srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/proxy/intrude_test.go
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-02-03 00:38:00 +0200
committersrdusr <[email protected]>2026-02-03 00:38:00 +0200
commitce6ce32469da720105258cb66e0274b2b009cd1d (patch)
treebf1766efcdb323755e5cf3128a74b137eeb34b88 /internal/proxy/intrude_test.go
parentc2443f27ef5a844f045c038c7689d217d1dbf0c4 (diff)
downloadmitmux-ce6ce32469da720105258cb66e0274b2b009cd1d.tar.gz
mitmux-ce6ce32469da720105258cb66e0274b2b009cd1d.zip
Intruder-equivalent: Sniper attacks with § markers
Implements build-order step 7, the last (optional) item. Scoped to Sniper only - one payload set, one §-marked position fuzzed at a time, others held at their base value - since that covers most real Intruder usage; battering ram / pitchfork / cluster bomb aren't implemented. Sequential sending, capped at 1000 generated requests as a fixed safety limit. internal/proxy: repeat.go's Repeat() is refactored into a shared sendRaw(..., source) primitive so Intrude can reuse the exact same raw-byte send/record path with source="intruder" instead of duplicating it. intrude.go adds ParseMarkers/buildRequest (marker parsing and payload substitution, covered by intrude_test.go - this is fiddly byte-splicing logic, worth locking down with real tests rather than trusting it by inspection) and Intrude(), which walks positions × payloads calling sendRaw and streaming each result through a callback. internal/ipc gains a dedicated streaming "intrude" connection (same shape as Subscribe, but blocking sends rather than drop-on-slow- consumer - each result is the attack's actual data, not a notification). cmd/mitmux gains an Intruder view: editable request template (ctrl+p inserts a § marker at the cursor - typing § directly also works, ctrl+p just doesn't require a keyboard layout that can produce it), editable payload list, and a live results table wired to the existing detail view (selecting a row and hitting enter opens the full request/response for that specific attack request). Verified live against real external traffic: a Sniper attack against httpbin.org/status/§200§ with payloads 200/404/500 produced exactly the three corresponding real status codes back (not a canned/local result), confirmed the three requests landed in history tagged source="intruder" with the § markers correctly stripped from what was actually sent, and confirmed opening a result row's full detail from the results table. This closes out the full build order from PLAN.md (steps 1-7).
Diffstat (limited to 'internal/proxy/intrude_test.go')
-rw-r--r--internal/proxy/intrude_test.go116
1 files changed, 116 insertions, 0 deletions
diff --git a/internal/proxy/intrude_test.go b/internal/proxy/intrude_test.go
new file mode 100644
index 0000000..5df80e6
--- /dev/null
+++ b/internal/proxy/intrude_test.go
@@ -0,0 +1,116 @@
+package proxy
+
+import (
+ "reflect"
+ "testing"
+)
+
+func TestParseMarkers(t *testing.T) {
+ tests := []struct {
+ name string
+ template string
+ wantPos []IntrudePosition
+ wantOut string
+ wantErr bool
+ }{
+ {
+ name: "single position",
+ template: "GET /users/§123§ HTTP/1.1",
+ wantPos: []IntrudePosition{{Index: 0, Base: "123"}},
+ wantOut: "GET /users/123 HTTP/1.1",
+ },
+ {
+ name: "two positions",
+ template: "GET /a/§1§/b/§2§ HTTP/1.1",
+ wantPos: []IntrudePosition{{Index: 0, Base: "1"}, {Index: 1, Base: "2"}},
+ wantOut: "GET /a/1/b/2 HTTP/1.1",
+ },
+ {
+ name: "no markers",
+ template: "GET / HTTP/1.1",
+ wantPos: nil,
+ wantOut: "GET / HTTP/1.1",
+ },
+ {
+ name: "empty marker",
+ template: "GET /§§ HTTP/1.1",
+ wantPos: []IntrudePosition{{Index: 0, Base: ""}},
+ wantOut: "GET / HTTP/1.1",
+ },
+ {
+ name: "unterminated marker",
+ template: "GET /§broken HTTP/1.1",
+ wantErr: true,
+ },
+ }
+
+ for _, tt := range tests {
+ t.Run(tt.name, func(t *testing.T) {
+ pos, out, err := ParseMarkers([]byte(tt.template))
+ if tt.wantErr {
+ if err == nil {
+ t.Fatalf("expected error, got nil")
+ }
+ return
+ }
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ if !reflect.DeepEqual(pos, tt.wantPos) {
+ t.Errorf("positions = %+v, want %+v", pos, tt.wantPos)
+ }
+ if string(out) != tt.wantOut {
+ t.Errorf("stripped = %q, want %q", out, tt.wantOut)
+ }
+ })
+ }
+}
+
+func TestBuildRequest(t *testing.T) {
+ template := "GET /a/§1§/b/§2§/c/§3§ HTTP/1.1"
+
+ tests := []struct {
+ active int
+ payload string
+ want string
+ }{
+ {0, "PAYLOAD", "GET /a/PAYLOAD/b/2/c/3 HTTP/1.1"},
+ {1, "PAYLOAD", "GET /a/1/b/PAYLOAD/c/3 HTTP/1.1"},
+ {2, "PAYLOAD", "GET /a/1/b/2/c/PAYLOAD HTTP/1.1"},
+ }
+
+ for _, tt := range tests {
+ got, err := buildRequest([]byte(template), tt.active, tt.payload)
+ if err != nil {
+ t.Fatalf("active=%d: unexpected error: %v", tt.active, err)
+ }
+ if string(got) != tt.want {
+ t.Errorf("active=%d: got %q, want %q", tt.active, got, tt.want)
+ }
+ }
+}
+
+func TestBuildRequestPayloadContainingMarkerChar(t *testing.T) {
+ // A payload that itself contains the marker character must not be
+ // reinterpreted as a marker on a later buildRequest call - each call
+ // re-splits the ORIGINAL template, not the previously built request.
+ template := "GET /§1§/§2§ HTTP/1.1"
+ got, err := buildRequest([]byte(template), 0, "§injected§")
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ want := "GET /§injected§/2 HTTP/1.1"
+ if string(got) != want {
+ t.Errorf("got %q, want %q", got, want)
+ }
+}
+
+func TestIntrudeRequestCount(t *testing.T) {
+ positions, _, err := ParseMarkers([]byte("GET /§a§/§b§ HTTP/1.1"))
+ if err != nil {
+ t.Fatal(err)
+ }
+ if len(positions) != 2 {
+ t.Fatalf("expected 2 positions, got %d", len(positions))
+ }
+}