The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Proxy passwords are saved in the clear in config files

Shawn | Last updated: May 26, 2016 10:54PM UTC

This affects both project and user JSON config files. At minimum, documentation warning of this would be good. Better yet, add an option to encrypt or not include them, like the save state file wizard has. If that's too much trouble, I'd prefer simply never saving the passwords.

PortSwigger Agent | Last updated: May 27, 2016 08:27AM UTC