Categories: General

Some Thoughts on the Future of IT

Some Thoughts on the Future of IT 1Some Thoughts on the Future of IT 1

If you use Burp a good bit you’ve likely run into the question of what
precisely the various Intruder Payload Methods do. Specifically, what are
the differences between them? To refresh the memory, they are Sniper,
Battering Ram, Pitchfork, and Cluster Bomb.

The manual has good explanations, but somehow nobody remembers them. So
here’s my own quick summary of the functionality.

Sniper

  • Payloads: One

  • Summary: One of the marked parameters tested at a time, with one of the
    payload items.

  • Common Use Cases: Individual field tests for a specific vulnerability,
    hit a password field for a known username with a guessing attack.

Battering Ram

  • Payloads: One

  • Summary: All marked parameters tested at the same time, using one of the
    payload items.

  • Common Use Cases: Request requires value to be in multiple fields
    simultaneously, e.g. username.

Pitchfork

  • Payloads: One for each parameter (up to 8)

  • Summary: Hits each parameter at the same time with one item from its
    associated payload.

  • Common Use Cases: Request requires value to be in multiple fields
    simultaneously, but different for each parameter.

Cluster Bomb

  • Payloads: One for each parameter (up to 8)

  • Summary: Combination of all payloads vs. parameters, so if there’s a
    username field and a password field, each has its own payload list, and
    the requests look like payloaduser1:payloadpass1,
    payloaduser1:payloadpass2, payloaduser1:payloadpass3,
    payloaduser2:payloadpass1, payloaduser2:payloadpass2,
    payloaduser2:payloadpass3.

  • Common Use Cases: Guess username/password combinations looking for clues
    in response codes, response lengths, etc.

Gerald Businge

Leave a Comment
Share
Published by
Gerald Businge

Recent Posts

Betrayal in the City by Francis Imbuga

1. Introduction to the Text Title: Betrayal in the City Author: Francis Imbuga (Kenya) Genre:…

2 months ago

The Moon also sets by Osi Ogbu

Brief Context Author & Publication: Written by Nigerian author Osita (Osi) Ogbu, the novel was…

2 months ago

Meet Musinguzi John Paul – Your AI Teacher of Christian Religious Education for O-Level in Uganda

Step into a deeper understanding of faith, values, and biblical truth with Musinguzi John Paul,…

3 months ago

Meet Mbabazi Bridget – Your AI Teacher of Entrepreneurship for O-Level in Uganda

Are you ready to unlock your business potential and become a future innovator, job creator,…

3 months ago

Meet Alinda Violet – Your AI Agriculture Teacher for O-Level in Uganda!

Step into the future of farming, food security, and environmental stewardship with Alinda Violet, your…

3 months ago

Meet Aheebwa Joseph – Your AI Mathematics Teacher for O-Level Uganda!

Welcome to the world of numbers, logic, and problem-solving with Aheebwa Joseph, your intelligent and…

3 months ago