CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy
A penetration tester is performing a black-box assessment against a client's web application. They discover a login form and want to test for common username enumeration vulnerabilities. They suspect the application might respond differently if a username exists, even if the password is wrong. Which Burp Suite tool is BEST suited for systematically testing a list of usernames against this login form?
- ARepeater
- BComparer
- CIntruder
- DSequencer
Show answer & explanationAnswer & explanation
Correct answer: C. Intruder
Burp Suite's Intruder tool is specifically designed for automated, customized attacks against web applications, including brute-forcing and enumeration. It allows the tester to define payload positions (e.g., username field) and iterate through a list of values, observing differences in responses.
Why the other options are wrong
- A. Repeater is for manually modifying and re-sending single requests.
- B. Comparer is used to visually compare two requests or responses, not for automated attacks.
- D. Sequencer analyzes the randomness of session tokens.
Burp Suite Intruder
Burp Suite Intruder is a powerful tool for automating customized attacks against web applications, including brute-force attacks, credential stuffing, and enumeration of usernames or parameters.
- Automates sending multiple requests with varying payloads.
- Useful for brute-forcing, enumeration, and fuzzing.
- Allows analysis of response lengths, times, and content.
Memory trick: Intruder systematically tries every possible entry.