diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 17 |
1 files changed, 14 insertions, 3 deletions
@@ -94,8 +94,18 @@ go build -o bin/mitmux ./cmd/mitmux 2. **Trust the CA.** To intercept HTTPS without constant certificate warnings, import `ca.pem` into whatever's making the requests - your browser's certificate store, `curl --cacert`, a mobile device's - trusted-certificate settings, etc. (Automated per-OS trust-store - installation isn't implemented yet - see `PLAN.md`.) + trusted-certificate settings, etc. For copy-pasteable, OS-specific + steps (Linux: whichever of `trust`/`update-ca-trust`/ + `update-ca-certificates` is actually on your system, plus Firefox's + own NSS store; macOS: Keychain; Windows: `certutil`/PowerShell), run: + + ```sh + ./bin/mitmuxd -install-ca + ``` + + This only prints commands - it never runs anything against your + trust store itself. Installing a root CA is a system-wide trust + change, so you run the printed command yourself. 3. **Point a client at the proxy.** e.g.: @@ -316,7 +326,8 @@ reasoning behind each: - Match-and-replace: headers only, no body rules yet - Intruder: Sniper attack only (no battering ram / pitchfork / cluster bomb), sequential sending, capped at 1000 requests per attack -- No automated CA installation into OS/browser trust stores +- `mitmuxd -install-ca` prints per-OS trust-store install steps; it + never runs them for you (see Quick start above for why) - No WebSocket interception - No client (mutual-TLS) certificate support - No active or passive vulnerability scanning, no plugin system - this |