CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
During a web application test, a tester intercepts a funds-transfer request in Burp Suite and wants to manually resend the request multiple times, tweaking the transfer amount and account number each time while carefully reviewing each individual response for business logic flaws. Which Burp Suite tool is best suited for this task?
- ARepeater
- BIntruder
- CDecoder
- DSequencer
Show answer & explanationAnswer & explanation
Correct answer: A. Repeater
Repeater lets a tester manually modify and resend individual HTTP requests one at a time, making it ideal for exploratory business-logic testing where each response needs careful review. Intruder is for automated bulk payload fuzzing, Sequencer analyzes token randomness, and Decoder encodes/decodes data.
Why the other options are wrong
- B. Intruder automates sending many payloads rapidly, not suited for careful manual one-off review.
- C. Decoder transforms data formats like Base64/URL encoding, not for sending requests.
- D. Sequencer analyzes the randomness/entropy of session tokens, unrelated to this task.
Burp Suite Repeater
A Burp Suite tool that allows testers to manually modify and resend individual HTTP requests, viewing the server's response for each iteration.
- Ideal for manual business logic and parameter tampering tests
- Unlike Intruder, sends one request at a time under tester control
- Commonly used to test IDOR, privilege escalation, and workflow bypasses
Memory trick: Repeater = Repeat one shot, review it closely