srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-08-26 01:06:00 +0200
committersrdusr <[email protected]>2026-08-26 01:06:00 +0200
commitcfe01fef65af082dccfc69b2fc78cb07a36ac2b4 (patch)
treeefc0b0468a0f43bd9c2f3f061c2a6a0b71d021ab /README.md
parent9e94bcbc939afd38b45f9ef42e1b1666fafd8d45 (diff)
downloadmitmux-cfe01fef65af082dccfc69b2fc78cb07a36ac2b4.tar.gz
mitmux-cfe01fef65af082dccfc69b2fc78cb07a36ac2b4.zip
Second plugin: paramminer, a Param Miner-style hidden parameter prober
For every distinct GET endpoint (deduplicated in-memory so revisiting a URL doesn't rerun the whole wordlist each time), sends a fresh baseline resend plus one probe per candidate from a ~40-entry wordlist of parameter names real backends surprisingly often read even when never part of any observed request (debug, admin, redirect, role, token, and similar). A probe whose response differs from baseline by more than a small threshold (body length, or a different status outright) is a likely hit, tagged paramminer:hit with the parameter name and both response sizes as evidence. Deliberately GET-only with a modest wordlist, not exhaustive POST/JSON-aware probing - same "small honest v1" reasoning as authcheck's single-identity simplification. Same discipline as authcheck: speaks the wire protocol directly, no internal/ipc import, proving PLUGINS.md's documented protocol is actually sufficient on its own. Found and documented two real, non-obvious net/http behaviors while building this: Request.Write ignores the RequestURI field entirely (confirmed directly - a deliberately stale RequestURI still produced the correct output, since Write derives the request line from Request.URL instead) and silently adds a default User-Agent header if the cloned request didn't already have one. Neither affects correctness here since baseline and every probe get identical treatment, but both are worth knowing before reusing this resend pattern elsewhere. Verified live end to end: a real daemon, a real Python origin with a genuinely hidden debug parameter that substantially changes the response, and a control endpoint that's stable regardless of any extra parameter - the hidden-parameter endpoint was correctly tagged with exactly the right parameter name, the stable one correctly left alone, confirmed via tag: search and visually in the TUI with the JSON-array tag payload rendering correctly.
Diffstat (limited to 'README.md')
-rw-r--r--README.md5
1 files changed, 3 insertions, 2 deletions
diff --git a/README.md b/README.md
index 4eace20..b23ba4e 100644
--- a/README.md
+++ b/README.md
@@ -70,8 +70,9 @@ the same socket the TUI itself uses - see [`PLUGINS.md`](PLUGINS.md).
a badge in the history list, searchable via `tag:name`, viewable
(`T` from detail view) with JSON data syntax-highlighted the same way
a pretty-printed response is. See [`PLUGINS.md`](PLUGINS.md) and
- `plugins/authcheck` for a real, working one (an Autorize-style
- authorization checker).
+ `plugins/authcheck`/`plugins/paramminer` for real, working ones (an
+ Autorize-style authorization checker, a Param Miner-style hidden
+ parameter prober).
- **Comparer**: mark one entry (`c`), then `c` on a different entry to
see a colored unified diff of either side's request or response.
- **Decoder**: standalone URL/Base64/Hex/HTML encode and decode (`d`),