scribble

sanlengjingvv

Blog GitHub

13 Feb 2016
Burp Suite & Charles HTTPS抓包

准备:

先看这篇文章,Nginx 配置 SSL 证书 + 搭建 HTTPS 网站教程 你会有配套的两个文件,一个后缀名.key另一个.crt 比如testerhome.keytesterhome.crt

生成p12文件

testerdeMac:forNginx tester$ pwd
/Users/tester/Downloads/forNginx
testerdeMac:forNginx tester$ ls
testerhome.crt	testerhome.key
testerdeMac:forNginx tester$ openssl pkcs12 -export -clcerts -in testerhome.crt -inkey testerhome.key -out testerhome.p12
Enter Export Password:
Verifying - Enter Export Password:

Burp Suite设置

启动 Burp Suite
java -jar burpsuite_free_v1.6.32.jar

修改代理设置
Burp Suite设置

Charles 设置

版本:Charles 3.11.2
菜单 -> Proxy -> SSL Proxying Settings
CharlesSSL
CharleClient
CharleRoot
完成就可以抓到HTTPS了


Til next time,
黑水 at 09:45

scribble

Blog GitHub