srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLUGINS.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLUGINS.md')
-rw-r--r--PLUGINS.md24
1 files changed, 16 insertions, 8 deletions
diff --git a/PLUGINS.md b/PLUGINS.md
index 630f211..d6c0ee9 100644
--- a/PLUGINS.md
+++ b/PLUGINS.md
@@ -11,13 +11,16 @@ Go), and means a plugin can be developed and tested against the exact
same socket the TUI is already using, with `mitmux` itself open in
another terminal watching what happens in real time.
-`plugins/authcheck` is a real, working reference implementation - an
-Autorize-style authorization checker (resends a captured request with
-its auth header stripped, tags the entry if the response still
-succeeds) - written to only ever exercise what's documented on this
-page, not any of mitmux's own internal Go packages, specifically so it
-proves this protocol is sufficient on its own. Worth reading alongside
-this document, or just copying as a starting point.
+`plugins/authcheck` and `plugins/paramminer` are real, working
+reference implementations - an Autorize-style authorization checker
+(resends a captured request with its auth header stripped, tags the
+entry if the response still succeeds) and a Param Miner-style hidden
+parameter prober (probes a small wordlist of candidate query
+parameters, tags the entry if any noticeably change the response) -
+both written to only ever exercise what's documented on this page, not
+any of mitmux's own internal Go packages, specifically so they prove
+this protocol is sufficient on its own. Worth reading alongside this
+document, or just copying as a starting point.
## Connecting
@@ -65,7 +68,12 @@ handful of these:
`scheme://host` exactly as given - no normalization, no header
injection, no auto-fixed `Content-Length` - and records the exchange
to history with `source: "repeater"`. This is what an Autorize- or
- Param-Miner-style plugin uses to send its own probe requests.
+ Param-Miner-style plugin uses to send its own probe requests. Every
+ probe becomes its own history row - a plugin sending many probes per
+ entry (Param Miner's wordlist, say) will visibly fill the history
+ view with them. That's intentional (every resend is auditable, same
+ as a human using Repeater by hand), and `source:proxy` in search
+ filters them back out when they're just noise.
- **`list`** / **`search`** - read existing history, same filters the
TUI's own `/` search uses (`status:`, `source:`, `flagged:`, `tag:`,
free text). Useful for a plugin that reconciles past traffic on