diff options
| author | srdusr <[email protected]> | 2026-05-22 21:47:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-05-22 21:47:00 +0200 |
| commit | d522b1177a9e1fdd04888121975f2b3509d19564 (patch) | |
| tree | 8f4a8acb9ce73ba7d656cdb5c05c26002e3a028c /internal/ipc | |
| parent | 51811b67018515366bd56f3c3b21aed11d906db2 (diff) | |
| download | mitmux-d522b1177a9e1fdd04888121975f2b3509d19564.tar.gz mitmux-d522b1177a9e1fdd04888121975f2b3509d19564.zip | |
CSV export and copy-as-curl (multiple export formats, like Burp)
Both extend the existing export system by dispatching on the file
extension the user types, rather than adding a separate format-
selection control - consistent with how any "save as" dialog already
works, and requires no new UI beyond what export already has.
Bulk export ('E' from the history list): .har (existing default) or
.csv. CSV is a summary table (id/method/host/path/status/sizes/timing/
flag/source) built directly from the already-loaded Summary rows -
deliberately lighter and faster than HAR, which needs a per-entry fetch
from the daemon to get raw bytes. This mirrors Burp's own "export as
CSV" being a listing for a report/spreadsheet, not a full-fidelity
capture format - HAR already covers that need.
Single-entry export ('e' from Detail view): .txt (existing default,
unchanged) or .sh/.curl - the request re-serialized as a runnable curl
command line (Burp/DevTools' "copy as curl"), for handing to someone
else or re-running standalone without mitmux. Every value is shell-
quoted (single-quote wrapping with '\'' escaping for embedded quotes) -
a captured or edited request is exactly the kind of content that might
contain shell metacharacters, so naive string concatenation would risk
producing a command that does something other than what it appears to
when pasted into a shell. Verified by actually executing a generated
command against the real target and confirming the response matched
the original request.
CSV export needed one thing HAR didn't: a guard against CSV/formula
injection. Method, host, path, and error all ultimately trace back to a
request line or Host header - content this tool exists specifically to
inspect from potentially hostile traffic - and a field starting with
=, +, -, @, tab, or CR is a formula to Excel/LibreOffice/Sheets when the
exported file is later opened, which can call out to other cells,
external data, or worse depending on the app and its settings. csvSafe
prefixes any such field with a single quote before writing - the
standard mitigation per OWASP's own CSV injection guidance - so every
affected spreadsheet application treats it as literal text instead.
This is the same class of bug as the terminal-injection fix from the
earlier robustness audit, just for a different output format: captured
content controlling whatever later processes it, rather than the
terminal that renders it.
cmd/mitmux/csv.go: csvFromSummaries + csvSafe, unit tested including the
formula-injection neutralization specifically. cmd/mitmux/export.go:
curlCommand + shellQuote, plus singleEntryFormat/bulkExportFormat
extension-dispatch helpers, all unit tested (curl generation, malformed-
request handling, shell-quote escaping of embedded quotes).
go build/vet/gofmt/test/mod tidy all clean.
Diffstat (limited to 'internal/ipc')
0 files changed, 0 insertions, 0 deletions