Hacking APIs: Difference between revisions

From Enlace Hacktivista
Jump to navigation Jump to search
mNo edit summary
Line 21: Line 21:


=== Wordlists ===
=== Wordlists ===
* Kiterunner is a contexual content discovery tool built by Assetnote built for testing APIs. You can use the .kite files with the Kiterunner tool. Additionally, the swagger-wordlist.txt dataset can be used with traditional content discovery tools: https://wordlists.assetnote.io
* Web API specific wordlists - See [https://enlacehacktivista.org/index.php?title=Scanning_and_Recon#Fuzzing Fuzzing]:
# https://wordlists-cdn.assetnote.io/rawdata/kiterunner/routes-large.json.tar.gz
# https://wordlists-cdn.assetnote.io/data/kiterunner/routes-large.kite.tar.gz
# https://wordlists-cdn.assetnote.io/rawdata/kiterunner/routes-small.json.tar.gz
# https://wordlists-cdn.assetnote.io/data/kiterunner/routes-small.kite.tar.gz
# https://wordlists-cdn.assetnote.io/rawdata/kiterunner/swagger-files.tar
# https://wordlists-cdn.assetnote.io/data/kiterunner/swagger-wordlist.txt
* https://wordlists.assetnote.io


== Intercepting proxies ==
== Intercepting proxies ==

Revision as of 17:07, 7 August 2023

Labs

Prerequisite reading

Tools

Wordlists

  • Web API specific wordlists - See Fuzzing:
  1. https://wordlists-cdn.assetnote.io/rawdata/kiterunner/routes-large.json.tar.gz
  2. https://wordlists-cdn.assetnote.io/data/kiterunner/routes-large.kite.tar.gz
  3. https://wordlists-cdn.assetnote.io/rawdata/kiterunner/routes-small.json.tar.gz
  4. https://wordlists-cdn.assetnote.io/data/kiterunner/routes-small.kite.tar.gz
  5. https://wordlists-cdn.assetnote.io/rawdata/kiterunner/swagger-files.tar
  6. https://wordlists-cdn.assetnote.io/data/kiterunner/swagger-wordlist.txt

Intercepting proxies

These let you view, edit, and replay requests, and are extremely useful for finding vulnerabilities in web, mobile and API applications.