CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is analyzing a web application using Burp Suite. They notice that a specific parameter, 'itemID', appears to be susceptible to SQL injection. To systematically test for various SQL injection payloads and observe the application's responses, which Burp Suite tool is most appropriate for automating this process?

  1. AIntruder
  2. BProxy
  3. CSequencer
  4. DRepeater
Show answer & explanation

Correct answer: A. Intruder

Burp Suite's Intruder tool is specifically designed for automated, customized attacks against web applications. It allows testers to define insertion points for payloads and then iterate through a list of payloads, making it ideal for systematically testing for vulnerabilities like SQL injection.

Why the other options are wrong

  • B. The Proxy intercepts and modifies individual requests, not for automated, systematic payload testing.
  • C. Sequencer is used for analyzing the randomness of session tokens, not for payload-based vulnerability testing.
  • D. Repeater allows manual modification and re-sending of single requests, not for automated iteration over payload lists.

Burp Suite Intruder

A Burp Suite tool used for automating customized attacks against web applications. It allows a penetration tester to define insertion points in an HTTP request and then iterate through a list of payloads at those points, observing the application's responses.

  • Automates customized attacks.
  • Supports various attack types (Sniper, Battering Ram, Pitchfork, Cluster Bomb).
  • Ideal for brute-forcing, fuzzing, and testing for injection vulnerabilities.
  • Analyzes responses for anomalies or success indicators.

Memory trick: Intruder intrudes with many payloads, like a systematic fuzzer.

More Reconnaissance and Enumeration questions