Burp Suite Community edition – Intruder

Friday, August 12th, 2022

If you accidentally dabble with a PEN-200 course, there is an introduction to the Burp Suite Intruder feature with a lot of meat on the bones.

Alas, since the course was created, Burp Suite released a newer version with a re-defined interface (covered by Burp Suite course on Pluralsight) but it’s still possible to piece together the required components to follow the course content.

Until…. everything is set as described and you click on “Start Attack” and you get this pop-up:

Is this another “feature” of the community edition to push you towards purchasing the Pro version of Burp Suite?

Well, it might be. But you don’t have to shell out the cash quite yet.

Head over to the Resource Pool tab and you’ll see:

In fact, what you’ll have to do is this:

And obviously select this added option, then start the attack. It will obviously be slower but this chapter in the course is about the principle, not about brute-forcing cracking real passwords.