Burp certificate
Install the certificates for both Burp and Zap to allow us to navigate HTTPS traffic without having encryption warnings.
Start up BurpSuite and go to Proxy tab -> Options.
data:image/s3,"s3://crabby-images/8e885/8e88514ee88a772d51aef9f11e2c9cd9e6d53ae7" alt="In Burp" |
You should see an entry for your localhost, 127.0.0.1 , and port 8080 . These are the default settings for BurpSuite. If not, add. |
Select BurpSuite on FoxyProxy, and navigate to http://burpsuite
:
data:image/s3,"s3://crabby-images/72301/7230127921deec6517b11a382fcbd6b74fececb6" alt="Get cert" |
Download that cert |
Go to the options menu in Firefox and select Settings -> Privacy & Security. Nearly all the way down, in the Security section click on the View Certificates
button. And from the Authorities
tab, choose Import
.
data:image/s3,"s3://crabby-images/a0fb2/a0fb25e7c50f221610623b0349f03242fcebaef6" alt="Import cert" |
Import the cert. |
data:image/s3,"s3://crabby-images/b7c11/b7c119bbdd8340453544a3e036ac3d8bb7c247f9" alt="Import cert" |
Select "Trust this CA to identify websites", and OK. |
Test that the certificate is imported correctly by visiting an HTTPS website with BurpSuite running and Burp being selected in FoxyProxy. It should load without errors.
Zap certificate
data:image/s3,"s3://crabby-images/d962f/d962f6e0df4348e65fdbfa8adddeb81d11a57b13" alt="Import cert" |
Zap, smart as it is when opening it up with Burp still running. |
data:image/s3,"s3://crabby-images/215e2/215e21c425aaacbecfc32ca65a42422b5a0c871a" alt="Import cert" |
If not, set it in Tools -> Options -> Local Servers/Proxies |
To install the HTTPS certificates for Zap, within the Options menu, Network
-> Server Certificates
.
data:image/s3,"s3://crabby-images/ce3fc/ce3fcc5962a16cd28c8ca117a60638ba2336e72a" alt="Import cert" |
Click Save |
Open Firefox Settings
-> Privacy & Security
menu -> View Certificates
button -> Authorities
tab, select Import
. Trust this CA to identify websites.
To test it, have Zap running and FoxyProxy set to Zap. Go to any HTTPS website, and it should load without error.