The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Getting Inconsistent Results when running Lab: Username enumeration via different responses

Pamela | Last updated: Sep 17, 2024 04:16PM UTC

Hi team, I am running the Authentication Lab with Burp Suite inside Kali Linux on top of Virtual Box and when I open Burp I use the built-in Chromium browser.Wwhen I run the intruder attack using Sniper, Single List. When I get the Username payload, I am able to successfully get the Username. I enter it inside the Request, change positions, and then I add the new payload for the Passwords and run the attack again. I then successfully get the Password but when I enter my newfound Username and Password combo, I fail and cannot access the account. I'm not sure what I am doing wrong. I have tried this multiple times. What I am wondering about is the randomness of the Username because the Username payload results in a brand new Username with every intruder attack I run. Does the Username randomly change when running the Password payloads attack? I have also followed the Solution you have provided. Your labs are excellent and I am sure I am doing something wrong but I don't know what to do next. If someone can help, I would be very grateful. Thank you, Pamela Dean

Ben, PortSwigger Agent | Last updated: Sep 18, 2024 06:34AM UTC