srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/plugins/jslibscan
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-08-26 01:06:00 +0200
committersrdusr <[email protected]>2026-08-26 01:06:00 +0200
commitcfe01fef65af082dccfc69b2fc78cb07a36ac2b4 (patch)
treeefc0b0468a0f43bd9c2f3f061c2a6a0b71d021ab /plugins/jslibscan
parent9e94bcbc939afd38b45f9ef42e1b1666fafd8d45 (diff)
downloadmitmux-cfe01fef65af082dccfc69b2fc78cb07a36ac2b4.tar.gz
mitmux-cfe01fef65af082dccfc69b2fc78cb07a36ac2b4.zip
Second plugin: paramminer, a Param Miner-style hidden parameter prober
For every distinct GET endpoint (deduplicated in-memory so revisiting a URL doesn't rerun the whole wordlist each time), sends a fresh baseline resend plus one probe per candidate from a ~40-entry wordlist of parameter names real backends surprisingly often read even when never part of any observed request (debug, admin, redirect, role, token, and similar). A probe whose response differs from baseline by more than a small threshold (body length, or a different status outright) is a likely hit, tagged paramminer:hit with the parameter name and both response sizes as evidence. Deliberately GET-only with a modest wordlist, not exhaustive POST/JSON-aware probing - same "small honest v1" reasoning as authcheck's single-identity simplification. Same discipline as authcheck: speaks the wire protocol directly, no internal/ipc import, proving PLUGINS.md's documented protocol is actually sufficient on its own. Found and documented two real, non-obvious net/http behaviors while building this: Request.Write ignores the RequestURI field entirely (confirmed directly - a deliberately stale RequestURI still produced the correct output, since Write derives the request line from Request.URL instead) and silently adds a default User-Agent header if the cloned request didn't already have one. Neither affects correctness here since baseline and every probe get identical treatment, but both are worth knowing before reusing this resend pattern elsewhere. Verified live end to end: a real daemon, a real Python origin with a genuinely hidden debug parameter that substantially changes the response, and a control endpoint that's stable regardless of any extra parameter - the hidden-parameter endpoint was correctly tagged with exactly the right parameter name, the stable one correctly left alone, confirmed via tag: search and visually in the TUI with the JSON-array tag payload rendering correctly.
Diffstat (limited to 'plugins/jslibscan')
0 files changed, 0 insertions, 0 deletions