Burp community forum

Burp Enterprise unattended install -- what is the administrator password?

John | Last updated: Sep 13, 2019 11:04PM UTC

When doing an unattended install from a response file generated by a previous install, e.g. `./burpsuite_enterprise_linux_v1_1_02.sh -q -varfile response.varfile`, what's the administrator password set to? The password from the previous installation is not saved to response.varfile.

Mike, PortSwigger Agent | Last updated: Sep 16, 2019 09:39AM UTC

Hi, when you install Burp Suite Enterprise you are required to specify the credentials for the administrator account, we don't have any default values for this. You can create a new administrator by running a utility that should be in the installation directory called ‘adminusercreator’. An example of how to run it is: adminusercreator —username=new_admin —password=letmein —email=some@example.com —dbUrl=jdbc:<your database url> —dbUsername=burp_enterprise —dbPassword=*

Burp User | Last updated: Sep 16, 2019 03:16PM UTC

What's the dbUrl format if you chose the file-based internal database?

Mike, PortSwigger Agent | Last updated: Sep 16, 2019 03:24PM UTC

Hi John, glad I could help and thank you for sharing your solution.

Burp User | Last updated: Sep 16, 2019 03:39PM UTC

Figured it out, I had to stop the burpsuiteenterpriseedition_db service then use: adminusercreator --username=administrator --password=newpassword --email=security@example.com --dbUrl=jdbc:h2:/var/lib/BurpSuiteEnterpriseEdition/data/burpsuiteenterpriseedition_db --dbUsername=burp_enterprise --dbPassword=[redacted] (where dbPassword was found in /opt/burpsuite_enterprise/database/init.sql) Thanks

Jay | Last updated: Feb 14, 2020 07:49PM UTC

With burpsuite_enterprise_linux_v2020_1.sh I am not getting prompted to enter credentials for the administrator account. And when I attempt to run: /opt/burpsuite_enterprise/adminusercreator —username=administrator —password=letmein —email=email@company.com —dbUrl=jdbc:dbaname:3306/burpenterprise —dbUsername=xxxxx —dbPassword=xxxxx I get a "password is mandatory" response.

Ben, PortSwigger Agent | Last updated: Feb 18, 2020 10:19AM UTC

Hi Jay, Are you using two hyphen characters when specifying each parameter (the formatting on your post suggests you are using the — character)?

You need to Log in to post a reply. Or register here, for free.