Burp Suite User Forum

Create new post

Burp Storing Credentials

Aleksejs | Last updated: Jan 11, 2022 01:06PM UTC

Hi! Burp has 2 options using credentials : hardcoding and recording, in both cases burp stores credentials somewhere. I want to know how using BurpSuite Api Interfaces i can get them. If it`s possible ? I need this for automation

Michelle, PortSwigger Agent | Last updated: Jan 11, 2022 03:18PM UTC

Thanks for your message. Can you tell us more about your use case, please? If you'd rather share this directly with us then feel free to email support@portswigger.net. Are you using Burp Suite Professional or Burp Suite Enterprise? The application login and recorded login sequences are generally provided and used during a specific scan and so would generally need to be passed to a scan configuration rather than retrieved from one, can you provide some more detail around the tasks you are trying to carry out, please?

Aleksejs | Last updated: Jan 11, 2022 07:36PM UTC

I use Burp Enterprize and use hardcoded credentials ( not using script ). So Burp sends hardcoded credentials saved under named label (our login and pass) to all forms with 2 fields automatically. But i want to send prepared build requests with login and pass to various forms on certain urls , and login and pass should be different. I could send it storing login and pass in my code, but it`s less secure than in case i pull it via yours api

Michelle, PortSwigger Agent | Last updated: Jan 12, 2022 11:34AM UTC

Thanks for the update. Do you have the sites for these already configured within Enterprise with the application logins saved with each site?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.