Bismit Panda

athena-proxy

Cross-platform CLI that gives every Athena CTF challenge instance a plain TCP address on localhost, so netcat, pwntools, and any socket tool reach it without speaking TLS.

athena-proxy

Project Details

Client

AstraQ Cyber Defence

Year

2026

Role

Developer

Status

Open source

Ownership

Sole author

Technologies

GoTLSCLI

The Challenge

Athena routes every challenge instance by TLS server name at a shared gateway on port 443. That keeps instances private per team, but most exploitation tooling expects a raw TCP socket.

The Solution

Built a Go daemon that serves one loopback listener per registered hostname. Each connection opens exactly one TLS connection to the gateway with SNI set to that hostname and pumps bytes both ways. Targets can be added and removed while the daemon is running, through a loopback control port. Signed release archives with build provenance attestations cover Linux, macOS, and Windows on x86-64 and ARM64, with one-line installers.

Highlights

  • One TLS connection per local connection, with no pooling or multiplexing
  • Daemon accepts new targets live, without a restart
  • Versioned releases with SHA-256 checksums and GitHub build attestations