pton.c \ + krb5.c \ diff --git a/lib/easy.c b/lib/easy.c -index 20293a710..66730b5fc 100644 +index 20293a710..88484d5af 100644 --- a/lib/easy.c +++ b/lib/easy.c -@@ -80,6 +80,7 @@ +@@ -80,6 +80,8 @@ #include "dynbuf.h" #include "altsvc.h" #include "hsts.h" +#include "strcase.h" ++#include "impersonate.h" /* The last 3 #include files should be in this order */ #include "curl_printf.h" -@@ -282,6 +283,237 @@ void curl_global_cleanup(void) +@@ -282,6 +284,73 @@ void curl_global_cleanup(void) init_flags = 0; } -+/* -+ * curl-impersonate: Options to be set for each supported target browser. -+ * Note: this does not include the HTTP headers, which are handled separately -+ * in Curl_http(). -+ */ -+#define IMPERSONATE_MAX_HEADERS 32 -+static const struct impersonate_opts { -+ const char *target; -+ int httpversion; -+ int ssl_version; -+ const char *ciphers; -+ const char *http_headers[IMPERSONATE_MAX_HEADERS]; -+ /* Other TLS options will come here in the future once they are -+ * configurable through curl_easy_setopt() */ -+} impersonations[] = { -+ { -+ .target = "ff91esr", -+ .httpversion = CURL_HTTP_VERSION_2_0, -+ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, -+ .ciphers = -+ "aes_128_gcm_sha_256," -+ "chacha20_poly1305_sha_256," -+ "aes_256_gcm_sha_384," -+ "ecdhe_ecdsa_aes_128_gcm_sha_256," -+ "ecdhe_rsa_aes_128_gcm_sha_256," -+ "ecdhe_ecdsa_chacha20_poly1305_sha_256," -+ "ecdhe_rsa_chacha20_poly1305_sha_256," -+ "ecdhe_ecdsa_aes_256_gcm_sha_384," -+ "ecdhe_rsa_aes_256_gcm_sha_384," -+ "ecdhe_ecdsa_aes_256_sha," -+ "ecdhe_ecdsa_aes_128_sha," -+ "ecdhe_rsa_aes_128_sha," -+ "ecdhe_rsa_aes_256_sha," -+ "rsa_aes_128_gcm_sha_256," -+ "rsa_aes_256_gcm_sha_384," -+ "rsa_aes_128_sha," -+ "rsa_aes_256_sha," -+ "rsa_3des_ede_cbc_sha", -+ .http_headers = { -+ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0", -+ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8", -+ "Accept-Language: en-US,en;q=0.5", -+ "Accept-Encoding: gzip, deflate, br", -+ "Upgrade-Insecure-Requests: 1", -+ "Sec-Fetch-Dest: document", -+ "Sec-Fetch-Mode: navigate", -+ "Sec-Fetch-Site: none", -+ "Sec-Fetch-User: ?1", -+ "TE: Trailers" -+ } -+ }, -+ { -+ .target = "ff95", -+ .httpversion = CURL_HTTP_VERSION_2_0, -+ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, -+ .ciphers = -+ "aes_128_gcm_sha_256," -+ "chacha20_poly1305_sha_256," -+ "aes_256_gcm_sha_384," -+ "ecdhe_ecdsa_aes_128_gcm_sha_256," -+ "ecdhe_rsa_aes_128_gcm_sha_256," -+ "ecdhe_ecdsa_chacha20_poly1305_sha_256," -+ "ecdhe_rsa_chacha20_poly1305_sha_256," -+ "ecdhe_ecdsa_aes_256_gcm_sha_384," -+ "ecdhe_rsa_aes_256_gcm_sha_384," -+ "ecdhe_ecdsa_aes_256_sha," -+ "ecdhe_ecdsa_aes_128_sha," -+ "ecdhe_rsa_aes_128_sha," -+ "ecdhe_rsa_aes_256_sha," -+ "rsa_aes_128_gcm_sha_256," -+ "rsa_aes_256_gcm_sha_384," -+ "rsa_aes_128_sha," -+ "rsa_aes_256_sha", -+ .http_headers = { -+ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0", -+ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8", -+ "Accept-Language: en-US,en;q=0.5", -+ "Accept-Encoding: gzip, deflate, br", -+ "Upgrade-Insecure-Requests: 1", -+ "Sec-Fetch-Dest: document", -+ "Sec-Fetch-Mode: navigate", -+ "Sec-Fetch-Site: none", -+ "Sec-Fetch-User: ?1", -+ "TE: Trailers" -+ } -+ }, -+ { -+ .target = "ff98", -+ .httpversion = CURL_HTTP_VERSION_2_0, -+ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, -+ .ciphers = -+ "aes_128_gcm_sha_256," -+ "chacha20_poly1305_sha_256," -+ "aes_256_gcm_sha_384," -+ "ecdhe_ecdsa_aes_128_gcm_sha_256," -+ "ecdhe_rsa_aes_128_gcm_sha_256," -+ "ecdhe_ecdsa_chacha20_poly1305_sha_256," -+ "ecdhe_rsa_chacha20_poly1305_sha_256," -+ "ecdhe_ecdsa_aes_256_gcm_sha_384," -+ "ecdhe_rsa_aes_256_gcm_sha_384," -+ "ecdhe_ecdsa_aes_256_sha," -+ "ecdhe_ecdsa_aes_128_sha," -+ "ecdhe_rsa_aes_128_sha," -+ "ecdhe_rsa_aes_256_sha," -+ "rsa_aes_128_gcm_sha_256," -+ "rsa_aes_256_gcm_sha_384," -+ "rsa_aes_128_sha," -+ "rsa_aes_256_sha", -+ .http_headers = { -+ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:98.0) Gecko/20100101 Firefox/98.0", -+ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8", -+ "Accept-Language: en-US,en;q=0.5", -+ "Accept-Encoding: gzip, deflate, br", -+ "Upgrade-Insecure-Requests: 1", -+ "Sec-Fetch-Dest: document", -+ "Sec-Fetch-Mode: navigate", -+ "Sec-Fetch-Site: none", -+ "Sec-Fetch-User: ?1", -+ "TE: Trailers" -+ } -+ }, -+ { -+ .target = "ff100", -+ .httpversion = CURL_HTTP_VERSION_2_0, -+ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, -+ .ciphers = -+ "aes_128_gcm_sha_256," -+ "chacha20_poly1305_sha_256," -+ "aes_256_gcm_sha_384," -+ "ecdhe_ecdsa_aes_128_gcm_sha_256," -+ "ecdhe_rsa_aes_128_gcm_sha_256," -+ "ecdhe_ecdsa_chacha20_poly1305_sha_256," -+ "ecdhe_rsa_chacha20_poly1305_sha_256," -+ "ecdhe_ecdsa_aes_256_gcm_sha_384," -+ "ecdhe_rsa_aes_256_gcm_sha_384," -+ "ecdhe_ecdsa_aes_256_sha," -+ "ecdhe_ecdsa_aes_128_sha," -+ "ecdhe_rsa_aes_128_sha," -+ "ecdhe_rsa_aes_256_sha," -+ "rsa_aes_128_gcm_sha_256," -+ "rsa_aes_256_gcm_sha_384," -+ "rsa_aes_128_sha," -+ "rsa_aes_256_sha", -+ .http_headers = { -+ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0", -+ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8", -+ "Accept-Language: en-US,en;q=0.5", -+ "Accept-Encoding: gzip, deflate, br", -+ "Upgrade-Insecure-Requests: 1", -+ "Sec-Fetch-Dest: document", -+ "Sec-Fetch-Mode: navigate", -+ "Sec-Fetch-Site: none", -+ "Sec-Fetch-User: ?1", -+ "TE: Trailers" -+ } -+ } -+}; -+ -+#define NUM_IMPERSONATIONS \ -+ sizeof(impersonations) / sizeof(impersonations[0]) -+ +/* + * curl-impersonate: + * Call curl_easy_setopt() with all the needed options as defined in the @@ -401,19 +253,16 @@ index 20293a710..66730b5fc 100644 +{ + int i; + int ret; -+ const struct impersonate_opts *opts = NULL; ++ const struct impersonate_opts *opts; + struct curl_slist *headers = NULL; + -+ for(i = 0; i < NUM_IMPERSONATIONS; i++) { -+ if (Curl_strncasecompare(target, -+ impersonations[i].target, -+ strlen(impersonations[i].target))) { -+ opts = &impersonations[i]; ++ for (opts = impersonations; opts->target != NULL; opts++) { ++ if (Curl_strncasecompare(target, opts->target, strlen(opts->target))) { + break; + } + } + -+ if(!opts) { ++ if(opts->target == NULL) { + DEBUGF(fprintf(stderr, "Error: unknown impersonation target '%s'\n", + target)); + return CURLE_BAD_FUNCTION_ARGUMENT; @@ -465,7 +314,7 @@ index 20293a710..66730b5fc 100644 /* * curl_easy_init() is the external interface to alloc, setup and init an * easy handle that is returned. If anything goes wrong, NULL is returned. -@@ -290,6 +522,7 @@ struct Curl_easy *curl_easy_init(void) +@@ -290,6 +359,7 @@ struct Curl_easy *curl_easy_init(void) { CURLcode result; struct Curl_easy *data; @@ -473,7 +322,7 @@ index 20293a710..66730b5fc 100644 /* Make sure we inited the global SSL stuff */ if(!initialized) { -@@ -308,6 +541,22 @@ struct Curl_easy *curl_easy_init(void) +@@ -308,6 +378,22 @@ struct Curl_easy *curl_easy_init(void) return NULL; } @@ -496,7 +345,7 @@ index 20293a710..66730b5fc 100644 return data; } -@@ -878,6 +1127,13 @@ struct Curl_easy *curl_easy_duphandle(struct Curl_easy *data) +@@ -878,6 +964,13 @@ struct Curl_easy *curl_easy_duphandle(struct Curl_easy *data) outcurl->state.referer_alloc = TRUE; } @@ -510,7 +359,7 @@ index 20293a710..66730b5fc 100644 /* Reinitialize an SSL engine for the new handle * note: the engine name has already been copied by dupset */ if(outcurl->set.str[STRING_SSL_ENGINE]) { -@@ -967,6 +1223,8 @@ struct Curl_easy *curl_easy_duphandle(struct Curl_easy *data) +@@ -967,6 +1060,8 @@ struct Curl_easy *curl_easy_duphandle(struct Curl_easy *data) */ void curl_easy_reset(struct Curl_easy *data) { @@ -519,7 +368,7 @@ index 20293a710..66730b5fc 100644 Curl_free_request_state(data); /* zero out UserDefined data: */ -@@ -991,6 +1249,12 @@ void curl_easy_reset(struct Curl_easy *data) +@@ -991,6 +1086,12 @@ void curl_easy_reset(struct Curl_easy *data) #if !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_CRYPTO_AUTH) Curl_http_auth_cleanup_digest(data); #endif @@ -899,6 +748,229 @@ index e74400a4c..1dd2593a5 100644 /* we are going to copy mem to httpc->inbuf. This is required since mem is part of buffer pointed by stream->mem, and callbacks called by nghttp2_session_mem_recv() will write stream specific +diff --git a/lib/impersonate.c b/lib/impersonate.c +new file mode 100644 +index 000000000..086fb383a +--- /dev/null ++++ b/lib/impersonate.c +@@ -0,0 +1,186 @@ ++#include "curl_setup.h" ++ ++#include "impersonate.h" ++ ++const struct impersonate_opts impersonations[] = { ++ { ++ .target = "ff91esr", ++ .httpversion = CURL_HTTP_VERSION_2_0, ++ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, ++ .ciphers = ++ "aes_128_gcm_sha_256," ++ "chacha20_poly1305_sha_256," ++ "aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_128_gcm_sha_256," ++ "ecdhe_rsa_aes_128_gcm_sha_256," ++ "ecdhe_ecdsa_chacha20_poly1305_sha_256," ++ "ecdhe_rsa_chacha20_poly1305_sha_256," ++ "ecdhe_ecdsa_aes_256_gcm_sha_384," ++ "ecdhe_rsa_aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_256_sha," ++ "ecdhe_ecdsa_aes_128_sha," ++ "ecdhe_rsa_aes_128_sha," ++ "ecdhe_rsa_aes_256_sha," ++ "rsa_aes_128_gcm_sha_256," ++ "rsa_aes_256_gcm_sha_384," ++ "rsa_aes_128_sha," ++ "rsa_aes_256_sha," ++ "rsa_3des_ede_cbc_sha", ++ .http_headers = { ++ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0", ++ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8", ++ "Accept-Language: en-US,en;q=0.5", ++ "Accept-Encoding: gzip, deflate, br", ++ "Upgrade-Insecure-Requests: 1", ++ "Sec-Fetch-Dest: document", ++ "Sec-Fetch-Mode: navigate", ++ "Sec-Fetch-Site: none", ++ "Sec-Fetch-User: ?1", ++ "TE: Trailers" ++ } ++ }, ++ { ++ .target = "ff95", ++ .httpversion = CURL_HTTP_VERSION_2_0, ++ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, ++ .ciphers = ++ "aes_128_gcm_sha_256," ++ "chacha20_poly1305_sha_256," ++ "aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_128_gcm_sha_256," ++ "ecdhe_rsa_aes_128_gcm_sha_256," ++ "ecdhe_ecdsa_chacha20_poly1305_sha_256," ++ "ecdhe_rsa_chacha20_poly1305_sha_256," ++ "ecdhe_ecdsa_aes_256_gcm_sha_384," ++ "ecdhe_rsa_aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_256_sha," ++ "ecdhe_ecdsa_aes_128_sha," ++ "ecdhe_rsa_aes_128_sha," ++ "ecdhe_rsa_aes_256_sha," ++ "rsa_aes_128_gcm_sha_256," ++ "rsa_aes_256_gcm_sha_384," ++ "rsa_aes_128_sha," ++ "rsa_aes_256_sha", ++ .http_headers = { ++ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0", ++ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8", ++ "Accept-Language: en-US,en;q=0.5", ++ "Accept-Encoding: gzip, deflate, br", ++ "Upgrade-Insecure-Requests: 1", ++ "Sec-Fetch-Dest: document", ++ "Sec-Fetch-Mode: navigate", ++ "Sec-Fetch-Site: none", ++ "Sec-Fetch-User: ?1", ++ "TE: Trailers" ++ } ++ }, ++ { ++ .target = "ff98", ++ .httpversion = CURL_HTTP_VERSION_2_0, ++ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, ++ .ciphers = ++ "aes_128_gcm_sha_256," ++ "chacha20_poly1305_sha_256," ++ "aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_128_gcm_sha_256," ++ "ecdhe_rsa_aes_128_gcm_sha_256," ++ "ecdhe_ecdsa_chacha20_poly1305_sha_256," ++ "ecdhe_rsa_chacha20_poly1305_sha_256," ++ "ecdhe_ecdsa_aes_256_gcm_sha_384," ++ "ecdhe_rsa_aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_256_sha," ++ "ecdhe_ecdsa_aes_128_sha," ++ "ecdhe_rsa_aes_128_sha," ++ "ecdhe_rsa_aes_256_sha," ++ "rsa_aes_128_gcm_sha_256," ++ "rsa_aes_256_gcm_sha_384," ++ "rsa_aes_128_sha," ++ "rsa_aes_256_sha", ++ .http_headers = { ++ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:98.0) Gecko/20100101 Firefox/98.0", ++ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8", ++ "Accept-Language: en-US,en;q=0.5", ++ "Accept-Encoding: gzip, deflate, br", ++ "Upgrade-Insecure-Requests: 1", ++ "Sec-Fetch-Dest: document", ++ "Sec-Fetch-Mode: navigate", ++ "Sec-Fetch-Site: none", ++ "Sec-Fetch-User: ?1", ++ "TE: Trailers" ++ } ++ }, ++ { ++ .target = "ff100", ++ .httpversion = CURL_HTTP_VERSION_2_0, ++ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, ++ .ciphers = ++ "aes_128_gcm_sha_256," ++ "chacha20_poly1305_sha_256," ++ "aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_128_gcm_sha_256," ++ "ecdhe_rsa_aes_128_gcm_sha_256," ++ "ecdhe_ecdsa_chacha20_poly1305_sha_256," ++ "ecdhe_rsa_chacha20_poly1305_sha_256," ++ "ecdhe_ecdsa_aes_256_gcm_sha_384," ++ "ecdhe_rsa_aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_256_sha," ++ "ecdhe_ecdsa_aes_128_sha," ++ "ecdhe_rsa_aes_128_sha," ++ "ecdhe_rsa_aes_256_sha," ++ "rsa_aes_128_gcm_sha_256," ++ "rsa_aes_256_gcm_sha_384," ++ "rsa_aes_128_sha," ++ "rsa_aes_256_sha", ++ .http_headers = { ++ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0", ++ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8", ++ "Accept-Language: en-US,en;q=0.5", ++ "Accept-Encoding: gzip, deflate, br", ++ "Upgrade-Insecure-Requests: 1", ++ "Sec-Fetch-Dest: document", ++ "Sec-Fetch-Mode: navigate", ++ "Sec-Fetch-Site: none", ++ "Sec-Fetch-User: ?1", ++ "TE: Trailers" ++ } ++ }, ++ { ++ .target = "ff102", ++ .httpversion = CURL_HTTP_VERSION_2_0, ++ .ssl_version = CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_DEFAULT, ++ .ciphers = ++ "aes_128_gcm_sha_256," ++ "chacha20_poly1305_sha_256," ++ "aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_128_gcm_sha_256," ++ "ecdhe_rsa_aes_128_gcm_sha_256," ++ "ecdhe_ecdsa_chacha20_poly1305_sha_256," ++ "ecdhe_rsa_chacha20_poly1305_sha_256," ++ "ecdhe_ecdsa_aes_256_gcm_sha_384," ++ "ecdhe_rsa_aes_256_gcm_sha_384," ++ "ecdhe_ecdsa_aes_256_sha," ++ "ecdhe_ecdsa_aes_128_sha," ++ "ecdhe_rsa_aes_128_sha," ++ "ecdhe_rsa_aes_256_sha," ++ "rsa_aes_128_gcm_sha_256," ++ "rsa_aes_256_gcm_sha_384," ++ "rsa_aes_128_sha," ++ "rsa_aes_256_sha", ++ .http_headers = { ++ "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0", ++ "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8", ++ "Accept-Language: en-US,en;q=0.5", ++ "Accept-Encoding: gzip, deflate, br", ++ "Upgrade-Insecure-Requests: 1", ++ "Sec-Fetch-Dest: document", ++ "Sec-Fetch-Mode: navigate", ++ "Sec-Fetch-Site: none", ++ "Sec-Fetch-User: ?1", ++ "TE: Trailers" ++ } ++ }, ++ { ++ /* Last one must be NULL. */ ++ .target = NULL ++ } ++}; +diff --git a/lib/impersonate.h b/lib/impersonate.h +new file mode 100644 +index 000000000..964b81f2e +--- /dev/null ++++ b/lib/impersonate.h +@@ -0,0 +1,25 @@ ++#ifndef HEADER_CURL_IMPERSONATE_H ++#define HEADER_CURL_IMPERSONATE_H ++ ++#define IMPERSONATE_MAX_HEADERS 32 ++ ++/* ++ * curl-impersonate: Options to be set for each supported target browser. ++ */ ++struct impersonate_opts { ++ const char *target; ++ int httpversion; ++ int ssl_version; ++ const char *ciphers; ++ const char *http_headers[IMPERSONATE_MAX_HEADERS]; ++ /* Other TLS options will come here in the future once they are ++ * configurable through curl_easy_setopt() */ ++}; ++ ++/* ++ * curl-impersonate: Global array of supported browsers and their ++ * impersonation options. ++ */ ++extern const struct impersonate_opts impersonations[]; ++ ++#endif /* HEADER_CURL_IMPERSONATE_H */ diff --git a/lib/setopt.c b/lib/setopt.c index 599ed5d99..1baa48e70 100644 --- a/lib/setopt.c diff --git a/tests/signatures/firefox.yaml b/tests/signatures/firefox.yaml index f8655cf..08b6ece 100644 --- a/tests/signatures/firefox.yaml +++ b/tests/signatures/firefox.yaml @@ -351,3 +351,91 @@ signature: - 'sec-fetch-site: none' - 'sec-fetch-user: ?1' - 'te: trailers' +--- +name: firefox_102.0_win10 +browser: + name: firefox + version: 102.0 + os: win10 + mode: regular +signature: + tls_client_hello: + record_version: 'TLS_VERSION_1_0' + handshake_version: 'TLS_VERSION_1_2' + session_id_length: 32 + ciphersuites: [ + 0x1301, 0x1303, 0x1302, 0xc02b, 0xc02f, 0xcca9, 0xcca8, 0xc02c, + 0xc030, 0xc00a, 0xc009, 0xc013, 0xc014, 0x009c, 0x009d, 0x002f, + 0x0035 + ] + comp_methods: [0x00] + extensions: + - type: server_name + - type: extended_master_secret + length: 0 + - type: renegotiation_info + length: 1 + - type: supported_groups + length: 14 + supported_groups: [ + 0x1d, 0x017, 0x18, 0x19, 0x0100, 0x0101 + ] + - type: ec_point_formats + length: 2 + ec_point_formats: [0] + - type: session_ticket + length: 0 + - type: application_layer_protocol_negotiation + length: 14 + alpn_list: ['h2', 'http/1.1'] + - type: status_request + length: 5 + status_request_type: 0x01 + - type: delegated_credentials + length: 10 + sig_hash_algs: [ + 0x0403, 0x0503, 0x0603, 0x0203 + ] + - type: keyshare + length: 107 + key_shares: + - group: 29 + length: 32 + - group: 23 + length: 65 + - type: supported_versions + length: 5 + supported_versions: [ + 'TLS_VERSION_1_3', 'TLS_VERSION_1_2' + ] + - type: signature_algorithms + length: 24 + sig_hash_algs: [ + 0x0403, 0x0503, 0x0603, 0x0804, + 0x0805, 0x0806, 0x0401, 0x0501, + 0x0601, 0x0203, 0x0201 + ] + - type: psk_key_exchange_modes + length: 2 + psk_ke_mode: 1 + - type: record_size_limit + length: 2 + record_size_limit: 16385 + - type: padding + http2: + pseudo_headers: + - ':method' + - ':path' + - ':authority' + - ':scheme' + headers: + - 'user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0' + - 'accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8' + - 'accept-language: en-US,en;q=0.5' + - 'accept-encoding: gzip, deflate, br' + - 'upgrade-insecure-requests: 1' + - 'sec-fetch-dest: document' + - 'sec-fetch-mode: navigate' + - 'sec-fetch-site: none' + - 'sec-fetch-user: ?1' + - 'te: trailers' diff --git a/tests/test_impersonate.py b/tests/test_impersonate.py index a0af2b3..605c222 100644 --- a/tests/test_impersonate.py +++ b/tests/test_impersonate.py @@ -148,6 +148,7 @@ class TestImpersonation: ("curl_ff95", None, None, "firefox_95.0.2_win10"), ("curl_ff98", None, None, "firefox_98.0_win10"), ("curl_ff100", None, None, "firefox_100.0_win10"), + ("curl_ff102", None, None, "firefox_102.0_win10"), # Test libcurl-impersonate by loading it with LD_PRELOAD to an app # linked against the regular libcurl and setting the @@ -239,6 +240,14 @@ class TestImpersonation: }, "libcurl-impersonate-ff", "firefox_100.0_win10" + ), + ( + "minicurl", + { + "CURL_IMPERSONATE": "ff102" + }, + "libcurl-impersonate-ff", + "firefox_102.0_win10" ) ]