官术网_书友最值得收藏!

Burp Proxy with HTTPS websites

Burp Proxy also works with HTTPS websites. In order to decrypt the communication and be able to analyze it, Burp Proxy intercepts the connection, presents itself as the web server, and issues a certificate that is signed by its own SSL/TLS Certificate Authority (CA). The proxy then presents itself to the actual HTTPS website as the user, and it encrypts the request with the certificate provided by the web server. The connection from the web server is then terminated at the proxy that decrypts the data and re-encrypts it with the self-signed CA certificate, which will be displayed on the user's web browser. The following diagram explains this process:

The web browser will display a warning, as the certificate is self-signed and not trusted by the web browser. You can safely add an exception to the web browser, since you are aware that Burp Proxy is intercepting the request and not a malicious user. Alternatively, you can export Burp's certificate to a file by clicking on the corresponding button in Proxy Listeners by going to Proxy | Options and then import the certificate into the browser and make it a trusted one:

主站蜘蛛池模板: 宝鸡市| 合阳县| 丁青县| 肥西县| 会宁县| 彰武县| 唐河县| 怀化市| 中阳县| 太原市| 平山县| 通渭县| 乡城县| 垫江县| 襄樊市| 和林格尔县| 凌云县| 平塘县| 萝北县| 城固县| 监利县| 抚顺县| 巴塘县| 安平县| 宜宾县| 蒙山县| 广汉市| 苏尼特左旗| 忻城县| 商都县| 宜城市| 昂仁县| 木兰县| 福建省| 杂多县| 栖霞市| 当阳市| 京山县| 开江县| 和平区| 平原县|