Firefox+BurpSuite bypass HSTS to capture packets

Encountered scene

During the penetration test, the target website used HSTS, causing burpsuite to fail to capture packets normally. The scenarios are as follows:

Solution

After setting up the burpsuite proxy in Firefox, visit http://burp, and then download the certificate to the local

Then import the certificate to the browser certificate authority:

After visiting the page again, you can browse normally:

burpsuite can capture packets:

 

Guess you like

Origin blog.csdn.net/Fly_hps/article/details/107403921