The Burp Suite User Forum will be discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Centre. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTRE DISCORD

Create new post

Getting Inconsistent Results when running Lab: Username enumeration via different responses

Pamela | Last updated: Sep 17, 2024 04:16PM UTC

Hi team, I am running the Authentication Lab with Burp Suite inside Kali Linux on top of Virtual Box and when I open Burp I use the built-in Chromium browser.Wwhen I run the intruder attack using Sniper, Single List. When I get the Username payload, I am able to successfully get the Username. I enter it inside the Request, change positions, and then I add the new payload for the Passwords and run the attack again. I then successfully get the Password but when I enter my newfound Username and Password combo, I fail and cannot access the account. I'm not sure what I am doing wrong. I have tried this multiple times. What I am wondering about is the randomness of the Username because the Username payload results in a brand new Username with every intruder attack I run. Does the Username randomly change when running the Password payloads attack? I have also followed the Solution you have provided. Your labs are excellent and I am sure I am doing something wrong but I don't know what to do next. If someone can help, I would be very grateful. Thank you, Pamela Dean

Ben, PortSwigger Agent | Last updated: Sep 18, 2024 06:34AM UTC

Hi Pamela, Are you able to provide us with any screenshots of the attack that you have configured and the results that you are seeing? If it is easier to do this via email (you cannot attach files to a forum post) then please feel free to send us an email at support@portswigger.net and we can take a look from there. The username and password are randomly generated for each lab instance but should remain the same throughout the duration of a particular instance (if the lab URL changes then that indicates a new lab instance has been created).

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.