diff options
| author | srdusr <[email protected]> | 2026-02-03 00:38:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-02-03 00:38:00 +0200 |
| commit | ce6ce32469da720105258cb66e0274b2b009cd1d (patch) | |
| tree | bf1766efcdb323755e5cf3128a74b137eeb34b88 /internal/proxy/intrude_test.go | |
| parent | c2443f27ef5a844f045c038c7689d217d1dbf0c4 (diff) | |
| download | mitmux-ce6ce32469da720105258cb66e0274b2b009cd1d.tar.gz mitmux-ce6ce32469da720105258cb66e0274b2b009cd1d.zip | |
Intruder-equivalent: Sniper attacks with § markers
Implements build-order step 7, the last (optional) item. Scoped to
Sniper only - one payload set, one §-marked position fuzzed at a time,
others held at their base value - since that covers most real Intruder
usage; battering ram / pitchfork / cluster bomb aren't implemented.
Sequential sending, capped at 1000 generated requests as a fixed safety
limit.
internal/proxy: repeat.go's Repeat() is refactored into a shared
sendRaw(..., source) primitive so Intrude can reuse the exact same
raw-byte send/record path with source="intruder" instead of
duplicating it. intrude.go adds ParseMarkers/buildRequest (marker
parsing and payload substitution, covered by intrude_test.go - this is
fiddly byte-splicing logic, worth locking down with real tests rather
than trusting it by inspection) and Intrude(), which walks positions ×
payloads calling sendRaw and streaming each result through a callback.
internal/ipc gains a dedicated streaming "intrude" connection (same
shape as Subscribe, but blocking sends rather than drop-on-slow-
consumer - each result is the attack's actual data, not a
notification). cmd/mitmux gains an Intruder view: editable request
template (ctrl+p inserts a § marker at the cursor - typing § directly
also works, ctrl+p just doesn't require a keyboard layout that can
produce it), editable payload list, and a live results table wired to
the existing detail view (selecting a row and hitting enter opens the
full request/response for that specific attack request).
Verified live against real external traffic: a Sniper attack against
httpbin.org/status/§200§ with payloads 200/404/500 produced exactly the
three corresponding real status codes back (not a canned/local result),
confirmed the three requests landed in history tagged source="intruder"
with the § markers correctly stripped from what was actually sent, and
confirmed opening a result row's full detail from the results table.
This closes out the full build order from PLAN.md (steps 1-7).
Diffstat (limited to 'internal/proxy/intrude_test.go')
| -rw-r--r-- | internal/proxy/intrude_test.go | 116 |
1 files changed, 116 insertions, 0 deletions
diff --git a/internal/proxy/intrude_test.go b/internal/proxy/intrude_test.go new file mode 100644 index 0000000..5df80e6 --- /dev/null +++ b/internal/proxy/intrude_test.go @@ -0,0 +1,116 @@ +package proxy + +import ( + "reflect" + "testing" +) + +func TestParseMarkers(t *testing.T) { + tests := []struct { + name string + template string + wantPos []IntrudePosition + wantOut string + wantErr bool + }{ + { + name: "single position", + template: "GET /users/§123§ HTTP/1.1", + wantPos: []IntrudePosition{{Index: 0, Base: "123"}}, + wantOut: "GET /users/123 HTTP/1.1", + }, + { + name: "two positions", + template: "GET /a/§1§/b/§2§ HTTP/1.1", + wantPos: []IntrudePosition{{Index: 0, Base: "1"}, {Index: 1, Base: "2"}}, + wantOut: "GET /a/1/b/2 HTTP/1.1", + }, + { + name: "no markers", + template: "GET / HTTP/1.1", + wantPos: nil, + wantOut: "GET / HTTP/1.1", + }, + { + name: "empty marker", + template: "GET /§§ HTTP/1.1", + wantPos: []IntrudePosition{{Index: 0, Base: ""}}, + wantOut: "GET / HTTP/1.1", + }, + { + name: "unterminated marker", + template: "GET /§broken HTTP/1.1", + wantErr: true, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + pos, out, err := ParseMarkers([]byte(tt.template)) + if tt.wantErr { + if err == nil { + t.Fatalf("expected error, got nil") + } + return + } + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + if !reflect.DeepEqual(pos, tt.wantPos) { + t.Errorf("positions = %+v, want %+v", pos, tt.wantPos) + } + if string(out) != tt.wantOut { + t.Errorf("stripped = %q, want %q", out, tt.wantOut) + } + }) + } +} + +func TestBuildRequest(t *testing.T) { + template := "GET /a/§1§/b/§2§/c/§3§ HTTP/1.1" + + tests := []struct { + active int + payload string + want string + }{ + {0, "PAYLOAD", "GET /a/PAYLOAD/b/2/c/3 HTTP/1.1"}, + {1, "PAYLOAD", "GET /a/1/b/PAYLOAD/c/3 HTTP/1.1"}, + {2, "PAYLOAD", "GET /a/1/b/2/c/PAYLOAD HTTP/1.1"}, + } + + for _, tt := range tests { + got, err := buildRequest([]byte(template), tt.active, tt.payload) + if err != nil { + t.Fatalf("active=%d: unexpected error: %v", tt.active, err) + } + if string(got) != tt.want { + t.Errorf("active=%d: got %q, want %q", tt.active, got, tt.want) + } + } +} + +func TestBuildRequestPayloadContainingMarkerChar(t *testing.T) { + // A payload that itself contains the marker character must not be + // reinterpreted as a marker on a later buildRequest call - each call + // re-splits the ORIGINAL template, not the previously built request. + template := "GET /§1§/§2§ HTTP/1.1" + got, err := buildRequest([]byte(template), 0, "§injected§") + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + want := "GET /§injected§/2 HTTP/1.1" + if string(got) != want { + t.Errorf("got %q, want %q", got, want) + } +} + +func TestIntrudeRequestCount(t *testing.T) { + positions, _, err := ParseMarkers([]byte("GET /§a§/§b§ HTTP/1.1")) + if err != nil { + t.Fatal(err) + } + if len(positions) != 2 { + t.Fatalf("expected 2 positions, got %d", len(positions)) + } +} |