How to intercept HSTS enabled HTTP requests using Burp or any other interceptors??

Yametazamwa mara 590
Ruka hadi kwenye ujumbe wa kwanza ambao haujasomwa

Nandan L G

hayajasomwa,
1 Ago 2016, 01:10:5701/08/2016
kwa null
Hi All,

Can anyone please help me out in how to intercept HSTS enabled requests in proxy interceptors? I'm unable to intercept requests in Burp/Fiddler as server doesn't allow communication with browser due to certificate errors.

Thanks in advance.

Best Regards,
Nandan

Taher Barodawala

hayajasomwa,
1 Ago 2016, 09:36:0701/08/2016
kwa null
Posting the errors received would help. Also, what does the alerts section of Burp say?
HSTS enforces all communication take place over a secured channel. No reason why you cant fit a proxy in between. Have you tried to add Portswigger CA as a trusted CA? Have you tried with another browser? Is this is a mobile app which implements cert pinning?

Abhay Rana

hayajasomwa,
1 Ago 2016, 09:36:0701/08/2016
kwa null
Hi,

HSTS has no effect in your capability to intercept your request. All HSTS does is inform the browser to only make requests over HTTPS, instead of HTTP.

You will face the same issue if the server is running only on HTTPS, for eg. To resolve this, what you need to do is install a root cert from burp/fiddler in your browser and have your proxy generate certs on the fly. 


--
______________________________________________________________________________
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
______________________________________________________________________________
se7enth edition of nullcon Goa (Mar 9-12, 2016)
http://nullcon.net
---
You received this message because you are subscribed to the Google Groups "null" group.
To unsubscribe from this group and stop receiving emails from it, send an email to null-co-in+...@googlegroups.com.
Visit this group at https://groups.google.com/group/null-co-in.
For more options, visit https://groups.google.com/d/optout.
--
--
Nemo

kamal

hayajasomwa,
1 Ago 2016, 09:36:0701/08/2016
kwa null-...@googlegroups.com

install burp certificate in the browsers trusted certificate liat and it should work.


Bharat

hayajasomwa,
2 Ago 2016, 05:56:0702/08/2016
kwa null-...@googlegroups.com
Well Hit and Try worked for me:
  1. Generate the certificate by Burp.
  2. In Firefox,  Options>Advanced>Certificates>View Certificates>Authorities>Import( the generated certificate)>Edit trust>Select All.
  3. In Chrome, Settings>Advanced Settings>Manage Certificates> Import the Certificate in Intermediate Certificate Authorities, Trusted Root Certification Authorities and Trusted Publishers. Don't forget to Select All in Advanced Options.
  4. Restart the browser and Burp.
Worked for me twice.
--
Bharat Razdan
Co-Founder & Author
www.techites.com

Please do not print this email unless it is absolutely necessary. Spread environmental awareness.

Shrivathsa Bhat

hayajasomwa,
4 Ago 2016, 14:06:5404/08/2016
kwa null-...@googlegroups.com
Close all chrome instances and open chrome using this command. (Use valid path for chrome installation)

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --disable-xss-auditor --ignore-certificate-errors

This will make chrome ignore all certificate errors (as well as disables default RXSS check) hence passes all requests through burp. 

Regards,
Vathsa.

Nandan L G

hayajasomwa,
7 Ago 2016, 16:20:0907/08/2016
kwa null-...@googlegroups.com

Thank you all


To unsubscribe from this group and stop receiving emails from it, send an email to null-co-in+unsubscribe@googlegroups.com.

--
______________________________________________________________________________
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
______________________________________________________________________________
se7enth edition of nullcon Goa (Mar 9-12, 2016)
http://nullcon.net
---
You received this message because you are subscribed to the Google Groups "null" group.
To unsubscribe from this group and stop receiving emails from it, send an email to null-co-in+unsubscribe@googlegroups.com.
--
Bharat Razdan
Co-Founder & Author
www.techites.com

Please do not print this email unless it is absolutely necessary. Spread environmental awareness.

--
______________________________________________________________________________
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
______________________________________________________________________________
se7enth edition of nullcon Goa (Mar 9-12, 2016)
http://nullcon.net
---
You received this message because you are subscribed to the Google Groups "null" group.
To unsubscribe from this group and stop receiving emails from it, send an email to null-co-in+unsubscribe@googlegroups.com.

--
______________________________________________________________________________
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
______________________________________________________________________________
se7enth edition of nullcon Goa (Mar 9-12, 2016)
http://nullcon.net
---
You received this message because you are subscribed to the Google Groups "null" group.
To unsubscribe from this group and stop receiving emails from it, send an email to null-co-in+unsubscribe@googlegroups.com.

Ap4Ch3

hayajasomwa,
9 Ago 2016, 03:51:0309/08/2016
kwa null
This seems to work:

In Firefox:

1. Right-click > New Integer (name test.currentTimeOffsetSeconds and value e.g. 11491200 or greater) in about:config.

You may also have to Clear Now the Cache and Active Logins with Time range to clear set to Everything via Tools (Alt + T) > Clear Recent History.


On Monday, 1 August 2016 10:40:57 UTC+5:30, Nandan L G wrote:
Jibu wote
Mjibu mchapishaji
Sambaza
Ujumbe 0 mpya