srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md16
1 files changed, 9 insertions, 7 deletions
diff --git a/README.md b/README.md
index 13e9429..ea2a885 100644
--- a/README.md
+++ b/README.md
@@ -396,12 +396,15 @@ matching Burp's own behavior.
### Match-and-replace rules
Press `m` from the history view. Rules match request or response
-headers (`a` add, `enter`/`e` edit, `d` delete, `space` toggle
-enabled). Matching is literal-substring by default, or regex if the
-rule's Regex toggle is on. Rules operate on the raw header *block* as
-text, not per-value substitution, so a rule can add or remove a header
-entirely, not just rewrite an existing one. Currently headers only -
-see `PLAN.md` for why body rules are a separate, harder problem.
+headers or bodies (`a` add, `enter`/`e` edit, `d` delete, `space`
+toggle enabled, Part field to choose header vs body). Matching is
+literal-substring by default, or regex if the rule's Regex toggle is
+on. Header rules operate on the raw header *block* as text, not
+per-value substitution, so a rule can add or remove a header entirely,
+not just rewrite an existing one. Body rules run directly against the
+raw body bytes; a body larger than the capture cap is left unmodified
+rather than partially rewritten, and Content-Length is recomputed
+automatically when a body rule changes a body's length.
### Scope
@@ -515,7 +518,6 @@ messages for what was checked and how.
Deliberate scope decisions, not oversights - see `PLAN.md` for the
reasoning behind each:
-- Match-and-replace: headers only, no body rules yet
- Intruder: Sniper attack only (no battering ram / pitchfork / cluster
bomb), sequential sending, capped at 1000 requests per attack
- `mitmuxd -install-ca` prints per-OS trust-store install steps; it