CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing a black-box assessment of a client's web application. They discover a parameter in a URL that appears to control a file download, e.g., `https://example.com/download?file=report.pdf`. They want to test for Local File Inclusion (LFI) vulnerabilities by attempting to access system files like `/etc/passwd`. Which Burp Suite tool is BEST suited for systematically modifying the 'file' parameter with a list of common LFI payloads?

  1. ADecoder
  2. BIntruder
  3. CRepeater
  4. DComparer
Show answer & explanation

Correct answer: B. Intruder

Burp Suite's Intruder tool is ideal for systematically testing a parameter with a list of payloads. It allows the tester to define the injection point (e.g., the 'file' parameter) and then iterate through a wordlist of LFI payloads, observing the responses for successful inclusions.

Why the other options are wrong

  • A. Decoder is for encoding and decoding data, not for automated payload injection.
  • C. Repeater is for sending single, manually modified requests, not for systematically iterating through a list of payloads.
  • D. Comparer is used for comparing two requests or responses, not for generating or injecting payloads.

Burp Suite Intruder (LFI Testing)

Burp Suite Intruder is used to automate the testing of Local File Inclusion (LFI) vulnerabilities by systematically injecting a list of common LFI payloads into a vulnerable parameter and analyzing the server's responses.

  • Automates payload injection into parameters.
  • Supports various attack types (Sniper, Battering Ram, Pitchfork, Cluster Bomb).
  • Essential for brute-forcing, fuzzing, and enumeration, including LFI testing.

Memory trick: Intruder systematically tries to break in with every payload.

More Reconnaissance and Enumeration questions