diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 28 |
1 files changed, 24 insertions, 4 deletions
@@ -124,10 +124,30 @@ the correct tab (send results carry the tab index they belong to), and the status line/response pane it's shown in only updates live if that tab is still the one on screen. -Still open from "worth considering": Intruder payload processing -(encoding/case rules) and grep-match/grep-extract on results, CA install -UX per OS, multiple proxy listeners and upstream proxy chaining. None of -these are started yet. +Shipped since: Intruder payload processing and grep-match/grep-extract. +Payload processing - an optional case rule (upper/lower) and an optional +encode rule (URL/Base64/Hex/HTML), cycled with `c`/`e` - is applied +client-side to each payload line before it ever crosses the IPC socket, +case first then encode (encoding an already-case-folded value is safe; +the reverse would corrupt e.g. Base64 padding), since it's a pure string +transform with no proxy-side state involved and reuses the Decoder's own +`urlEncodeAll`. Grep-match/grep-extract are optional Go regexps +(`m`/`v` to edit, both gated to normal mode and both revert-on-esc / +validate-on-enter the same way the history list's `/` search box +works), evaluated server-side in `internal/ipc/server.go`'s "intrude" +handler against each result's actual response bytes - chosen over a +client-side implementation because the daemon already has `entry. +ResponseRaw` in hand right where the result is built, and Burp's own +grep options work the same way (matched against the real response, not +a client-refetched copy). Grep-match flags a result (shown as a Match +column); grep-extract captures the first submatch (or the whole match +if the pattern has no capturing group) into an Extract column. Both are +configured once before `ctrl+r` starts an attack and apply for that run +only - matching Burp, which doesn't retroactively re-grep already-fired +requests if you change the options mid-attack. + +Still open from "worth considering": CA install UX per OS, multiple +proxy listeners and upstream proxy chaining. Neither is started yet. Skipped deliberately (from the research, matches this tool's stated scope): active/passive vulnerability scanning, plugin marketplace, |