CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A tester configures Burp Suite Intruder with two payload positions: a username field and a password field. The tester supplies a list of 50 usernames and a list of 100 passwords and wants every possible combination tested. Which Intruder attack type should be selected?

  1. ASniper
  2. BPitchfork
  3. CCluster bomb
  4. DBattering ram
Show answer & explanation

Correct answer: C. Cluster bomb

Cluster bomb tests every combination of multiple payload sets across multiple positions, making it ideal for brute-forcing username/password combinations. Sniper cycles one payload set through positions one at a time, battering ram uses the same payload in all positions simultaneously, and pitchfork iterates payload sets in parallel (same index pairs only).

Why the other options are wrong

  • A. Sniper only uses one payload set at a time in a single position.
  • B. Pitchfork pairs payloads by index (position 1 item 1 with position 2 item 1), not all combinations.
  • D. Battering ram places the identical payload value in all positions simultaneously.

Burp Intruder Attack Types

Burp Suite Intruder offers four attack types (Sniper, Battering ram, Pitchfork, Cluster bomb) that control how payload sets are applied across multiple positions.

  • Cluster bomb = all combinations of multiple payload sets
  • Pitchfork = parallel, index-matched payloads
  • Sniper = single payload set, one position at a time

Memory trick: 'Cluster Bomb explodes into every combination' — think fireworks covering all pairs

More Attacks and Exploits questions