알아봅시다 당신의 모든 웹 사이트는 내 것입니다. All your website are belong to us (with a reverse proxy) 사이트 훔치기
2020.05.05 18:33
당신의 모든 웹 사이트는 내 것입니다.
All your website are belong to us (with a reverse proxy) 사이트 훔치기
All your websites are belong to us (with a reverse proxy)
I have taken the habit to use a single domain as an umbrella for multiple websites. Which in short means we can benefit from different software stacks being hosted on different platforms.
As a bonus, we can use a custom domain on GitHub Pages with our own SSL certificate.
§tl;dr
Apache httpd ProxyPass and ProxyPassReverse are our best friend to mount an external URL (and its descendants) onto a folder of our very own domain.
§Why using a reverse proxy?
We are in 2016 and mentioning reverse proxy in a conversation sounds odd and pretty much dated from a different century. But hey, who cares?
I use reverse proxies for various reasons:
- to isolate components So instead of putting everything in a larger and larger monolithic website, we can manage them as different git repositories and have a different build process as well (like
/photographyand/talkson this website) - to manage different stacks In the case of a conference with a yearly edition or so, we can iterate over the software stack and change accordingly to our needs without having to upgrade legacy editions nor to keep continuing them because we feel obliged to.
- to provide a transparent experience to our users We can host content in different places and still provide a coherent experience to a user without having them to feel the spread of our infrastructure.
- to upgrade individual components One by one rather than the entire stacks. Which makes the life easier in term of Q&A scope. Obviously, we fall in the microservices trap so the more individual projects we have, the more scattered our attention and efforts can be.
- to run Docker containers or web applications We can prevent to expose them directly on the port 80 or 443 – although this is not the point of this article as we are rather focused on proxying external content.
It is a good way to hide complex and purposeful components under a same and apparently unique domain. This is for example how websites like the BBC feel like one website whereas they are in reality composed of dozens and dozens of different websites developed by independent teams.

§How does it work?
An HTTP request directed to our hosting provider will usually look like the following examples:
1 2 3 4 5 6 7 8 |
# Root example.com → VirtualHost → /var/www/example.com # Folder example.com/cheese → VirtualHost → /var/www/example.com/cheese # Specific file example.com/doc/index.html → VirtualHost → /var/www/example.com/doc/index.html |
By default we assume the folders /cheese and /doc are contained in the same directory as the root of the website.
Let's say we actually have decided to opt in for a whitelabeled content provider for a part of the website and moved another part of it to a static website hosted on GitHub Pages. The above example would evolve into:
1 2 3 4 5 6 7 8 |
# Root example.com → VirtualHost → /var/www/example.com # Folder example.com/cheese → VirtualHost + ProxyPass → http://cheese.com/whitelabel/example.com # File example.com/doc/index.html → VirtualHost + ProxyPass → http://example.github.io/site-doc/index.html |
It should be clear enough so let's dive a bit more in how to achieve this.
§Configuring ProxyPass
The configuration of a reverse mainly relies on a declaration of Apache ProxyPass for each path (and its descendants) we would like to host elsewhere:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 |
<VirtualHost *> ServerName example.com DocumentRoot /var/www/example.com <IfModule mod_proxy.c> ProxyPreserveHost Off ProxyPass /cheese http://cheese.com/whitelabel/example.com ProxyPassReverse /cheese http://cheese.com/whitelabel/example.com ProxyPass /doc http://example.github.io/site-doc ProxyPassReverse /doc http://example.github.io/site-doc </IfModule> </VirtualHost> |
And that's pretty much it!

§Configuring Proxy directives
I found Apache ProxyPass documentation to be quite clear actually (or maybe I spent too much time reading it). We can manage to exclude folders from the proxying or match only specific patterns with ProxyPassMatch. I guess all we need is a use case before starting to use them ????.
§ProxyPreserveHost
This setting has an influence on how our VirtualHost proxy server will advertise the Host HTTP header to the client.
With ProxyPreserveHost On:
1 2 3 |
curl --head http://example.com/cheese HTTP/1.1 200 Found Host: cheese.com |
With ProxyPreserveHost Off:
1 2 3 |
curl --head http://example.com/cheese HTTP/1.1 200 Found Host: example.com |
So in general we will want to have it set to Off, especially in the case of web browsers and relative link computation.
§ProxyPassReverse
This reverse directive indicates Apache how to treat location headers emitted by the backend of the proxy.
In other words, if the backend emits some headers like Location and Content-Location, our proxy will rewrite them to match our VirtualHost.
Without ProxyPassReverse:
1 2 3 |
curl --head http://example.com/cheese/old-uri HTTP/1.1 301 Redirect Location: http://cheese.com/whitelabel/example.com/new-uri |
With ProxyPassReverse:
1 2 3 |
curl --head http://example.com/cheese HTTP/1.1 301 Redirect Location: http://example.com/cheese/new-uri |
§ProxyPassReverseCookieDomain
This is exactly the same principle as ProxyPassReverse but to rewrite the hostnames contained in any Cookie header emitted by the backend.
§SSLProxyEngine
This one will enable the proxy module to deal with signed requests. We could definitely have an HTTP to HTTPS or, better, HTTPS to HTTP – to secure insecure parts of our website. Or to secure them… with a different SSL certificate.
And that's precisely one advantage to use a reverse proxy in front of GitHub Pages to use our custom domain and our own certificate.

§Reverse Proxy over HTTPS
GitHub serves every GitHub Pages websites over HTTPS if they have been created after June 15th 2016. So we will have to make sure both our server can talk over SSL with GitHub by enabling mod_ssl.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 |
# ∨∨∨∨∨∨ We add this line LoadModule ssl_module /wherever/is/apache2/modules/mod_ssl.so # ∧∧∧∧∧∧ <VirtualHost *> ServerName example.com <IfModule mod_proxy.c> ProxyPreserveHost Off # ∨∨∨∨∨∨ and this one too. SSLProxyEngine On # ∧∧∧∧∧∧ # ∨∨∨∨∨∨ Look, the backend URL now uses the https scheme! ProxyPass /doc https://example.github.io/site-doc ProxyPassReverse /doc https://example.github.io/site-doc </IfModule> </VirtualHost> |
As an alternative, we can also run the following to globally enable mod_ssl :
1
|
$ a2enmod mod_ssl
|
By doing so, we do not need to write the LoadModule line.
If we cannot enable mod_ssl, well we are screwed so best is to raise a support ticket to our hosting service provider if there is a way to enable it.

§Conclusion
Is the reverse proxy technique limited to Apache httpd? Of course not:
- Nginx has proxy_pass and a good reverse proxy tutorial;
- Varnish is more powerful but slightly harder to dive into its documentation;
- Node.js express-http-proxy package will help mount proxy routes in our Express application. I personally use it to proxy authentication at the app level and query internal APIs.
[출처] https://oncletom.io/2016/http-reverse-proxy/
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
| 번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
|---|---|---|---|---|
| 17 |
[알아봅시다] 원자로의 미래는 작을 수 있다”...전 세계가 뛰어든 SMR은 무엇
| 졸리운_곰 | 2023.01.22 | 246 |
| 16 |
[알아봅시다][물리학][시공간] [사이언스N사피엔스]시간과 공간이 아닌 시공간
| 졸리운_곰 | 2021.04.01 | 212 |
| 15 |
"우주 나이는 137억7천만년±4천만년"…허블상수 논쟁 해결 난망
| 졸리운_곰 | 2020.07.17 | 253 |
| 14 |
태양 표면 작은 폭발까지 드러낸 최근접 태양 이미지들
| 졸리운_곰 | 2020.07.17 | 302 |
| 13 |
[사이언스&사피엔스] 전자기학의 완성
| 졸리운_곰 | 2020.07.12 | 340 |
| 12 |
우주 생명체 '씨앗' 탄소 뿌리고 스러지는 백색왜성
| 졸리운_곰 | 2020.07.09 | 283 |
| 11 |
태양계 무게중심 100m 이내로 오차 줄여 블랙홀 연구 도약
| 졸리운_곰 | 2020.07.08 | 200 |
| 10 |
[잠깐과학]'우주배경복사' 발견하다
| 졸리운_곰 | 2020.07.06 | 300 |
| 9 |
초소형 블랙홀인가 초대형 중성자별인가...중력파로 발견한 미지의 천체
| 졸리운_곰 | 2020.06.30 | 183 |
| 8 |
[사이언스N사피엔스] 열역학과 엔트로피
| 졸리운_곰 | 2020.06.28 | 402 |
| 7 |
목성 위성 유로파 얼음층 밑 대양 "생명체가 꽤 서식할만한 곳"
| 졸리운_곰 | 2020.06.27 | 182 |
| 6 |
'무거운 중성자별일까 가벼운 블랙홀일까' 중력파로 미지의 천체 찾았다
| 졸리운_곰 | 2020.06.27 | 234 |
| 5 |
'1조분의 1초'만에 원자가 분자로 바뀌는 전 과정 세계 최초 포착
| 졸리운_곰 | 2020.06.27 | 346 |
| 4 |
[프리미엄리포트] ‘핵’ 빠르게 던지는 가속기
| 졸리운_곰 | 2020.06.27 | 173 |
| 3 |
"우주는 훌륭한 양자역학실험실…ISS서 BEC실험 첫 성공"
| 졸리운_곰 | 2020.06.15 | 172 |
| 2 |
우주 미스터리 풀어줄 157일 주기 '빠른 전파 폭발' 확인
| 졸리운_곰 | 2020.06.14 | 246 |
| 1 | 알파 센타우리 | 졸리운_곰 | 2019.01.23 | 511 |



Hello,
Can you hide the URL in the previous post ?
Yes it's work, I can connect to Traccar.
But now, after connection I have this error : Web socket connection error
And many errors about API in the developper console :
Errors developper console
I have change the config like this :
ProxyPass /traccar/api/socket/ ws://192.168.1.103:8082/api/socket/
ProxyPassReverse /traccar/api/socket/ ws:///192.168.1.103:8082/api/socket/
ProxyPass /traccar/ http://192.168.1.103:8082/
ProxyPassReverse /traccar/ http://192.168.1.103:8082/
But no work...
I have also test with one virtual machine with Traccar + Apache2 : it's the same, no work and same errors...
Thank you
Adrien