1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
|
# mitmux - Intercepting Proxy TUI (Burp/Caido replacement)
## Overview
Daily-driver intercepting proxy for manual pentest work, terminal-based.
Prior art to read before writing code: Cruster (Rust, built on
hudsucker) - same problem, worth studying even though this build is Go.
## Stack
- Language: Go - memory safety on hostile input matters here more than
in the other projects, since this parses attacker-adjacent traffic
- TLS interception: Go's own `crypto/tls` + a CA cert generator
(analogous to `rcgen`) for per-domain leaf certs
- Proxy core: `net/http` + manual `CONNECT` handling, or a MITM proxy
library if one fits without fighting Go's aggressive header
normalization
- Storage: SQLite in WAL mode - blob columns for raw request/response
bytes, FTS5 index for search across bodies
- UI: Bubble Tea + Lipgloss (TUI), same family as the packet analyzer's
Go sibling if that ever gets built
## Architecture sketch (important - don't skip this)
- Split proxy engine from TUI. Headless daemon owns the listening
socket and the DB; TUI is a client over a Unix socket. The proxy
keeps running when the UI restarts, and a web UI or CLI scanner can
be bolted on later without touching the engine.
- Store raw bytes as the source of truth. Parse into a display view,
never re-serialize for storage - request smuggling, header injection,
and parser-differential bugs depend on the original malformed framing
surviving. For Repeater specifically, write requests as raw bytes
over the socket rather than through a normalizing HTTP client.
## Build order
1. Proxy + CA cert generation + plaintext HTTP passthrough
2. TLS interception (per-host cert generation, install CA)
3. History view (SQLite storage, raw bytes preserved) in the TUI
4. Repeater (raw-byte send/resend, the feature used daily)
5. Search/filter (FTS5)
6. Match-and-replace rules
7. Intruder-equivalent (last, optional)
## Open questions
- HTTP/2: handle natively (decided) - full fidelity over MITM'd
connections rather than downgrading to HTTP/1.1. Adds complexity to
CONNECT handling, stream framing, and step 3 storage (multiplexed
streams over one connection need per-stream request/response
boundaries, not just per-connection ones).
- CA install UX per OS (Linux/macOS/Windows trust stores)
- Whether WebSocket interception is v1 or a later addition
|