diff options
| author | srdusr <[email protected]> | 2026-08-28 09:42:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-08-28 09:42:00 +0200 |
| commit | 2ee4a95c9ccc701482c88f58840568738354dc36 (patch) | |
| tree | aa8800f9ccd1b2b58663795a508258b7cf4588c0 /PLUGINS.md | |
| parent | 8748df8a30b038e429aeeff1684e1014f42a68ee (diff) | |
| download | mitmux-2ee4a95c9ccc701482c88f58840568738354dc36.tar.gz mitmux-2ee4a95c9ccc701482c88f58840568738354dc36.zip | |
Fourth plugin: bpscanner, a Backslash Powered Scanner-style detector
- Phase 1 plugin ecosystem complete
The last of the four "cheap IPC win" plugins identified in the
original research pass. Different mechanism from the other three,
deliberately: where paramminer finds parameters that shouldn't exist,
bpscanner tests parameters that already do, asking a more general
question than a signature-based scanner does - does the backend treat
syntactically-significant characters ('"\<>(){}$;|&, covering SQL
quoting, HTML/JS, shell metacharacters, and template syntax at once)
differently than an equal-length string of inert filler? That question
doesn't need to know what the backend is built on, the whole appeal of
the real tool this borrows its name and idea from.
For each existing query parameter, sends two same-length replacement
values wrapped in a stable marker - one filler, one special-character
- and checks whether the marker itself came back intact, not just
whether the response looks different overall. An endpoint that never
reflects the parameter at all naturally produces "both intact: false,"
which correctly isn't a finding - the marker-reflection design avoids
false-positiving on the common case of a parameter that's read but
never echoed.
Verified live against a deliberately realistic scenario: an origin
with one endpoint that strips a few special characters before
reflecting a parameter (a naive-sanitizer/WAF-like pattern) and one
that reflects verbatim (the control case) - the sanitizing endpoint
was correctly tagged with the exact differential
(control_marker_intact: true, special_marker_intact: false), the
verbatim endpoint correctly left alone.
This closes Phase 1: every plugin identified as a "cheap IPC win" - no
new protocol capability needed beyond tag_entry itself - is now real,
working, and live-verified (authcheck, paramminer, jslibscan,
bpscanner).
Diffstat (limited to 'PLUGINS.md')
| -rw-r--r-- | PLUGINS.md | 22 |
1 files changed, 13 insertions, 9 deletions
@@ -11,15 +11,19 @@ Go), and means a plugin can be developed and tested against the exact same socket the TUI is already using, with `mitmux` itself open in another terminal watching what happens in real time. -`plugins/authcheck`, `plugins/paramminer`, and `plugins/jslibscan` are -real, working reference implementations - an Autorize-style -authorization checker (resends a captured request with its auth header -stripped, tags the entry if the response still succeeds), a Param -Miner-style hidden parameter prober (probes a small wordlist of -candidate query parameters, tags the entry if any noticeably change the -response), and a Retire.js-style passive scanner for known-vulnerable -JS library versions (reads response bodies already captured by ordinary -proxying, no probing at all) - all written to only ever exercise what's +`plugins/authcheck`, `plugins/paramminer`, `plugins/jslibscan`, and +`plugins/bpscanner` are real, working reference implementations - an +Autorize-style authorization checker (resends a captured request with +its auth header stripped, tags the entry if the response still +succeeds), a Param Miner-style hidden parameter prober (probes a small +wordlist of candidate query parameters, tags the entry if any noticeably +change the response), a Retire.js-style passive scanner for +known-vulnerable JS library versions (reads response bodies already +captured by ordinary proxying, no probing at all), and a Backslash +Powered Scanner-style generic injection detector (mutates each existing +query parameter's value with syntactically-significant characters vs. an +equal-length inert control, tags the entry if a stable marker survives +one but not the other) - all written to only ever exercise what's documented on this page, not any of mitmux's own internal Go packages, specifically so they prove this protocol is sufficient on its own. Worth reading alongside this document, or just copying as a starting |