CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester is analyzing a web server and observes that it responds differently to HTTP requests based on the `User-Agent` header. Specifically, requests with a mobile `User-Agent` receive a simplified page, while desktop `User-Agent` requests receive the full site. To effectively enumerate all possible content and functionality, the tester needs to systematically test the application with various `User-Agent` strings. Which Burp Suite tool is best suited for this automated, iterative testing?
- ARepeater
- BIntruder
- CSequencer
- DComparer
Show answer & explanationAnswer & explanation
Correct answer: B. Intruder
Burp Intruder is designed for automated, customized attacks against web applications. It allows a tester to define 'payload positions' within a request and iterate through a list of payloads (e.g., different User-Agent strings), observing and analyzing the responses. This perfectly matches the requirement for systematic, iterative testing with various User-Agent strings.
Why the other options are wrong
- A. Repeater allows manual modification and re-sending of a single request, not automated iterative testing with multiple payloads.
- C. Sequencer is used for analyzing the randomness of session tokens or other 'unpredictable' data items, not for iterating through different HTTP headers.
- D. Comparer is used to perform a visual diff between two requests or responses, not for automated testing with varied inputs.
Burp Intruder
Burp Intruder is a powerful tool for automating customized attacks against web applications, such as brute-forcing, fuzzing, and enumerating data by iterating through various payloads.
- Allows defining 'payload positions' within an HTTP request.
- Supports various attack types (e.g., Sniper, Battering Ram, Pitchfork).
- Useful for testing input validation, authentication, and enumeration.
Memory trick: Burp: Intruder attacks, Repeater manual, Sequencer tokens, Comparer diff.