diff options
Diffstat (limited to 'PLUGINS.md')
| -rw-r--r-- | PLUGINS.md | 24 |
1 files changed, 16 insertions, 8 deletions
@@ -11,13 +11,16 @@ Go), and means a plugin can be developed and tested against the exact same socket the TUI is already using, with `mitmux` itself open in another terminal watching what happens in real time. -`plugins/authcheck` is a real, working reference implementation - an -Autorize-style authorization checker (resends a captured request with -its auth header stripped, tags the entry if the response still -succeeds) - written to only ever exercise what's documented on this -page, not any of mitmux's own internal Go packages, specifically so it -proves this protocol is sufficient on its own. Worth reading alongside -this document, or just copying as a starting point. +`plugins/authcheck` and `plugins/paramminer` are real, working +reference implementations - an Autorize-style authorization checker +(resends a captured request with its auth header stripped, tags the +entry if the response still succeeds) and a Param Miner-style hidden +parameter prober (probes a small wordlist of candidate query +parameters, tags the entry if any noticeably change the response) - +both written to only ever exercise what's documented on this page, not +any of mitmux's own internal Go packages, specifically so they prove +this protocol is sufficient on its own. Worth reading alongside this +document, or just copying as a starting point. ## Connecting @@ -65,7 +68,12 @@ handful of these: `scheme://host` exactly as given - no normalization, no header injection, no auto-fixed `Content-Length` - and records the exchange to history with `source: "repeater"`. This is what an Autorize- or - Param-Miner-style plugin uses to send its own probe requests. + Param-Miner-style plugin uses to send its own probe requests. Every + probe becomes its own history row - a plugin sending many probes per + entry (Param Miner's wordlist, say) will visibly fill the history + view with them. That's intentional (every resend is auditable, same + as a human using Repeater by hand), and `source:proxy` in search + filters them back out when they're just noise. - **`list`** / **`search`** - read existing history, same filters the TUI's own `/` search uses (`status:`, `source:`, `flagged:`, `tag:`, free text). Useful for a plugin that reconciles past traffic on |