CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

A penetration tester is performing a black-box assessment against a client's web application. They discover a login form and want to test for common username enumeration vulnerabilities. They suspect the application might respond differently if a username exists, even if the password is wrong. Which Burp Suite tool is BEST suited for systematically testing a list of usernames against this login form?

  1. ARepeater
  2. BComparer
  3. CIntruder
  4. DSequencer
Show answer & explanation

Correct answer: C. Intruder

Burp Suite's Intruder tool is specifically designed for automated, customized attacks against web applications, including brute-forcing and enumeration. It allows the tester to define payload positions (e.g., username field) and iterate through a list of values, observing differences in responses.

Why the other options are wrong

  • A. Repeater is for manually modifying and re-sending single requests.
  • B. Comparer is used to visually compare two requests or responses, not for automated attacks.
  • D. Sequencer analyzes the randomness of session tokens.

Burp Suite Intruder

Burp Suite Intruder is a powerful tool for automating customized attacks against web applications, including brute-force attacks, credential stuffing, and enumeration of usernames or parameters.

  • Automates sending multiple requests with varying payloads.
  • Useful for brute-forcing, enumeration, and fuzzing.
  • Allows analysis of response lengths, times, and content.

Memory trick: Intruder systematically tries every possible entry.

More Reconnaissance and Enumeration questions