The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Finding Sensitive API Keys

D | Last updated: Oct 28, 2022 07:38PM UTC

Dear all, I have just started using the burp suite and bug hunting in general. While reviewing a site, I noticed that some API keys, including NREUM and Bootstrap are exposed. I am trying to find vulnerabilities and could use some guidance. How do I know if this exposed information is critical enough to report (Any suggestions on general API testing would help) and how I should go about assessing what I've found? Thank you in advance.

Ben, PortSwigger Agent | Last updated: Nov 01, 2022 08:34AM UTC