- Web Penetration Testing with Kali Linux(Third Edition)
- Gilberto Najera Gutierrez Juned Ahmed Ansari
- 197字
- 2021-06-24 18:44:59
Burp Proxy with HTTPS websites
Burp Proxy also works with HTTPS websites. In order to decrypt the communication and be able to analyze it, Burp Proxy intercepts the connection, presents itself as the web server, and issues a certificate that is signed by its own SSL/TLS Certificate Authority (CA). The proxy then presents itself to the actual HTTPS website as the user, and it encrypts the request with the certificate provided by the web server. The connection from the web server is then terminated at the proxy that decrypts the data and re-encrypts it with the self-signed CA certificate, which will be displayed on the user's web browser. The following diagram explains this process:

The web browser will display a warning, as the certificate is self-signed and not trusted by the web browser. You can safely add an exception to the web browser, since you are aware that Burp Proxy is intercepting the request and not a malicious user. Alternatively, you can export Burp's certificate to a file by clicking on the corresponding button in Proxy Listeners by going to Proxy | Options and then import the certificate into the browser and make it a trusted one:

- 全屋互聯(lián):智能家居系統(tǒng)開發(fā)指南
- Linux系統(tǒng)架構(gòu)與運(yùn)維實(shí)戰(zhàn)
- Implementing Cisco UCS Solutions
- 鴻蒙生態(tài):開啟萬物互聯(lián)的智慧新時(shí)代
- 精解Windows 8
- Haskell Financial Data Modeling and Predictive Analytics
- 玩到極致 iPhone 4S完全攻略
- 高性能Linux服務(wù)器構(gòu)建實(shí)戰(zhàn):運(yùn)維監(jiān)控、性能調(diào)優(yōu)與集群應(yīng)用
- Windows Phone 7.5 Data Cookbook
- PLC控制系統(tǒng)應(yīng)用與維護(hù)
- 細(xì)說Linux基礎(chǔ)知識(shí)
- 注冊(cè)表應(yīng)用完全DIY
- 云原生落地:產(chǎn)品、架構(gòu)與商業(yè)模式
- Linux服務(wù)器配置與管理
- Windows 7實(shí)戰(zhàn)從入門到精通(超值版)