官术网_书友最值得收藏!

Burp Proxy with HTTPS websites

Burp Proxy also works with HTTPS websites. In order to decrypt the communication and be able to analyze it, Burp Proxy intercepts the connection, presents itself as the web server, and issues a certificate that is signed by its own SSL/TLS Certificate Authority (CA). The proxy then presents itself to the actual HTTPS website as the user, and it encrypts the request with the certificate provided by the web server. The connection from the web server is then terminated at the proxy that decrypts the data and re-encrypts it with the self-signed CA certificate, which will be displayed on the user's web browser. The following diagram explains this process:

The web browser will display a warning, as the certificate is self-signed and not trusted by the web browser. You can safely add an exception to the web browser, since you are aware that Burp Proxy is intercepting the request and not a malicious user. Alternatively, you can export Burp's certificate to a file by clicking on the corresponding button in Proxy Listeners by going to Proxy | Options and then import the certificate into the browser and make it a trusted one:

主站蜘蛛池模板: 武乡县| 咸阳市| 日喀则市| 龙陵县| 海宁市| 定西市| 抚州市| 五家渠市| 安陆市| 新营市| 明溪县| 加查县| 晋中市| 祁门县| 宝应县| 兖州市| 澳门| 怀仁县| 奉化市| 兰溪市| 出国| 抚远县| 福安市| 南昌县| 平湖市| 腾冲县| 宜昌市| 隆昌县| 临漳县| 霍城县| 荃湾区| 湟中县| 东方市| 监利县| 浮山县| 孟连| 剑阁县| 永济市| 昭苏县| 新余市| 南城县|