srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md22
1 files changed, 21 insertions, 1 deletions
diff --git a/README.md b/README.md
index 393b0bc..dfa9f87 100644
--- a/README.md
+++ b/README.md
@@ -144,13 +144,33 @@ shorter `-socket /tmp/mitmux.sock` (and the matching `-socket` to
trust store itself. Installing a root CA is a system-wide trust
change, so you run the printed command yourself.
+ For a phone, tablet, or any other device where copying a file over
+ and importing it manually is awkward - the actual common case for
+ mobile testing - point the device's browser at
+ **`http://mitmux.cert/`** once it's configured to proxy through
+ mitmux (step 3). mitmuxd recognizes that hostname specifically and
+ serves its own CA certificate as a download, the same trick
+ [mitmproxy's `mitm.it`](https://mitm.it) uses: no DNS lookup, no
+ real domain, works the moment traffic is flowing through the proxy
+ at all - the browser's install-certificate prompt handles the rest.
+ Plain `http://`, not `https://`: fetching it over TLS would need the
+ device to already trust mitmux's CA to intercept that very
+ connection, which is the exact problem this page solves.
+
3. **Point a client at the proxy.** e.g.:
```sh
curl -x http://127.0.0.1:8080 --cacert ~/.config/mitmux/ca.pem https://example.com/
```
- Or configure your browser's proxy settings to `127.0.0.1:8080`.
+ Or configure your browser's proxy settings to `127.0.0.1:8080` -
+ directly, or via a proxy-switcher extension like
+ [FoxyProxy](https://getfoxyproxy.org/): add a new proxy profile
+ pointing at `127.0.0.1:8080` (HTTP, and reused for HTTPS - mitmux
+ handles both on the same listener), no mitmux-specific setup needed
+ since it's a standard forward proxy speaking the same protocol Burp/
+ ZAP/Caido all do. Same story for a phone or tablet: set its Wi-Fi
+ proxy to your machine's LAN address and the daemon's port.
4. **Open the TUI** (in another terminal - the daemon keeps running
independently):