Burp Suite User Forum

Create new post

User credential visible over https communication

Nikhil | Last updated: Jul 07, 2020 07:49AM UTC

Hello, I have recently started using burp suite community edition and i started learning request/response interception using proxy. During the practice i noticed one thing. I was trying to intercept the request of a web application which has HTTPS enabled. When i intercepted login request of a user, i could see their credentials in burp suite. Can you please help to understand how burp suite can see the password from encrypted traffic? Note: I didn't install burp suite CA.

Liam, PortSwigger Agent | Last updated: Jul 07, 2020 11:06AM UTC

In order to intercept traffic between your browser and the web server, Burp breaks the SSL connection. Burp generates a unique CA certificate for each installation, and the private key for this certificate is stored on your computer, in a user-specific location. If untrusted people can read local data on your computer, you may not wish to install Burp's CA certificate.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.