CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

A penetration tester is using Burp Suite Intruder against a login form and wants to test every combination of a list of 50 usernames against a list of 100 passwords, using two separate payload positions (username and password). Which Intruder attack type will iterate through all possible combinations of both payload sets?

  1. ASniper
  2. BCluster bomb
  3. CBattering ram
  4. DPitchfork
Show answer & explanation

Correct answer: B. Cluster bomb

Cluster bomb uses multiple payload sets and cycles through every possible combination of the positions, making it ideal for testing all username/password pairs (50 x 100 = 5,000 requests). Pitchfork pairs payloads by index in parallel rather than combining all permutations.

Why the other options are wrong

  • A. Sniper uses a single payload set applied one position at a time.
  • C. Battering ram inserts the same single payload value into all positions simultaneously.
  • D. Pitchfork iterates payload lists in parallel (index-matched pairs), not all combinations.

Burp Suite Intruder Attack Types

Burp Intruder offers four attack types that control how payload sets are applied to marked positions in a request.

  • Sniper: one payload set, one position at a time
  • Pitchfork: multiple sets, synced by index
  • Cluster bomb: multiple sets, all combinations tested

Memory trick: Sniper hits one, Ram hits all same, Pitchfork syncs, Bomb explodes all combos

More Vulnerability Discovery and Analysis questions