The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

SSL session establishment using burp

Geetanjali | Last updated: Oct 12, 2017 09:00AM UTC

Hi Team, I just wanted to understand how SSL handshake takes place when burp lies between browser and server. Could you please provide some information on it. Thanks & Regards Geet (Security Ananlyst)

PortSwigger Agent | Last updated: Oct 12, 2017 09:15AM UTC

Hi Geet, Thanks for your message. Burp is an SSL breaking proxy. It terminates the SSL connection from your browser to Burp, and makes a fresh connection from Burp to the target server. The certificate it returns to the browser is generated using a certificate authority that is generated for your install of Burp. That's why you have to follow the certificate installation instructions to avoid browser warnings: - https://support.portswigger.net/customer/portal/articles/1783075-installing-burp-s-ca-certificate-in-your-browser

Burp User | Last updated: Oct 20, 2017 08:55PM UTC