Book Image

Burp Suite Essentials

By : Akash Mahajan
Book Image

Burp Suite Essentials

By: Akash Mahajan

Overview of this book

Table of Contents (19 chapters)
Burp Suite Essentials
Credits
About the Author
Acknowledgments
About the Reviewers
www.PacktPub.com
Preface
Index

Importing the Burp certificate in Mozilla Firefox


Starting with Mozilla Firefox, it is quite simple to import the certificate:

  1. While Burp is running, go to http://burp.

  2. Click on CA Certificate. Note where this file is downloaded:

    The method is very convenient for testers, but it does open the tester to a malicious user who could perform MITM attacks against the pentester, abusing the trust related to the Burp Suite root certificate.

  3. Open Firefox Options, click on Advanced, Certificates, and View Certificates. Have a look at the following screenshot:

  4. Click on Authorities, click on the Import button, and navigate to the place where you downloaded the certificate, as shown in the following screenshot:

  5. You will get another window about whether you trust the new certificate authority. Select Trust this CA to identify web sites. And if you like, click on View to examine the CA certificate:

  6. Click on the OK button and then navigate to https://burp. If there are no errors or warnings about the certificate...