CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing a black-box assessment against a client's web application. They notice that requests to a specific API endpoint return different error messages depending on the length of the input string in a particular parameter. Which Burp Suite tool would be most effective for systematically testing various input lengths and observing the responses?

  1. ABurp Repeater
  2. BBurp Sequencer
  3. CBurp Intruder
  4. DBurp Scanner
Show answer & explanation

Correct answer: C. Burp Intruder

Burp Intruder is designed for automating customized attacks against web applications, including fuzzing parameters with different payloads like varying lengths of input strings, and then analyzing the responses for differences.

Why the other options are wrong

  • A. Repeater is for manually modifying and reissuing single requests, not for systematic fuzzing.
  • B. Sequencer analyzes the randomness of session tokens or other data items.
  • D. Scanner is for automated vulnerability detection, not for targeted, systematic parameter fuzzing based on observed behavior.

Burp Suite Intruder

A Burp Suite tool used for automating customized attacks against web applications. It can fuzz parameters, brute-force credentials, and test for various vulnerabilities by systematically sending altered requests.

  • Automates sending multiple requests with varied payloads.
  • Useful for fuzzing, brute-forcing, and enumeration.
  • Analyzes response lengths, status codes, and content for differences.
  • Supports various payload types and attack configurations.

Memory trick: Burp's tools dissect web traffic.

More Reconnaissance and Enumeration questions