srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLUGINS.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLUGINS.md')
-rw-r--r--PLUGINS.md25
1 files changed, 15 insertions, 10 deletions
diff --git a/PLUGINS.md b/PLUGINS.md
index d6c0ee9..69961d3 100644
--- a/PLUGINS.md
+++ b/PLUGINS.md
@@ -11,16 +11,21 @@ Go), and means a plugin can be developed and tested against the exact
same socket the TUI is already using, with `mitmux` itself open in
another terminal watching what happens in real time.
-`plugins/authcheck` and `plugins/paramminer` are real, working
-reference implementations - an Autorize-style authorization checker
-(resends a captured request with its auth header stripped, tags the
-entry if the response still succeeds) and a Param Miner-style hidden
-parameter prober (probes a small wordlist of candidate query
-parameters, tags the entry if any noticeably change the response) -
-both written to only ever exercise what's documented on this page, not
-any of mitmux's own internal Go packages, specifically so they prove
-this protocol is sufficient on its own. Worth reading alongside this
-document, or just copying as a starting point.
+`plugins/authcheck`, `plugins/paramminer`, and `plugins/jslibscan` are
+real, working reference implementations - an Autorize-style
+authorization checker (resends a captured request with its auth header
+stripped, tags the entry if the response still succeeds), a Param
+Miner-style hidden parameter prober (probes a small wordlist of
+candidate query parameters, tags the entry if any noticeably change the
+response), and a Retire.js-style passive scanner for known-vulnerable
+JS library versions (reads response bodies already captured by ordinary
+proxying, no probing at all) - all written to only ever exercise what's
+documented on this page, not any of mitmux's own internal Go packages,
+specifically so they prove this protocol is sufficient on its own.
+Worth reading alongside this document, or just copying as a starting
+point. `jslibscan` in particular is the simplest possible plugin shape
+- subscribe, inspect, tag, nothing else - worth starting from if a
+plugin idea doesn't need to send any traffic of its own.
## Connecting