用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/uphiago/recon-skills --skill tls-fingerprint-impersonation命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | tls-fingerprint-impersonation |
| description | Spoof TLS ClientHello and JA4 fingerprints for browser impersonation. |
| version | 1.1.0 |
| revision_date | "2026-07-25T00:00:00.000Z" |
| license | MIT |
| platforms | ["linux"] |
| compatibility | Requires curl, httpx, python3 |
| tags | ["recon","TLS","JA3","JA4","fingerprint","impersonation","HTTP","browser"] |
| category | recon |
| related_skills | ["http2-header-impersonation","stealth-browser-launch","humanize-automation"] |
Spoof TLS ClientHello parameters — cipher suites, key exchange groups, signature algorithms, and extension order — to match real browsers at the JA3/JA4 fingerprint level. Uses patched rustls to rebuild the TLS layer with browser-identical configurations. Bypasses TLS fingerprinting detection (Cloudflare, Akamai, F5) that flags non-browser TLS stacks. Supports 20 browser profiles including Chrome 100-142, Firefox 128-144, Safari iOS 18, and OkHttp 3-5 (Android).
terminal with python3.pip install impit (wraps the Rust library via PyO3).npm install impit (native binding).impit crate with patched dependencies in Cargo.toml.# Check if a target blocks non-browser TLS
curl --max-time 30 --connect-timeout 10 -sk https://target.com | head -1
# If 403, test with browser impersonation:
python3 -c "
from impit import Impit
impit = Impit.builder().with_fingerprint('chrome142').build()
r = impit.get('https://target.com').text
print(r[:200])
"
Choose the right fingerprint for your target:
| Profile | Use case | Key differentiator |
|---|---|---|
chrome142 | Modern desktop | Latest Chrome, post-quantum KEX (X25519MLKEM768), GREASE |
chrome100 | Legacy systems | Older cipher suites, no GREASE in key exchange |
firefox144 | Firefox desktop | Different pseudo-header order, FFDHE groups, SHA-1 signatures |
safari_ios18 |
| iOS mobile |
| 3DES ciphers, duplicate signature algorithm, no session tickets |
okhttp4 | Android apps | BoringSSL profile, no GREASE, no ECH, simpler cipher suites |
chrome124 | Common default | Good balance of modern compatibility and detection pass rate |
from impit import Impit
# Chrome 142 (latest)
client = Impit.builder().with_fingerprint("chrome142").build()
# Firefox 144
client = Impit.builder().with_fingerprint("firefox144").build()
# Safari iOS 18 (mobile API endpoints)
client = Impit.builder().with_fingerprint("ios18").build()
# OkHttp 4 (Android app impersonation)
client = Impit.builder().with_fingerprint("okhttp4").build()
from impit import Impit
impit = (
Impit.builder()
.with_fingerprint("chrome142")
.with_ignore_tls_errors(True) # for self-signed certs during recon
.with_http3() # HTTP/3 support
.with_fallback_to_vanilla(True) # retry without fingerprint if blocked
.build()
)
response = impit.get("https://target.com")
print(response.status_code)
print(response.headers)
print(response.text()[:500])
impit = (
Impit.builder()
.with_fingerprint("chrome142")
.with_proxy("http://user:pass@residential-proxy:8080")
.with_default_timeout(15_000) # 15 seconds in milliseconds
.build()
)
response = impit.get("https://target.com/api/endpoint")
# Custom headers are merged with fingerprint defaults
# Fingerprint headers have lower priority — custom headers win on conflict
response = impit.get(
"https://target.com/api/v1",
headers={
"X-Forwarded-For": "[REDACTED_IP]",
"Authorization": "Bearer token",
}
)
from impit.cookie import Jar
impit = (
Impit.builder()
.with_fingerprint("chrome142")
.with_cookie_store(Jar()) # persistent cookie jar
.build()
)
# Login
impit.post("https://target.com/login", json={
"username": "admin", "password": "admin"
})
# Authenticated request — cookies preserved automatically
response = impit.get("https://target.com/dashboard")
Choose based on target characteristics:
def select_fingerprint(target_url):
"""Auto-select browser fingerprint based on target."""
if "mobile" in target_url or "api/v2" in target_url:
return "ios18"
elif "android" in target_url or "play.google" in target_url:
return "okhttp4"
elif target_url.startswith("https://"):
return "chrome142" # default for modern HTTPS
return "chrome124"
Verify your TLS fingerprint is working correctly:
# Test against a site that returns JA4 hash in response headers
python3 -c "
from impit import Impit
impit = Impit.builder().with_fingerprint('chrome142').build()
r = impit.get('https://cloudflare.com/cdn-cgi/trace')
print(r.text())
# Look for JA4 hash in trace output or response headers
"
| Feature | Chrome 142 | Firefox 144 | Safari iOS 18 | OkHttp 4 |
|---|---|---|---|---|
| TLS versions | 1.3 + 1.2 | 1.3 + 1.2 | 1.3 + 1.2 | 1.3 + 1.2 |
| GREASE cipher | ✅ (pos 1) | ❌ | ✅ | ❌ |
| GREASE key exchange | ✅ (pos 1) | ❌ | ✅ | ❌ |
| Post-quantum (MLKEM768) | ✅ | ✅ | ✅ | ❌ |
| FFDHE groups | ❌ | ✅ (2048/3072) | ❌ | ❌ |
| SHA-1 signatures | ❌ | ✅ | ✅ (legacy) | ✅ (RSA only) |
| ECH GREASE | ✅ | ✅ | ❌ | ❌ |
| 3DES ciphers | ❌ | ❌ | ✅ | ❌ |
| Certificate compression | Brotli | Zlib+Brotli+Zstd | Zlib | ❌ |
| Delegated credentials | ❌ | ✅ | ❌ | ❌ |
| Session tickets | ✅ | ✅ | ❌ | ✅ |
| Duplicate signatures | ❌ | ❌ | ✅ (RsaPssRsaSha384) | ❌ |
| Browser | Stream Window | Connection Window | Pseudo-Header Order |
|---|---|---|---|
| Chrome | 6,291,456 | 15,663,105 | :method :authority :scheme :path |
| Firefox | 131,072 | 12,517,377 | :method :path :authority :scheme |
| Safari iOS | 2,097,152 | 10,485,760 | :method :scheme :authority :path |
| OkHttp | 16,777,216 | 16,777,216 | :method :path :authority :scheme |
| Browser | Format | Example |
|---|---|---|
| Chrome | ----WebKitFormBoundary + 16 alphanumeric | ----WebKitFormBoundaryx8fH3kLm9pQr2sTv |
| Firefox | ----geckoformboundary + hex u64 values | ----geckoformboundary3fa8c10e5d6b2904 |
| OkHttp | UUID v4 | 550e8400-e29b-41d4-a716-446655440000 |
with_http3() flag only matters for sites that support it.CryptoProvider instances are cached per fingerprint — subsequent requests are fast.vanilla_fallback if stealth is critical.https://www.howsmyssl.com/ or Cloudflare trace endpoint.cf-ja4 response header when hitting Cloudflare-protected sites.http2-header-impersonation — HTTP/2 pseudo-header ordering and SETTINGS frame matching.stealth-browser-launch — Full browser automation with C++ fingerprint patches for JS-heavy targets.humanize-automation — Human-like interaction patterns for behavioral detection bypass.