CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is analyzing a web application using Burp Suite. They notice that a specific parameter in a GET request, `?id=123`, seems to be vulnerable to SQL injection. Before proceeding with manual injection, they want to quickly test a range of common SQL injection payloads against this parameter to see how the application responds, without creating a long list of manual requests. Which Burp Suite tool and attack type would be most efficient for this initial automated testing?
- AScanner, running an active scan on the entire request.
- BRepeater, changing the ID value manually for each test.
- CIntruder, using the 'Sniper' attack type on the 'id' parameter.
- DComparer, comparing responses from two different ID values.
Show answer & explanationAnswer & explanation
Correct answer: C. Intruder, using the 'Sniper' attack type on the 'id' parameter.
Burp Suite's Intruder tool, specifically with the 'Sniper' attack type, is designed for exactly this scenario. It takes a single payload set and inserts each payload into a single defined position (the 'id' parameter in this case), allowing for efficient automated testing of various inputs against a specific parameter.
Why the other options are wrong
- A. Scanner runs a comprehensive vulnerability scan, which is broader and potentially noisier than a focused test on a single parameter with specific payloads.
- B. Repeater is for manual modification and re-sending of single requests, not for automated testing of a range of payloads.
- D. Comparer is used to highlight differences between two responses, not for sending multiple payloads or initiating attacks.
Burp Suite Intruder (Sniper Attack)
A Burp Suite Intruder attack type that uses a single payload set and inserts each payload into a single defined insertion point in the base request. Ideal for testing individual parameters for vulnerabilities.
- Uses one payload set.
- One insertion point per request.
- Efficient for testing single parameters.
- Generates a separate request for each payload.
Memory trick: SNIPER Targets One Parameter