Python2中urllib2通过Burp代理绕过SSL证书验证失败求助
I’ve run into this exact headache before when routing Python 2 traffic through Burp, so let’s walk through the correct way to get this working—no more CERTIFICATE_VERIFY_FAILED errors, and your requests will show up in Burp as expected.
The core issue with your current code is that you’re assigning the SSL context directly to the opener, but urllib2 doesn’t actually use that property. You need to attach a custom HTTPSHandler that explicitly uses your unverified (or Burp CA-trusted) context instead.
Step 1: Set up the SSL context and handlers properly
Here’s the corrected code that will route traffic through Burp and skip certificate verification (since Burp’s CA isn’t trusted by Python 2 by default):
import ssl import urllib2 # Define your Burp proxy details proxy = {'http': '127.0.0.1:8081', 'https': '127.0.0.1:8081'} proxy_handler = urllib2.ProxyHandler(proxy) # Create an unverified SSL context (skips certificate checks) context = ssl._create_unverified_context() # Attach the context to an HTTPS handler—this is the key step you missed https_handler = urllib2.HTTPSHandler(context=context) # Build the opener with both proxy and HTTPS handlers opener = urllib2.build_opener(proxy_handler, https_handler) # Install the opener so all urllib2 requests use it urllib2.install_opener(opener) # Test the request try: url_request = urllib2.Request("https://example.com") response = opener.open(url_request) print(response.read()) except urllib2.URLError as e: print(f"Error: {e}")
Why your previous attempts didn’t work
- Assigning
opener.context = contextdoes nothing—urllib2’s opener doesn’t look for this property. The SSL context has to be passed directly to theHTTPSHandler. - While
ssl.create_default_context()withCERT_NONEworks in Python 3, Python 2 relies onssl._create_unverified_context()for this use case. - Adding Burp’s CA to system trust stores often won’t work for Python 2, since it typically uses its own bundled certificate store instead of the system’s.
More secure alternative: Trust Burp’s CA explicitly
If you don’t want to disable all certificate checks, you can configure Python to trust Burp’s CA specifically:
- Export Burp’s CA certificate in PEM format (Burp → Proxy → Options → Import/Export CA Certificate → Export Certificate in PEM Format).
- Use this code to load the CA and verify requests against it:
import ssl import urllib2 # Path to your exported Burp CA PEM file burp_ca_path = "/path/to/burp_ca.pem" # Create a context that trusts Burp's CA context = ssl.create_default_context(cafile=burp_ca_path) context.check_hostname = False # Optional, if you hit hostname mismatch issues # Set up proxy and handlers proxy_handler = urllib2.ProxyHandler({'http': '127.0.0.1:8081', 'https': '127.0.0.1:8081'}) https_handler = urllib2.HTTPSHandler(context=context) opener = urllib2.build_opener(proxy_handler, https_handler) urllib2.install_opener(opener) # Test the request response = opener.open("https://example.com") print(response.read())
内容的提问来源于stack exchange,提问作者SilverlightFox

