diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 45 |
1 files changed, 31 insertions, 14 deletions
@@ -158,7 +158,7 @@ below is enough to get going. | `c` | mark for comparison - press `c` on another entry to diff | | `x` | delete the selected entry (asks `y`/`n` to confirm) | | `X` | clear ALL history, not just the current search filter (asks `y`/`n` to confirm) | -| `E` | export the current view (respects an active search filter) as a HAR file | +| `E` | export the current view (respects an active search filter) - `.har` or `.csv` | | `d` | Decoder | | `/` | search | | `m` | match-and-replace rules | @@ -196,20 +196,37 @@ only - not chained/pipelined the way Burp's Decoder supports. ### Export Two independent export paths, both a modal path-prompt (`enter` writes -and confirms, `esc` cancels): - -- `e` from Detail view exports the single selected entry - request and - response raw bytes, plain text, exactly what Detail view already - shows. Each side is annotated when it isn't wire-exact (truncated or - reconstructed), matching Detail view's own labels. +and confirms, `esc` cancels). Format is picked by the extension you +type, the same convention any "save as" dialog uses - no separate +format-selection control: + +- `e` from Detail view exports the single selected entry. + - `.txt` (default) - request and response raw bytes, plain text, + exactly what Detail view already shows. Each side is annotated when + it isn't wire-exact (truncated or reconstructed), matching Detail + view's own labels. + - `.sh` / `.curl` - the request as a runnable `curl` command line + (Burp/DevTools' own "copy as curl"), for handing to someone else or + re-running standalone without mitmux. Every value is shell-quoted + (a captured or edited request can contain arbitrary bytes). - `E` from the history list exports the current view - the visible, - filtered set if a search is active, everything otherwise - as one - [HAR](https://en.wikipedia.org/wiki/HAR_(file_format)) file, for - importing into Chrome/Firefox DevTools, Burp, Postman, or anything - else that reads HAR 1.2. A binary body (an image, say) is base64- - encoded in the HAR rather than corrupted as text. An entry that fails - to fetch or parse is skipped rather than aborting the whole export; - the status line reports how many, if any. + filtered set if a search is active, everything otherwise. + - `.har` (default) - one + [HAR](https://en.wikipedia.org/wiki/HAR_(file_format)) 1.2 file, for + importing into Chrome/Firefox DevTools, Burp, Postman, or anything + else that reads HAR. A binary body (an image, say) is base64- + encoded rather than corrupted as text. An entry that fails to fetch + or parse is skipped rather than aborting the whole export; the + status line reports how many, if any. + - `.csv` - a summary table (id, method, host, path, status, sizes, + timing, flag, source) for a report or spreadsheet - lighter and + faster than HAR since it needs no per-entry fetch from the daemon. + Any field that could be interpreted as a spreadsheet formula (starts + with `=`, `+`, `-`, `@`, tab, or CR - method/host/path/error all + ultimately trace back to a request line or Host header, exactly the + kind of content this tool exists to inspect from hostile traffic) + is neutralized with a leading quote before writing, the standard + CSV-injection mitigation. There's no import yet (see `PLAN.md`). |