diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 19 |
1 files changed, 17 insertions, 2 deletions
@@ -123,8 +123,21 @@ go build -o bin/mitmux ./cmd/mitmux ``` Both binaries take flags for non-default setups - `-listen`, `-socket`, -`-ca-dir`, `-db` on `mitmuxd`; `-socket` on `mitmux`. Run either with -`-h` for the full list. +`-ca-dir`, `-db`, `-upstream-proxy` on `mitmuxd`; `-socket` on `mitmux`. +Run either with `-h` for the full list. + +`-listen` takes a comma-separated list to bind more than one address +(`-listen "127.0.0.1:8080,127.0.0.1:8081"`) - one logical proxy on +several ports/interfaces, sharing the same history, CA and rules. + +`-upstream-proxy host:port` chains every outbound connection through +another HTTP CONNECT proxy (Burp, a corporate proxy, anything that +speaks CONNECT) instead of dialing origins directly. Chaining into +another *intercepting* proxy needs that proxy's own CA trusted too - +it terminates and re-signs the connection with its own CA, which +mitmux's outbound TLS client has no reason to trust otherwise; you'll +see a clear certificate-verification error in history rather than a +silent failure. SOCKS5 upstreams aren't implemented. ## Usage @@ -330,5 +343,7 @@ reasoning behind each: never runs them for you (see Quick start above for why) - No WebSocket interception - No client (mutual-TLS) certificate support +- Upstream proxy chaining (`-upstream-proxy`) is HTTP CONNECT only, no + SOCKS5 - No active or passive vulnerability scanning, no plugin system - this is a manual-testing tool, not a scanner |