Penetration Testing mailing list archives

Re: Burp Proxy Question


From: pasquale imperato <slashbackpt () gmail com>
Date: Thu, 8 Apr 2010 20:58:53 +0200

Hi.
I guess you have to configure both HTTP and SSL proxy, In the "proxy
settings" of the browser you will use for your tests.
By example, If your burp is running on port 8080 of your local
machine, you have to use these settings on your browser:
HTTP: 127.0.0.1  on port 8080
SSL:   127.0.0.1 on port 8080

At this point, when u will connect to your https url, u will be asked
to accept a new ceritificate in order to browse the website.
Try it and tell me if it works.
Bye

On Tue, Apr 6, 2010 at 4:03 AM, learn lids <learnlids () yahoo com> wrote:

hi all, i am using burp proxy 1.3 to look at a webstie through a http proxy - http://something.com . the website 
redirects to https, and then burp gives the message "Burp proxy error: Unrecognized SSL message, plaintext 
connection? "

this seems to be a common java error, and the burp suite documentation did not have any poiters to resolve this 
issue. does burp supprot outgoing http/https proxies at all? if yes or no, what is the best way to use it?

- learner




------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: