CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

During a penetration test, a web application is discovered to be running on an unusual port, 8443, and appears to be a custom-developed application. The tester needs to thoroughly analyze the traffic and identify potential vulnerabilities. Which tool is best suited for intercepting, modifying, and replaying HTTP/HTTPS requests to this application?

  1. AWireshark
  2. BBurp Suite
  3. CNmap
  4. DMetasploit Framework
Show answer & explanation

Correct answer: B. Burp Suite

Burp Suite is a leading web application security testing tool designed to intercept, analyze, and manipulate HTTP/HTTPS traffic. Its proxy functionality and suite of tools are ideal for in-depth web application analysis.

Why the other options are wrong

  • A. Wireshark is a packet capture and analysis tool, useful for viewing traffic but not for actively modifying or replaying requests in an attack context.
  • C. Nmap is for network scanning and host discovery, not for web application traffic manipulation.
  • D. Metasploit Framework is for exploit development and execution, not primarily for web traffic interception and modification.

Burp Suite for Web Testing

Burp Suite is an integrated platform for performing security testing of web applications, offering a proxy, scanner, intruder, repeater, and more.

  • Intercepts HTTP/HTTPS traffic between browser and web server.
  • Allows modification and replaying of requests.
  • Includes tools for scanning, fuzzing, and brute-forcing web applications.

Memory trick: Web tools: Burp for proxy, Nmap for scan, Metasploit for exploit, Wireshark for sniff.

More Reconnaissance and Enumeration questions