We send the Login to the Intruder, change Attack Type to Cluster Bomb and add payloads for username and password, afterwards we can check via Status Code and see one with 302