The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Configure multiple NTLM credentials for the same target?

Hank | Last updated: Jun 08, 2023 02:00AM UTC

Testing an application that uses NTLMv2 auth, Platform authentication works fine to log into it. But I have multiple test accounts I need to switch between. It seems that you can only have one entry for a given destination host; when I Add a new one, it overwrites an existing entry for that host. As a poor workaround, I can configure user-1 as a User setting and user-2 as a Project setting, and then toggle "Override options for this project only" off and on. But that is pretty unintuitive so I expect I'll mess up on occasion, plus, it only gets me two choices, what if I need 4+?

Michelle, PortSwigger Agent | Last updated: Jun 08, 2023 12:08PM UTC

Hi If all 4 sets of credentials are for the same target host, I'm sorry, but there isn't currently a way to add them all at the same time and then enable a single one as needed. This is useful to help keep the list simple and reduce the chances of two sets of credentials being enabled for the same domain, but it does result in the scenario you are seeing. How frequently do you have this scenario where you need to set up multiple sets of credentials for one domain? If you added a new set of credentials for a domain that was already enabled, which set of credentials would you expect to remain enabled as you add the new set, the existing set or the new set?

Hank | Last updated: Jun 09, 2023 12:49AM UTC

This might be the first time this has come up for me :) But I think it's going to come up like a half dozen times over the next couple months, as I test a bunch of SSO-tied-to-AD-enabled webapps, where I need to switch between multiple differently-privileged accounts to test different business logic enforcement, etc. Another bad idea I had was to run multiple copies of Burp simultaneously, on different local listeners, with different browsers pointing at each, and each with different platform creds configured. This would probably work but... oy.

Michelle, PortSwigger Agent | Last updated: Jun 09, 2023 07:52AM UTC