srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md19
1 files changed, 17 insertions, 2 deletions
diff --git a/README.md b/README.md
index f65e3fe..b880fc3 100644
--- a/README.md
+++ b/README.md
@@ -123,8 +123,21 @@ go build -o bin/mitmux ./cmd/mitmux
```
Both binaries take flags for non-default setups - `-listen`, `-socket`,
-`-ca-dir`, `-db` on `mitmuxd`; `-socket` on `mitmux`. Run either with
-`-h` for the full list.
+`-ca-dir`, `-db`, `-upstream-proxy` on `mitmuxd`; `-socket` on `mitmux`.
+Run either with `-h` for the full list.
+
+`-listen` takes a comma-separated list to bind more than one address
+(`-listen "127.0.0.1:8080,127.0.0.1:8081"`) - one logical proxy on
+several ports/interfaces, sharing the same history, CA and rules.
+
+`-upstream-proxy host:port` chains every outbound connection through
+another HTTP CONNECT proxy (Burp, a corporate proxy, anything that
+speaks CONNECT) instead of dialing origins directly. Chaining into
+another *intercepting* proxy needs that proxy's own CA trusted too -
+it terminates and re-signs the connection with its own CA, which
+mitmux's outbound TLS client has no reason to trust otherwise; you'll
+see a clear certificate-verification error in history rather than a
+silent failure. SOCKS5 upstreams aren't implemented.
## Usage
@@ -330,5 +343,7 @@ reasoning behind each:
never runs them for you (see Quick start above for why)
- No WebSocket interception
- No client (mutual-TLS) certificate support
+- Upstream proxy chaining (`-upstream-proxy`) is HTTP CONNECT only, no
+ SOCKS5
- No active or passive vulnerability scanning, no plugin system - this
is a manual-testing tool, not a scanner