diff options
| author | srdusr <[email protected]> | 2024-01-16 16:26:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2024-01-16 16:26:00 +0200 |
| commit | 1125afc47b9d6e68d95d0ffdbb74514f4618e624 (patch) | |
| tree | 63d5150b7dbc74685ebaec35ee0e74ec30c721d5 /PLAN.md | |
| download | mitmux-1125afc47b9d6e68d95d0ffdbb74514f4618e624.tar.gz mitmux-1125afc47b9d6e68d95d0ffdbb74514f4618e624.zip | |
Scaffold mitmux: proxy daemon, CA generation, HTTP/CONNECT passthrough
Implements build-order step 1: headless proxy daemon (mitmuxd) with
plaintext HTTP passthrough and raw CONNECT tunneling, plus root CA
generation/persistence for later TLS interception. Verified live
against real HTTP and HTTPS requests through the proxy.
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 48 |
1 files changed, 48 insertions, 0 deletions
@@ -0,0 +1,48 @@ +# mitmux - Intercepting Proxy TUI (Burp/Caido replacement) + +## Overview +Daily-driver intercepting proxy for manual pentest work, terminal-based. +Prior art to read before writing code: Cruster (Rust, built on +hudsucker) - same problem, worth studying even though this build is Go. + +## Stack +- Language: Go - memory safety on hostile input matters here more than + in the other projects, since this parses attacker-adjacent traffic +- TLS interception: Go's own `crypto/tls` + a CA cert generator + (analogous to `rcgen`) for per-domain leaf certs +- Proxy core: `net/http` + manual `CONNECT` handling, or a MITM proxy + library if one fits without fighting Go's aggressive header + normalization +- Storage: SQLite in WAL mode - blob columns for raw request/response + bytes, FTS5 index for search across bodies +- UI: Bubble Tea + Lipgloss (TUI), same family as the packet analyzer's + Go sibling if that ever gets built + +## Architecture sketch (important - don't skip this) +- Split proxy engine from TUI. Headless daemon owns the listening + socket and the DB; TUI is a client over a Unix socket. The proxy + keeps running when the UI restarts, and a web UI or CLI scanner can + be bolted on later without touching the engine. +- Store raw bytes as the source of truth. Parse into a display view, + never re-serialize for storage - request smuggling, header injection, + and parser-differential bugs depend on the original malformed framing + surviving. For Repeater specifically, write requests as raw bytes + over the socket rather than through a normalizing HTTP client. + +## Build order +1. Proxy + CA cert generation + plaintext HTTP passthrough +2. TLS interception (per-host cert generation, install CA) +3. History view (SQLite storage, raw bytes preserved) in the TUI +4. Repeater (raw-byte send/resend, the feature used daily) +5. Search/filter (FTS5) +6. Match-and-replace rules +7. Intruder-equivalent (last, optional) + +## Open questions +- HTTP/2: handle natively (decided) - full fidelity over MITM'd + connections rather than downgrading to HTTP/1.1. Adds complexity to + CONNECT handling, stream framing, and step 3 storage (multiplexed + streams over one connection need per-stream request/response + boundaries, not just per-connection ones). +- CA install UX per OS (Linux/macOS/Windows trust stores) +- Whether WebSocket interception is v1 or a later addition |