Book Image

Burp Suite Essentials

By : Akash Mahajan
Book Image

Burp Suite Essentials

By: Akash Mahajan

Overview of this book

Table of Contents (19 chapters)
Burp Suite Essentials
Credits
About the Author
Acknowledgments
About the Reviewers
www.PacktPub.com
Preface
Index

SSL pass-through


Sometimes due to the way applications and websites are set up, it may not be possible to intercept SSL traffic. Usually, Burp will show an SSL negotiation error in the Alerts tab. One of the most common cases is when a mobile application utilizes certificate pinning. In such a scenario, when we still want to keep working with the other parts of the application, we can add the host in the SSL pass-through list.

This can be automated by checking an option, which will kick in as soon as Burp encounters an SSL negotiation error. Have a look at the following screenshot: