From 2ade8c807584bff0b60d6b6f278dbde29b13a5ff Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Mon, 29 Jun 2026 09:58:00 +0200 Subject: Browser-launcher helper: throwaway proxied profile, one flag Adds -launch-browser=chrome|firefox|auto to the mitmux TUI binary. Resolves an installed browser (PATH first, then common per-OS install locations), spins up a brand new throwaway profile, configures it to proxy through the daemon, and opens straight to http://mitmux.cert/ so installing the CA in that profile is one click. This is the answer to "build an in-house browser": a bundled GUI browser is a different, much larger project and works against this tool's terminal-native positioning - the actually useful part of that idea is zero-friction setup (proxy + CA-install page, no profile pollution), which this delivers by launching the user's own browser in a disposable profile instead of embedding one. Chrome takes --proxy-server as a flag; Firefox has none, so its profile gets a generated user.js instead - the only non-interactive way to configure it. Verified against this machine's real installed Chrome and Firefox: binary discovery resolves both, auto prefers chrome-family when both are present, and the generated Firefox prefs are well-formed. Deliberately did not spawn a live browser window as part of verification - that's a visible GUI action on whoever runs it, left for a user to trigger by hand via the flag. --- README.md | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) (limited to 'README.md') diff --git a/README.md b/README.md index 16a1880..ad4db79 100644 --- a/README.md +++ b/README.md @@ -180,6 +180,18 @@ shorter `-socket /tmp/mitmux.sock` (and the matching `-socket` to ZAP/Caido all do. Same story for a phone or tablet: set its Wi-Fi proxy to your machine's LAN address and the daemon's port. + Or skip manual configuration entirely: `mitmux -launch-browser=chrome` + (or `firefox`, or `auto` to use whichever's installed) opens a fresh, + throwaway browser profile already pointed at the proxy, landing + straight on `http://mitmux.cert/` so installing the CA in that one + profile is a single click. The profile is brand new every time - + no cookies, extensions, or cached certificate-trust decisions carried + over from your regular browsing - and never reused, matching the + "don't disturb your everyday session" spirit of a pentest tool. + mitmux doesn't ship its own browser - building and maintaining one + is a different project entirely, and a terminal proxy tool has no + business trying; this launches your existing one instead. + 4. **Open the TUI** (in another terminal - the daemon keeps running independently): @@ -188,7 +200,8 @@ shorter `-socket /tmp/mitmux.sock` (and the matching `-socket` to ``` Both binaries take flags for non-default setups - `-listen`, `-socket`, -`-ca-dir`, `-db`, `-upstream-proxy` on `mitmuxd`; `-socket` on `mitmux`. +`-ca-dir`, `-db`, `-upstream-proxy` on `mitmuxd`; `-socket`, +`-launch-browser` on `mitmux`. Both also take `-version` (prints version/commit/date and exits - `dev` for a plain `go build`; `make build`/`make release` fill it in from `git describe`) and `-h` for the full list. -- cgit v1.2.3