Using Intruder for brute force

The Intruder component/module within Burp Suite allows a penetration tester to perform online password attacks using the brute force method. Let's attempt to obtain the password to log in to the http://<target ip addr>/mutillidae URL:

  1. Using the Firefox web browser click on Mutillidae II. On Burp Suite, you should see the mutillidae folder appearing under the left pane of the Site map tab.
  2. Next, right-click on the mutillidae folder, and select Add to scope as shown in the following screenshot:
  1. The following Proxy history logging window will appear; simply click on Yes:
  1. To verify our scope has been added ...

Get Learn Kali Linux 2019 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.