CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
A penetration tester is using Burp Suite Intruder against a login form and wants to test every combination of a list of 50 usernames against a list of 100 passwords, using two separate payload positions (username and password). Which Intruder attack type will iterate through all possible combinations of both payload sets?
- ASniper
- BCluster bomb
- CBattering ram
- DPitchfork
Show answer & explanationAnswer & explanation
Correct answer: B. Cluster bomb
Cluster bomb uses multiple payload sets and cycles through every possible combination of the positions, making it ideal for testing all username/password pairs (50 x 100 = 5,000 requests). Pitchfork pairs payloads by index in parallel rather than combining all permutations.
Why the other options are wrong
- A. Sniper uses a single payload set applied one position at a time.
- C. Battering ram inserts the same single payload value into all positions simultaneously.
- D. Pitchfork iterates payload lists in parallel (index-matched pairs), not all combinations.
Burp Suite Intruder Attack Types
Burp Intruder offers four attack types that control how payload sets are applied to marked positions in a request.
- Sniper: one payload set, one position at a time
- Pitchfork: multiple sets, synced by index
- Cluster bomb: multiple sets, all combinations tested
Memory trick: Sniper hits one, Ram hits all same, Pitchfork syncs, Bomb explodes all combos