srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md45
1 files changed, 31 insertions, 14 deletions
diff --git a/README.md b/README.md
index de8274e..7058180 100644
--- a/README.md
+++ b/README.md
@@ -158,7 +158,7 @@ below is enough to get going.
| `c` | mark for comparison - press `c` on another entry to diff |
| `x` | delete the selected entry (asks `y`/`n` to confirm) |
| `X` | clear ALL history, not just the current search filter (asks `y`/`n` to confirm) |
-| `E` | export the current view (respects an active search filter) as a HAR file |
+| `E` | export the current view (respects an active search filter) - `.har` or `.csv` |
| `d` | Decoder |
| `/` | search |
| `m` | match-and-replace rules |
@@ -196,20 +196,37 @@ only - not chained/pipelined the way Burp's Decoder supports.
### Export
Two independent export paths, both a modal path-prompt (`enter` writes
-and confirms, `esc` cancels):
-
-- `e` from Detail view exports the single selected entry - request and
- response raw bytes, plain text, exactly what Detail view already
- shows. Each side is annotated when it isn't wire-exact (truncated or
- reconstructed), matching Detail view's own labels.
+and confirms, `esc` cancels). Format is picked by the extension you
+type, the same convention any "save as" dialog uses - no separate
+format-selection control:
+
+- `e` from Detail view exports the single selected entry.
+ - `.txt` (default) - request and response raw bytes, plain text,
+ exactly what Detail view already shows. Each side is annotated when
+ it isn't wire-exact (truncated or reconstructed), matching Detail
+ view's own labels.
+ - `.sh` / `.curl` - the request as a runnable `curl` command line
+ (Burp/DevTools' own "copy as curl"), for handing to someone else or
+ re-running standalone without mitmux. Every value is shell-quoted
+ (a captured or edited request can contain arbitrary bytes).
- `E` from the history list exports the current view - the visible,
- filtered set if a search is active, everything otherwise - as one
- [HAR](https://en.wikipedia.org/wiki/HAR_(file_format)) file, for
- importing into Chrome/Firefox DevTools, Burp, Postman, or anything
- else that reads HAR 1.2. A binary body (an image, say) is base64-
- encoded in the HAR rather than corrupted as text. An entry that fails
- to fetch or parse is skipped rather than aborting the whole export;
- the status line reports how many, if any.
+ filtered set if a search is active, everything otherwise.
+ - `.har` (default) - one
+ [HAR](https://en.wikipedia.org/wiki/HAR_(file_format)) 1.2 file, for
+ importing into Chrome/Firefox DevTools, Burp, Postman, or anything
+ else that reads HAR. A binary body (an image, say) is base64-
+ encoded rather than corrupted as text. An entry that fails to fetch
+ or parse is skipped rather than aborting the whole export; the
+ status line reports how many, if any.
+ - `.csv` - a summary table (id, method, host, path, status, sizes,
+ timing, flag, source) for a report or spreadsheet - lighter and
+ faster than HAR since it needs no per-entry fetch from the daemon.
+ Any field that could be interpreted as a spreadsheet formula (starts
+ with `=`, `+`, `-`, `@`, tab, or CR - method/host/path/error all
+ ultimately trace back to a request line or Host header, exactly the
+ kind of content this tool exists to inspect from hostile traffic)
+ is neutralized with a leading quote before writing, the standard
+ CSV-injection mitigation.
There's no import yet (see `PLAN.md`).