diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 30 |
1 files changed, 24 insertions, 6 deletions
@@ -49,11 +49,14 @@ list of what's deliberately not implemented (and why), see sent) and grep-match/grep-extract (flag or pull text out of each result's response with a regexp) are both configurable before starting an attack - see [Intruder](#intruder) below. -- **Match-and-replace**: header rewrite rules (add, remove, or modify) - for requests and/or responses, applied live as traffic passes - through. History still shows what was actually sent/received on each - side - match-and-replace transforms the wire, it doesn't rewrite the - audit trail. +- **Match-and-replace**: header or body rewrite rules (add, remove, or + modify) for requests and/or responses, applied live as traffic + passes through. History still shows what was actually sent/received + on each side - match-and-replace transforms the wire, it doesn't + rewrite the audit trail. +- **Client certificates**: configure a mutual-TLS cert/key per host + pattern, presented automatically on matching handshakes - for + proxied traffic and Repeater/Intruder resends alike. - **Flagging**: mark an entry to revisit later (★), filterable via `flagged:true`. - **Comparer**: mark one entry (`c`), then `c` on a different entry to @@ -442,6 +445,22 @@ Repeater and Intruder always record regardless of scope - a request you deliberately resend or fuzz is something you clearly want to see the result of, not noise scope exists to cut. +### Client (mutual-TLS) certificates + +Press `t` from the history view to manage which client certificate +mitmux presents when an upstream server's TLS handshake requests one +- a target requiring mutual TLS otherwise fails the handshake before +any request/response ever happens. `a` adds one: a name, a host +pattern (same substring-or-regex model as scope and match-and-replace +rules), and paths to a PEM certificate file and its matching PEM +private key. The files are read once, at save time, and their content +- not the paths - is what's stored and later presented, so a cert +keeps working even if the original file moves or is deleted +afterward. `space` toggles one on/off, `d` deletes it. Applies to +proxied HTTPS traffic and to Repeater/Intruder resends against +`https://` targets alike; a host matching no configured certificate +just handshakes without one, same as if this feature didn't exist. + ### Mouse This is a real terminal application (any terminal, not just tmux - the @@ -538,7 +557,6 @@ reasoning behind each: - `mitmuxd -install-ca` prints per-OS trust-store install steps; it never runs them for you (see Quick start above for why) - No WebSocket interception -- No client (mutual-TLS) certificate support - Upstream proxy chaining (`-upstream-proxy`) is HTTP CONNECT only, no SOCKS5 - No active or passive vulnerability scanning, no plugin system - this |