2011-03-16 02:50:31 +00:00
|
|
|
|
2011-08-04 22:23:32 +00:00
|
|
|
## Sticky cookies
|
|
|
|
|
|
|
|
When the sticky cookie option is set, __mitmproxy__ will add the cookie most
|
2011-03-17 20:04:49 +00:00
|
|
|
recently set by the server to any cookie-less request. Consider a service that
|
|
|
|
sets a cookie to track the session after authentication. Using sticky cookies,
|
|
|
|
you can fire up mitmproxy, and authenticate to a service as you usually would
|
|
|
|
using a browser. After authentication, you can request authenticated resources
|
|
|
|
through mitmproxy as if they were unauthenticated, because mitmproxy will
|
|
|
|
automatically add the session tracking cookie to requests. Among other things,
|
|
|
|
this lets you script interactions with authenticated resources (using tools
|
|
|
|
like wget or curl) without having to worry about authentication.
|
|
|
|
|
|
|
|
Sticky cookies are especially powerful when used in conjunction with [client
|
|
|
|
replay](@!urlTo("clientreplay.html")!@) - you can record the authentication
|
|
|
|
process once, and simply replay it on startup every time you need to interact
|
|
|
|
with the secured resources.
|
2011-03-16 02:50:31 +00:00
|
|
|
|
2013-01-02 08:57:39 +00:00
|
|
|
<table class="table">
|
|
|
|
<tbody>
|
|
|
|
<tr>
|
|
|
|
<th width="20%">command-line</th>
|
|
|
|
<td>
|
|
|
|
<ul>
|
2013-03-10 22:49:36 +00:00
|
|
|
<li>-t FILTER</li>
|
2013-01-02 08:57:39 +00:00
|
|
|
</ul>
|
|
|
|
</td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<th>mitmproxy shortcut</th> <td><b>t</b></td>
|
|
|
|
</tr>
|
|
|
|
</tbody>
|
|
|
|
</table>
|
2011-03-16 02:50:31 +00:00
|
|
|
|
2011-03-20 04:31:54 +00:00
|
|
|
|
2013-01-02 08:57:39 +00:00
|
|
|
## Sticky auth
|
2011-08-04 22:23:32 +00:00
|
|
|
|
|
|
|
The sticky auth option is analogous to the sticky cookie option, in that HTTP
|
|
|
|
__Authorization__ headers are simply replayed to the server once they have been
|
|
|
|
seen. This is enough to allow you to access a server resource using HTTP Basic
|
|
|
|
authentication through the proxy. Note that __mitmproxy__ doesn't (yet) support
|
|
|
|
replay of HTTP Digest authentication.
|
2013-01-02 08:57:39 +00:00
|
|
|
|
|
|
|
<table class="table">
|
|
|
|
<tbody>
|
|
|
|
<tr>
|
|
|
|
<th width="20%">command-line</th>
|
|
|
|
<td>
|
|
|
|
<ul>
|
2013-03-10 22:49:36 +00:00
|
|
|
<li>-u FILTER</li>
|
2013-01-02 08:57:39 +00:00
|
|
|
</ul>
|
|
|
|
</td>
|
|
|
|
</tr>
|
|
|
|
<tr>
|
|
|
|
<th>mitmproxy shortcut</th> <td><b>u</b></td>
|
|
|
|
</tr>
|
|
|
|
</tbody>
|
|
|
|
</table>
|
|
|
|
|
|
|
|
|