From ce6ce32469da720105258cb66e0274b2b009cd1d Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Tue, 3 Feb 2026 00:38:00 +0200 Subject: Intruder-equivalent: Sniper attacks with § markers MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Implements build-order step 7, the last (optional) item. Scoped to Sniper only - one payload set, one §-marked position fuzzed at a time, others held at their base value - since that covers most real Intruder usage; battering ram / pitchfork / cluster bomb aren't implemented. Sequential sending, capped at 1000 generated requests as a fixed safety limit. internal/proxy: repeat.go's Repeat() is refactored into a shared sendRaw(..., source) primitive so Intrude can reuse the exact same raw-byte send/record path with source="intruder" instead of duplicating it. intrude.go adds ParseMarkers/buildRequest (marker parsing and payload substitution, covered by intrude_test.go - this is fiddly byte-splicing logic, worth locking down with real tests rather than trusting it by inspection) and Intrude(), which walks positions × payloads calling sendRaw and streaming each result through a callback. internal/ipc gains a dedicated streaming "intrude" connection (same shape as Subscribe, but blocking sends rather than drop-on-slow- consumer - each result is the attack's actual data, not a notification). cmd/mitmux gains an Intruder view: editable request template (ctrl+p inserts a § marker at the cursor - typing § directly also works, ctrl+p just doesn't require a keyboard layout that can produce it), editable payload list, and a live results table wired to the existing detail view (selecting a row and hitting enter opens the full request/response for that specific attack request). Verified live against real external traffic: a Sniper attack against httpbin.org/status/§200§ with payloads 200/404/500 produced exactly the three corresponding real status codes back (not a canned/local result), confirmed the three requests landed in history tagged source="intruder" with the § markers correctly stripped from what was actually sent, and confirmed opening a result row's full detail from the results table. This closes out the full build order from PLAN.md (steps 1-7). --- internal/proxy/intrude.go | 124 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 124 insertions(+) create mode 100644 internal/proxy/intrude.go (limited to 'internal/proxy/intrude.go') diff --git a/internal/proxy/intrude.go b/internal/proxy/intrude.go new file mode 100644 index 0000000..933a309 --- /dev/null +++ b/internal/proxy/intrude.go @@ -0,0 +1,124 @@ +// Intruder-equivalent: mark positions in a raw request template with § +// (Burp's own marker character, so anyone who's used Burp already knows +// the syntax), and Sniper-attack them - one position fuzzed at a time +// through a shared payload set, every other marked position holding its +// base value. Battering ram / pitchfork / cluster bomb are not +// implemented; Sniper covers the large majority of real Intruder usage +// and this whole feature is explicitly optional in the build order. +package proxy + +import ( + "bytes" + "context" + "fmt" + + "mitmux/internal/store" +) + +const marker = "§" + +// maxIntrudeRequests caps positions × payloads for one attack - a safety +// limit against an accidental huge wordlist times several positions +// turning into an unbounded flood, not a tuned production value. +const maxIntrudeRequests = 1000 + +// IntrudePosition is one marked, resolved insertion point. +type IntrudePosition struct { + Index int // 0-based, in order of appearance + Base string // the text between its markers +} + +// ParseMarkers finds every §base§ pair in template and returns the +// resolved positions plus template with the markers stripped out (the +// form actually used as the base request when no position is being +// fuzzed). An odd number of § markers is a user error - unterminated +// marker - reported rather than guessed at. +func ParseMarkers(template []byte) (positions []IntrudePosition, stripped []byte, err error) { + parts := bytes.Split(template, []byte(marker)) + if len(parts)%2 != 1 { + return nil, nil, fmt.Errorf("unterminated %s marker - markers must come in pairs", marker) + } + if len(parts) == 1 { + return nil, template, nil + } + + var buf bytes.Buffer + for i, part := range parts { + if i%2 == 1 { + positions = append(positions, IntrudePosition{Index: len(positions), Base: string(part)}) + } + buf.Write(part) + } + return positions, buf.Bytes(), nil +} + +// buildRequest re-inserts each position's base value into stripped +// (computed relative to the ORIGINAL template's marker layout, so this +// re-derives offsets rather than operating on the already-stripped +// bytes) except for `active`, which gets payload instead. +func buildRequest(template []byte, active int, payload string) ([]byte, error) { + parts := bytes.Split(template, []byte(marker)) + if len(parts)%2 != 1 { + return nil, fmt.Errorf("unterminated %s marker", marker) + } + var buf bytes.Buffer + pos := 0 + for i, part := range parts { + if i%2 == 1 { + if pos == active { + buf.WriteString(payload) + } else { + buf.Write(part) + } + pos++ + continue + } + buf.Write(part) + } + return buf.Bytes(), nil +} + +// Intrude runs a Sniper attack: template must contain at least one +// §marked§ position. For each position, in order, every payload is sent +// with that position replaced by the payload and all others at their +// base value; onResult is called synchronously after each request +// completes - with the position index, the payload used, the resulting +// entry (nil if sendErr is set), and any send error - so a caller can +// stream progress, and stops the attack early if it returns false. +func (s *Server) Intrude(ctx context.Context, scheme, host string, template []byte, payloads []string, + onResult func(position int, payload string, entry *store.Entry, sendErr error) bool) error { + positions, _, err := ParseMarkers(template) + if err != nil { + return err + } + if len(positions) == 0 { + return fmt.Errorf("no %s-marked positions in the request template", marker) + } + if len(payloads) == 0 { + return fmt.Errorf("no payloads") + } + if total := len(positions) * len(payloads); total > maxIntrudeRequests { + return fmt.Errorf("attack would send %d requests (%d positions × %d payloads), over the %d limit", + total, len(positions), len(payloads), maxIntrudeRequests) + } + + for _, pos := range positions { + for _, payload := range payloads { + raw, err := buildRequest(template, pos.Index, payload) + if err != nil { + return err + } + + // sendRaw is already self-bounding (dialForRepeat's own dial + // timeout, then conn.SetDeadline for the rest), so ctx here + // only needs to carry cancellation - e.g. the IPC connection + // driving this attack closing mid-run. + e, sendErr := s.sendRaw(ctx, scheme, host, raw, "intruder") + + if !onResult(pos.Index, payload, e, sendErr) { + return nil + } + } + } + return nil +} -- cgit v1.2.3