Ross ROSS = Recommend OSS · open-source software intelligence for agents

drk1wi/Modlishka

Modlishka. Reverse Proxy. observed · 2026-08-28

github.com/drk1wi/Modlishka · Go · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

66/100

  • Activity 97
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2814
  • days_rel: 472
  • days_push: 19
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

5407 stars · 960 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Modlishka is an open-source penetration testing tool written in Go that acts as a transparent man-in-the-middle reverse proxy. It can proxy multi-domain TLS and non-TLS traffic over a single domain without client certificate installation, and was the first public tool demonstrating 2FA bypass via adversary-in-the-middle techniques.

Use cases

  • set up a reverse proxy for ethical phishing penetration tests
  • demonstrate 2FA bypass weaknesses in security assessments
  • wrap legacy websites with TLS
  • transparently proxy arbitrary domains over HTTPS
  • inject JavaScript payloads into proxied web traffic
  • harvest credentials during authorized red team engagements

When to choose

  • you need a transparent AitM reverse proxy for authorized security testing
  • you want to demonstrate 2FA weaknesses to clients or stakeholders
  • you need to proxy multi-domain TLS traffic through a single domain
  • you want a stateless proxy that scales via DNS load balancing

When to avoid

  • you need a general-purpose production reverse proxy like nginx or traefik
  • you lack explicit authorization to test target systems
  • you need a simple forward proxy or VPN solution
  • your use case is defensive monitoring rather than offensive testing

Facets

cli-tool · maturity active

proxy penetration-testing security http-server security penetration-testing networking windows bsd go cli mitm reverse-proxy phishing-simulation 2fa-bypass red-team credential-harvesting tls linux macos

1 source

Member repositories

RepositoryRoleHealth v2
drk1wi/Modlishkamain66

For agents

markdown · JSON · MCP: product_card(name="drk1wi/Modlishka")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem