How mitmproxy works
corte.si
corte.si
If you haven't looked at Burp Suite and, unlike Aldo Cortesi, can stomach running a Java program (I don't like Java either, but...), Burp is both the industry standard tool used by appsec testing for web work and pretty inexpensive for what it does.
I should also add - Burp is a fine tool, but I would hope there's room for more than a single "industry standard" in this area. Mitmproxy has some comparative strengths, is completely open, and is improving rapidly. I'd hate for people to be discouraged from trying it out and helping to make it better.
(bias: submitted a few patches to mitmproxy.git)
I guess it wouldn't really be mitm in this regard, but manipulating the traffic is not always needed.
Currently I use httpry to watch http traffic without interfering with its flow, but httpry is fairly limited in its functionality.
By the way, very impressive piece of software. Its nice to have more quality open tools like this.
Yes, it's very similar to tcpdump in this respect. You can write flows to disk like this:
mitmdump -w outfile
And then read them back: mitmdump -r outfile
All the standard options for modifying, replaying and filtering are available when you read saved flows. So you could do this: mitmdump -r outfile -s foo.py -w newfile
Which will read flows from file, run the script foo.py over each flow as its read (which can then modify them arbitrarily), and then write the result to newfile.Sometimes you might want to analyze traffic on production systems and changing routes is not an option.
What I would love to see is a way of doing a non-invasive, realtime processing of http traffic, eg when a specific post request is made, trigger some job.