4 ms·
[edit: I actually misread your question. We don't at the moment have reassembly of HTTP flows from pcaps in base, but there's an external project that does this
by cortesi 13y ago
[edit: I actually misread your question. We don't at the moment have reassembly of HTTP flows from pcaps in base, but there's an external project that does this. As another comment noted, transparent mode is probably still your best bet. https://github.com/cjneasbi/mitmextract https://github.com/cjneasbi/mitmextract]
Yes, it's very similar to tcpdump in this respect. You can write flows to disk like this:
mitmdump -w outfile
And then read them back:
mitmdump -r outfile
All the standard options for modifying, replaying and filtering are available when you read saved flows. So you could do this:
mitmdump -r outfile -s foo.py -w newfile
Which will read flows from file, run the script foo.py over each flow as its read (which can then modify them arbitrarily), and then write the result to newfile.
- WatchDog 13y agoTransparent mode is great but invasive, and mitmextract is fine for non real-time analysis. Sometimes you might want to analyze traffic on production systems and changing routes is not an option. What I would love to see is a way of doing a non-invasive, realtime processing of http traffic, eg when a specific post request is made, trigger some job.
- cortesi 13y agoThat would be nice indeed. Mitmextract uses libnids, which can do stream reassembly on the fly. It's not such a big step going from reassembling a pcap file to doing the same thing on network traffic.