CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing a black-box assessment against a client's web application. They suspect the application might be vulnerable to directory traversal. Which Burp Suite tool would be most effective for systematically testing various directory traversal payloads in URL parameters?
- AComparer
- BIntruder
- CRepeater
- DSequencer
Show answer & explanationAnswer & explanation
Correct answer: B. Intruder
Burp Suite's Intruder tool is designed for automated, systematic attacks with customizable payloads and attack types, making it ideal for testing directory traversal vulnerabilities by injecting various payloads into parameters.
Why the other options are wrong
- A. Comparer performs a visual diff between two requests or responses, which is not for active vulnerability testing.
- C. Repeater is used for manually modifying and re-issuing individual requests, not for systematic payload injection.
- D. Sequencer analyzes the randomness of session tokens and other unpredictable data, which is unrelated to directory traversal.
Burp Suite Intruder
A Burp Suite tool for automating customized attacks against web applications, often used for brute-forcing, fuzzing, and testing for vulnerabilities like directory traversal.
- Automated payload injection.
- Customizable attack types (e.g., Sniper, Battering Ram).
- Useful for fuzzing and brute-force attacks.
Memory trick: Intruders like to inject bad payloads into your web apps.