The Intruder component/module within Burp Suite allows a penetration tester to perform online password attacks using the brute force method. Let's attempt to obtain the password to log in to the http://<target ip addr>/mutillidae URL:
- Using the Firefox web browser click on Mutillidae II. On Burp Suite, you should see the mutillidae folder appearing under the left pane of the Site map tab.
- Next, right-click on the mutillidae folder, and select Add to scope as shown in the following screenshot:
- The following Proxy history logging window will appear; simply click on Yes:
- To verify our scope has been added ...