srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md28
1 files changed, 24 insertions, 4 deletions
diff --git a/PLAN.md b/PLAN.md
index 2dac629..d874f69 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -124,10 +124,30 @@ the correct tab (send results carry the tab index they belong to), and
the status line/response pane it's shown in only updates live if that
tab is still the one on screen.
-Still open from "worth considering": Intruder payload processing
-(encoding/case rules) and grep-match/grep-extract on results, CA install
-UX per OS, multiple proxy listeners and upstream proxy chaining. None of
-these are started yet.
+Shipped since: Intruder payload processing and grep-match/grep-extract.
+Payload processing - an optional case rule (upper/lower) and an optional
+encode rule (URL/Base64/Hex/HTML), cycled with `c`/`e` - is applied
+client-side to each payload line before it ever crosses the IPC socket,
+case first then encode (encoding an already-case-folded value is safe;
+the reverse would corrupt e.g. Base64 padding), since it's a pure string
+transform with no proxy-side state involved and reuses the Decoder's own
+`urlEncodeAll`. Grep-match/grep-extract are optional Go regexps
+(`m`/`v` to edit, both gated to normal mode and both revert-on-esc /
+validate-on-enter the same way the history list's `/` search box
+works), evaluated server-side in `internal/ipc/server.go`'s "intrude"
+handler against each result's actual response bytes - chosen over a
+client-side implementation because the daemon already has `entry.
+ResponseRaw` in hand right where the result is built, and Burp's own
+grep options work the same way (matched against the real response, not
+a client-refetched copy). Grep-match flags a result (shown as a Match
+column); grep-extract captures the first submatch (or the whole match
+if the pattern has no capturing group) into an Extract column. Both are
+configured once before `ctrl+r` starts an attack and apply for that run
+only - matching Burp, which doesn't retroactively re-grep already-fired
+requests if you change the options mid-attack.
+
+Still open from "worth considering": CA install UX per OS, multiple
+proxy listeners and upstream proxy chaining. Neither is started yet.
Skipped deliberately (from the research, matches this tool's stated
scope): active/passive vulnerability scanning, plugin marketplace,