The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How do I specify which SSL/TLS ciphers Burp Collaborator can use?

Stijn | Last updated: Feb 22, 2016 09:08AM UTC

Dear All, We're currently running a private instance of Burp Collaborator. As this host is visible to the internet, we include this system in our regular vulnerability scans focused on internet-facing systems. Our most recent scan included possible vulnerabilities on the Collaborator system. Most vulnerabilities relate to the use of unauthenticated, not encrypted or weak cipher suites. One of the vulnerabilities that popped up was the all-known BEAST. As the context of a Burp Collaborator instance is to receive connections from possibly weak systems or applications, from a wide variety of systems, we cannot have a situation in which the SSL/TLS connection can be considered to be providing insufficient security. We do need the system to be internet facing, as we won't be testing internal applications only. This leads to my question: How do I specify which SSL/TLS ciphers Burp Collaborator can use? Is there a (e.g. command line) option I can pass to the Burp Collaborator instance, which would tell it what cipher suites it can or cannot use? Thank you for your reply. Kind regards, Stijn

PortSwigger Agent | Last updated: Feb 22, 2016 10:17AM UTC