CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing reconnaissance against a client's web application. They discover a login form and suspect it might be vulnerable to username enumeration. They want to systematically test common usernames against the form to see if the application responds differently to valid versus invalid usernames. Which Burp Suite tool is best suited for this task?
- ABurp Repeater
- BBurp Sequencer
- CBurp Intruder
- DBurp Decoder
Show answer & explanationAnswer & explanation
Correct answer: C. Burp Intruder
Burp Intruder is specifically designed for automating repetitive tasks, such as iterating through a list of payloads (like usernames) and analyzing the application's responses. This makes it ideal for username enumeration attacks.
Why the other options are wrong
- A. Burp Repeater is used for manually modifying and re-issuing individual HTTP requests, not for automated, systematic testing with multiple payloads.
- B. Burp Sequencer is used for analyzing the randomness of session tokens or other 'unpredictable' data items, not for enumerating usernames.
- D. Burp Decoder is used for manual or intelligent decoding/encoding of data, not for automated payload injection and response analysis.
Burp Intruder
Burp Intruder is a powerful tool within Burp Suite used for automating customized attacks against web applications, such as brute-force attacks, dictionary attacks, and username enumeration.
- Automates repetitive requests
- Supports various attack types (e.g., Sniper, Battering Ram)
- Analyzes response differences for enumeration/vulnerability discovery
Memory trick: Intruder is the Bouncer for Bad Username Lists.