diff options
| author | srdusr <[email protected]> | 2026-06-11 00:37:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-06-11 00:37:00 +0200 |
| commit | 6114567258bcad0517a0d881168711aaacdba5d5 (patch) | |
| tree | 6bb9f3af9cfe0c857140a51f7992e3853cb2a236 /internal/proxy/repeat.go | |
| parent | a2362fc08c31b23fb971279f8b160555123ad2f6 (diff) | |
| download | mitmux-6114567258bcad0517a0d881168711aaacdba5d5.tar.gz mitmux-6114567258bcad0517a0d881168711aaacdba5d5.zip | |
Intruder: Battering ram, Pitchfork, and Cluster bomb attack modes
Generalizes Intrude beyond Sniper to all four of Burp's attack modes
(proxy.AttackMode). Sniper and Battering ram only ever need one shared
payload set; Pitchfork and Cluster bomb are inherently per-position, so
they take one payload set per §marked§ position instead.
Request-set generation (intrudeValues) is pure and side-effect free,
so the total request count is validated against the existing 1000
cap before anything is dispatched - Cluster bomb's product is checked
incrementally, one payload set at a time, so a pathological product
bails out before ever trying to enumerate it. This also makes the
combinatorics unit-testable without a live target.
IntrudeResultMsg now reports Values (one substitution per marked
position, in order) instead of a single Position/Payload pair, since
three of the four modes touch multiple positions per request.
TUI: `a` cycles the attack mode. Pitchfork/Cluster bomb reuse the
existing single Payloads pane rather than a new multi-widget editor -
sets are separated by a `---` delimiter line, in position order.
Verified live against a real daemon: all four modes produce the
expected substitution values and request counts, and pitchfork
correctly rejects a payload-set count that doesn't match the
template's marked positions.
Diffstat (limited to 'internal/proxy/repeat.go')
0 files changed, 0 insertions, 0 deletions