srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md17
1 files changed, 14 insertions, 3 deletions
diff --git a/README.md b/README.md
index 67536c7..f65e3fe 100644
--- a/README.md
+++ b/README.md
@@ -94,8 +94,18 @@ go build -o bin/mitmux ./cmd/mitmux
2. **Trust the CA.** To intercept HTTPS without constant certificate
warnings, import `ca.pem` into whatever's making the requests -
your browser's certificate store, `curl --cacert`, a mobile device's
- trusted-certificate settings, etc. (Automated per-OS trust-store
- installation isn't implemented yet - see `PLAN.md`.)
+ trusted-certificate settings, etc. For copy-pasteable, OS-specific
+ steps (Linux: whichever of `trust`/`update-ca-trust`/
+ `update-ca-certificates` is actually on your system, plus Firefox's
+ own NSS store; macOS: Keychain; Windows: `certutil`/PowerShell), run:
+
+ ```sh
+ ./bin/mitmuxd -install-ca
+ ```
+
+ This only prints commands - it never runs anything against your
+ trust store itself. Installing a root CA is a system-wide trust
+ change, so you run the printed command yourself.
3. **Point a client at the proxy.** e.g.:
@@ -316,7 +326,8 @@ reasoning behind each:
- Match-and-replace: headers only, no body rules yet
- Intruder: Sniper attack only (no battering ram / pitchfork / cluster
bomb), sequential sending, capped at 1000 requests per attack
-- No automated CA installation into OS/browser trust stores
+- `mitmuxd -install-ca` prints per-OS trust-store install steps; it
+ never runs them for you (see Quick start above for why)
- No WebSocket interception
- No client (mutual-TLS) certificate support
- No active or passive vulnerability scanning, no plugin system - this