The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

User credential visible over https communication

Nikhil | Last updated: Jul 07, 2020 07:49AM UTC

Hello, I have recently started using burp suite community edition and i started learning request/response interception using proxy. During the practice i noticed one thing. I was trying to intercept the request of a web application which has HTTPS enabled. When i intercepted login request of a user, i could see their credentials in burp suite. Can you please help to understand how burp suite can see the password from encrypted traffic? Note: I didn't install burp suite CA.

Liam, PortSwigger Agent | Last updated: Jul 07, 2020 11:06AM UTC