diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 23 |
1 files changed, 21 insertions, 2 deletions
@@ -23,6 +23,9 @@ list of what's deliberately not implemented (and why), see independently on the client and upstream legs - a client that only speaks HTTP/1.1 and an origin that prefers HTTP/2 both work correctly in the same request. +- **WebSocket**: `ws://`/`wss://` connections are relayed byte-for-byte + unmodified with every frame captured for display, not just the + upgrade handshake - see WebSocket below. - **History**: every request/response captured to SQLite. Raw wire bytes are preserved byte-for-byte on HTTP/1.1 legs (what request smuggling and parser-differential analysis actually needs); HTTP/2 @@ -258,7 +261,22 @@ response (display-only - never touches the stored or resent bytes), `c` mark/compare (same as the history list), `r`/`i` jump straight to Repeater/Intruder seeded from this entry, `e` exports the entry (request and response, raw bytes, plain text - type a path and press -enter), `esc` back. +enter), `w` views captured WebSocket messages if this entry's +connection was upgraded (see WebSocket below), `esc` back. + +### WebSocket + +A `ws://` or `wss://` request that gets a matching `101 Switching +Protocols` back stops being one-shot request/response - mitmux relays +every frame byte-for-byte unmodified in both directions (this is +capture, not tampering) while decoding each one's payload for display. +Press `w` from an upgraded entry's detail view to see them: direction, +opcode (text/binary/close/ping/pong), size, and a preview; `enter` on +a row shows that frame's full decoded payload. One row per frame, not +per reassembled logical message - a message fragmented across several +frames (rare in real-world WebSocket traffic: JSON events, chat +messages, game state are almost always single-frame) shows up as +several rows rather than being stitched back together. ### Comparer @@ -571,7 +589,8 @@ reasoning behind each: 1000 requests per attack across all four modes - `mitmuxd -install-ca` prints per-OS trust-store install steps; it never runs them for you (see Quick start above for why) -- No WebSocket interception +- WebSocket messages are captured one row per frame, not reassembled + from fragments (rare in real-world traffic) - see WebSocket below - No active or passive vulnerability scanning, no plugin system - this is a manual-testing tool, not a scanner |