srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md30
1 files changed, 24 insertions, 6 deletions
diff --git a/README.md b/README.md
index 4d424e6..b1237f6 100644
--- a/README.md
+++ b/README.md
@@ -49,11 +49,14 @@ list of what's deliberately not implemented (and why), see
sent) and grep-match/grep-extract (flag or pull text out of each
result's response with a regexp) are both configurable before starting
an attack - see [Intruder](#intruder) below.
-- **Match-and-replace**: header rewrite rules (add, remove, or modify)
- for requests and/or responses, applied live as traffic passes
- through. History still shows what was actually sent/received on each
- side - match-and-replace transforms the wire, it doesn't rewrite the
- audit trail.
+- **Match-and-replace**: header or body rewrite rules (add, remove, or
+ modify) for requests and/or responses, applied live as traffic
+ passes through. History still shows what was actually sent/received
+ on each side - match-and-replace transforms the wire, it doesn't
+ rewrite the audit trail.
+- **Client certificates**: configure a mutual-TLS cert/key per host
+ pattern, presented automatically on matching handshakes - for
+ proxied traffic and Repeater/Intruder resends alike.
- **Flagging**: mark an entry to revisit later (★), filterable via
`flagged:true`.
- **Comparer**: mark one entry (`c`), then `c` on a different entry to
@@ -442,6 +445,22 @@ Repeater and Intruder always record regardless of scope - a request you
deliberately resend or fuzz is something you clearly want to see the
result of, not noise scope exists to cut.
+### Client (mutual-TLS) certificates
+
+Press `t` from the history view to manage which client certificate
+mitmux presents when an upstream server's TLS handshake requests one
+- a target requiring mutual TLS otherwise fails the handshake before
+any request/response ever happens. `a` adds one: a name, a host
+pattern (same substring-or-regex model as scope and match-and-replace
+rules), and paths to a PEM certificate file and its matching PEM
+private key. The files are read once, at save time, and their content
+- not the paths - is what's stored and later presented, so a cert
+keeps working even if the original file moves or is deleted
+afterward. `space` toggles one on/off, `d` deletes it. Applies to
+proxied HTTPS traffic and to Repeater/Intruder resends against
+`https://` targets alike; a host matching no configured certificate
+just handshakes without one, same as if this feature didn't exist.
+
### Mouse
This is a real terminal application (any terminal, not just tmux - the
@@ -538,7 +557,6 @@ reasoning behind each:
- `mitmuxd -install-ca` prints per-OS trust-store install steps; it
never runs them for you (see Quick start above for why)
- No WebSocket interception
-- No client (mutual-TLS) certificate support
- Upstream proxy chaining (`-upstream-proxy`) is HTTP CONNECT only, no
SOCKS5
- No active or passive vulnerability scanning, no plugin system - this