CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard

A penetration tester is analyzing a web application using Burp Suite and observes that a specific parameter in a GET request, `?id=123`, consistently returns data from a database. When attempting to manipulate this parameter to `?id=123 AND 1=1` and `?id=123 AND 1=2`, the application behaves identically, but when a single quote is introduced, `?id=123'`, the application returns a generic error page. The tester suspects a SQL injection vulnerability. Which of the following Burp Suite tools would be most effective for systematically identifying the specific database type and extracting data?

  1. ABurp Scanner's active scan for SQL injection.
  2. BBurp Sequencer to analyze randomness of session tokens.
  3. CBurp Repeater with manual payload modification.
  4. DBurp Intruder with a 'Sniper' attack type and SQLi payloads.
Show answer & explanation

Correct answer: D. Burp Intruder with a 'Sniper' attack type and SQLi payloads.

Burp Intruder, configured with a 'Sniper' attack type, is ideal for systematically testing a single injection point with a large set of SQL injection payloads. This allows for observing subtle differences in responses (e.g., error messages, content length, timing) that indicate the database type and can be used for data extraction.

Why the other options are wrong

  • A. While Burp Scanner can find SQL injection, Intruder provides more granular control over payloads and response analysis, which is critical for systematic identification and extraction, especially in black-box scenarios.
  • B. Burp Sequencer is used for analyzing the randomness of session tokens or other unpredictable values and is unrelated to SQL injection testing or database extraction.
  • C. Burp Repeater is for manual testing and modification of individual requests, which is inefficient for systematically testing a wide range of SQL injection payloads to identify the database type and extract data.

SQL Injection (SQLi)

A web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database, potentially leading to unauthorized data access, modification, or deletion.

  • Occurs when user-supplied input is insecurely incorporated into SQL queries.
  • Can be detected by injecting special characters (e.g., single quote, double dash).
  • Blind SQLi relies on timing or boolean responses; error-based SQLi returns database errors.

Memory trick: SQLi is like a database whisperer, making it reveal its secrets.

More Vulnerability Discovery and Analysis questions