CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is analyzing a web application using Burp Suite. They notice that a specific parameter in a GET request, `?id=123`, seems to be vulnerable to SQL injection. Before proceeding with manual injection, they want to quickly test a range of common SQL injection payloads against this parameter to see how the application responds, without creating a long list of manual requests. Which Burp Suite tool and attack type would be most efficient for this initial automated testing?

  1. AScanner, running an active scan on the entire request.
  2. BRepeater, changing the ID value manually for each test.
  3. CIntruder, using the 'Sniper' attack type on the 'id' parameter.
  4. DComparer, comparing responses from two different ID values.
Show answer & explanation

Correct answer: C. Intruder, using the 'Sniper' attack type on the 'id' parameter.

Burp Suite's Intruder tool, specifically with the 'Sniper' attack type, is designed for exactly this scenario. It takes a single payload set and inserts each payload into a single defined position (the 'id' parameter in this case), allowing for efficient automated testing of various inputs against a specific parameter.

Why the other options are wrong

  • A. Scanner runs a comprehensive vulnerability scan, which is broader and potentially noisier than a focused test on a single parameter with specific payloads.
  • B. Repeater is for manual modification and re-sending of single requests, not for automated testing of a range of payloads.
  • D. Comparer is used to highlight differences between two responses, not for sending multiple payloads or initiating attacks.

Burp Suite Intruder (Sniper Attack)

A Burp Suite Intruder attack type that uses a single payload set and inserts each payload into a single defined insertion point in the base request. Ideal for testing individual parameters for vulnerabilities.

  • Uses one payload set.
  • One insertion point per request.
  • Efficient for testing single parameters.
  • Generates a separate request for each payload.

Memory trick: SNIPER Targets One Parameter

More Reconnaissance and Enumeration questions