Burp Suite User Forum

Create new post

Finding Sensitive API Keys

D | Last updated: Oct 28, 2022 07:38PM UTC

Dear all, I have just started using the burp suite and bug hunting in general. While reviewing a site, I noticed that some API keys, including NREUM and Bootstrap are exposed. I am trying to find vulnerabilities and could use some guidance. How do I know if this exposed information is critical enough to report (Any suggestions on general API testing would help) and how I should go about assessing what I've found? Thank you in advance.

Ben, PortSwigger Agent | Last updated: Nov 01, 2022 08:34AM UTC

Hi, Assisting users with specific guidance on testing is slightly beyond the level of support that we can provide here - having said that, the following blog posts seem a good place to start with this domain: https://www.mindpointgroup.com/blog/rest-assured-penetration-testing-rest-apis-using-burp-suite-part-1-introduction-configuration https://labs.detectify.com/2021/08/10/how-to-hack-apis-in-2021/ We will also leave this forum post up in case any other users have some further suggestions for you.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.