daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (32516B)


      1 ---
      2 title: "80,443 - Pentesting Web Methodology"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 80,443 - Pentesting Web Methodology
     14 
     15 ## Basic Info
     16 
     17 Web services are among the most **common and extensive attack surfaces**, and many different vulnerability classes can affect them.
     18 
     19 **Default ports:** 80 (HTTP) and 443 (HTTPS)
     20 
     21 ```bash
     22 PORT    STATE SERVICE
     23 80/tcp  open  http
     24 443/tcp open  ssl/https
     25 ```
     26 
     27 ```bash
     28 nc -v domain.com 80 # GET / HTTP/1.0
     29 openssl s_client -connect domain.com:443 # GET / HTTP/1.0
     30 ```
     31 
     32 ### Web API Guidance
     33 
     34 [Web Api Pentesting](/hacktricks/network-services-pentesting/pentesting-web/web-api-pentesting)
     35 
     36 ## Methodology summary
     37 
     38 > This methodology assumes that you are assessing one domain or subdomain at a time. Apply it to every discovered in-scope domain, subdomain, or IP address that exposes an unidentified web server.
     39 
     40 - [ ] Start by **identifying** the **technologies** used by the web server. Look for **tricks** to keep in mind during the rest of the test if you can successfully identify the tech.
     41   - [ ] Any **known vulnerability** of the version of the technology?
     42   - [ ] Is it using any **well-known technology**? Are there **useful techniques** for extracting more information?
     43   - [ ] Any **specialised scanner** to run (like wpscan)?
     44 - [ ] Launch **general-purpose scanners**. They may identify a vulnerability or provide useful information for manual testing.
     45 - [ ] Start with the **initial checks**: **robots**, **sitemap**, **404** error and **SSL/TLS scan** (if HTTPS).
     46 - [ ] Start **spidering** the web page: It's time to **find** all the possible **files, folders** and **parameters being used.** Also, check for **special findings**.
     47   - [ ] _Note that anytime a new directory is discovered during brute-forcing or spidering, it should be spidered._
     48 - [ ] **Directory Brute-Forcing**: Try to brute force all the discovered folders searching for new **files** and **directories**.
     49   - [ ] _Note that anytime a new directory is discovered during brute-forcing or spidering, it should be Brute-Forced._
     50 - [ ] **Backups checking**: Test if you can find **backups** of **discovered files** appending common backup extensions.
     51 - [ ] **Brute-Force parameters**: Try to **find hidden parameters**.
     52 - [ ] Once you have identified all possible endpoints that accept user input, check them for every relevant vulnerability class.
     53   - [ ] [Follow this checklist](/hacktricks/pentesting-web/web-vulnerabilities-methodology)
     54 
     55 ## Server Version (Vulnerable?)
     56 
     57 ### Identify
     58 
     59 Check if there are **known vulnerabilities** for the server **version** that is running.\
     60 The **HTTP headers and cookies of the response** could be very useful to **identify** the **technologies** and/or **version** being used. **Nmap scan** can identify the server version, but it could also be useful the tools [**whatweb**](https://github.com/urbanadventurer/WhatWeb)**,** [**webtech** ](https://github.com/ShielderSec/webtech)or [**https://builtwith.com/**](https://builtwith.com)**:**
     61 
     62 ```bash
     63 whatweb -a 1 <URL> #Stealthy
     64 whatweb -a 3 <URL> #Aggresive
     65 webtech -u <URL>
     66 webanalyze -host https://google.com -crawl 2
     67 ```
     68 
     69 Search **for** [**vulnerabilities of the web application** **version**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/search-exploits.md)
     70 
     71 ### **Check if any WAF**
     72 
     73 - [**https://github.com/EnableSecurity/wafw00f**](https://github.com/EnableSecurity/wafw00f)
     74 - [**https://github.com/Ekultek/WhatWaf.git**](https://github.com/Ekultek/WhatWaf.git)
     75 - [**https://nmap.org/nsedoc/scripts/http-waf-detect.html**](https://nmap.org/nsedoc/scripts/http-waf-detect.html)
     76 
     77 ### Web tech tricks
     78 
     79 Some **tricks** for **finding vulnerabilities** in different well known **technologies** being used:
     80 
     81 - [**AEM - Adobe Experience Cloud**](/hacktricks/network-services-pentesting/pentesting-web/aem-adobe-experience-cloud)
     82 - [**Apache**](/hacktricks/network-services-pentesting/pentesting-web/apache)
     83 - [**HAProxy / reverse-proxy backdooring (post-compromise)**](/hacktricks/linux-hardening/post-exploitation/linux-post-exploitation/trojanized-system-daemons-and-reverse-proxies)
     84 - [**Artifactory**](/hacktricks/network-services-pentesting/pentesting-web/artifactory-hacking-guide)
     85 - [**Buckets**](buckets/index.html)
     86 - [**CGI**](/hacktricks/network-services-pentesting/pentesting-web/cgi)
     87 - [**Custom UDP RPC Protocols**](/hacktricks/network-services-pentesting/pentesting-web/custom-protocols)
     88 - [**Dotnet SOAP WSDL client exploitation**](/hacktricks/network-services-pentesting/pentesting-web/dotnet-soap-wsdl-client-exploitation)
     89 - [**Drupal**](drupal/index.html)
     90 - [**Flask**](/hacktricks/network-services-pentesting/pentesting-web/flask)
     91 - [**Fortinet FortiWeb**](/hacktricks/network-services-pentesting/pentesting-web/fortinet-fortiweb)
     92 - [**Git**](/hacktricks/network-services-pentesting/pentesting-web/git)
     93 - [**GeoNetwork**](/hacktricks/network-services-pentesting/pentesting-web/geonetwork)
     94 - [**Golang**](/hacktricks/network-services-pentesting/pentesting-web/golang)
     95 - [**GraphQL**](/hacktricks/network-services-pentesting/pentesting-web/graphql)
     96 - [**H2 - Java SQL database**](/hacktricks/network-services-pentesting/pentesting-web/h2-java-sql-database)
     97 - [**ISPConfig**](/hacktricks/network-services-pentesting/pentesting-web/ispconfig)
     98 - [**IIS tricks**](/hacktricks/network-services-pentesting/pentesting-web/iis-internet-information-services)
     99 - [**Microsoft SharePoint**](/hacktricks/network-services-pentesting/pentesting-web/microsoft-sharepoint)
    100 - [**JBOSS**](/hacktricks/network-services-pentesting/pentesting-web/jboss)
    101 - [**Jenkins**](https://github.com/HackTricks-wiki/hacktricks-cloud/tree/master/pentesting-ci-cd/jenkins-security)
    102 - [**Jira**](/hacktricks/network-services-pentesting/pentesting-web/jira)
    103 - [**Joomla**](/hacktricks/network-services-pentesting/pentesting-web/joomla)
    104 - [**JSP**](/hacktricks/network-services-pentesting/pentesting-web/jsp)
    105 - [**Laravel**](/hacktricks/network-services-pentesting/pentesting-web/laravel)
    106 - [**MeshCentral**](/hacktricks/network-services-pentesting/pentesting-web/meshcentral)
    107 - [**Moodle**](/hacktricks/network-services-pentesting/pentesting-web/moodle)
    108 - [**ZoneMinder / motionEye / Motion**](/hacktricks/network-services-pentesting/pentesting-web/zoneminder-motioneye-motion)
    109 - [**Nginx**](/hacktricks/network-services-pentesting/pentesting-web/nginx)
    110 - [**PHP (php has a lot of interesting tricks that could be exploited)**](php-tricks-esp/index.html)
    111 - [**Proxmox VE**](/hacktricks/network-services-pentesting/pentesting-web/proxmox-ve)
    112 - [**Python**](/hacktricks/network-services-pentesting/pentesting-web/python)
    113 - [**Roundcube**](/hacktricks/network-services-pentesting/pentesting-web/roundcube)
    114 - [**ServiceNow**](/hacktricks/network-services-pentesting/pentesting-web/servicenow)
    115 - [**Spring Actuators**](/hacktricks/network-services-pentesting/pentesting-web/spring-actuators)
    116 - [**Symphony**](/hacktricks/network-services-pentesting/pentesting-web/symphony)
    117 - [**Traefik / HTTP/3 slow-body timeouts**](/hacktricks/network-services-pentesting/pentesting-web/traefik)
    118 - [**Tomcat**](tomcat/index.html)
    119 - [**VMWare**](/hacktricks/network-services-pentesting/pentesting-web/vmware-esx-vcenter)
    120 - [**Web API Pentesting**](/hacktricks/network-services-pentesting/pentesting-web/web-api-pentesting)
    121 - [**WebDav**](/hacktricks/network-services-pentesting/pentesting-web/put-method-webdav)
    122 - [**Werkzeug**](/hacktricks/network-services-pentesting/pentesting-web/werkzeug)
    123 - [**Wordpress**](/hacktricks/network-services-pentesting/pentesting-web/wordpress)
    124 - [**Electron Desktop (XSS to RCE)**](electron-desktop-apps/index.html)
    125 - [**Sitecore**](sitecore/index.html)
    126 - [**Zabbix**](/hacktricks/network-services-pentesting/pentesting-web/zabbix)
    127 
    128 _Take into account that the **same domain** can be using **different technologies** in different **ports**, **folders** and **subdomains**._\
    129 If the web application is using any well known **tech/platform listed before** or **any other**, don't forget to **search on the Internet** new tricks (and let me know!).
    130 
    131 ### Source Code Review
    132 
    133 If the application's source code is available on **GitHub**, perform a white-box review and use the following information to improve black-box testing:
    134 
    135 - Is there a **Change-log or Readme or Version** file or anything with **version info accessible** via web?
    136 - How and where are **credentials** stored? Is any accessible file exposing usernames or passwords?
    137 - Are **passwords** in **plain text**, **encrypted** or which **hashing algorithm** is used?
    138 - Is it using any **master key** for encrypting something? Which **algorithm** is used?
    139 - Can you **access any of these files** exploiting some vulnerability?
    140 - Do GitHub issues (open or closed) or the commit history contain useful information, such as a password committed in an older revision?
    141 
    142 [Code Review Tools](/hacktricks/network-services-pentesting/pentesting-web/code-review-tools)
    143 
    144 ### Automatic scanners
    145 
    146 #### General purpose automatic scanners
    147 
    148 ```bash
    149 nikto -h <URL>
    150 whatweb -a 4 <URL>
    151 wapiti -u <URL>
    152 W3af
    153 zaproxy #You can use an API
    154 nuclei -ut && nuclei -target <URL>
    155 
    156 # https://github.com/ignis-sec/puff (client side vulns fuzzer)
    157 node puff.js -w ./wordlist-examples/xss.txt -u "http://www.xssgame.com/f/m4KKGHi2rVUN/?query=FUZZ"
    158 ```
    159 
    160 #### CMS scanners
    161 
    162 If a CMS is used don't forget to **run a scanner**, maybe something juicy is found:
    163 
    164 [**Clusterd**](https://github.com/hatRiot/clusterd)**:** [**JBoss**](/hacktricks/network-services-pentesting/pentesting-web/jboss)**, ColdFusion, WebLogic,** [**Tomcat**](tomcat/index.html)**, Railo, Axis2, Glassfish**\
    165 [**CMSScan**](https://github.com/ajinabraham/CMSScan): [**WordPress**](/hacktricks/network-services-pentesting/pentesting-web/wordpress), [**Drupal**](drupal/index.html), **Joomla**, **vBulletin** websites for Security issues. (GUI)\
    166 [**VulnX**](https://github.com/anouarbensaad/vulnx)**:** [**Joomla**](/hacktricks/network-services-pentesting/pentesting-web/joomla)**,** [**Wordpress**](/hacktricks/network-services-pentesting/pentesting-web/wordpress)**,** [**Drupal**](drupal/index.html)**, PrestaShop, Opencart**\
    167 **CMSMap**: [**(W)ordpress**](/hacktricks/network-services-pentesting/pentesting-web/wordpress)**,** [**(J)oomla**](/hacktricks/network-services-pentesting/pentesting-web/joomla)**,** [**(D)rupal**](drupal/index.html) **or** [**(M)oodle**](/hacktricks/network-services-pentesting/pentesting-web/moodle)\
    168 [**droopscan**](https://github.com/droope/droopescan)**:** [**Drupal**](drupal/index.html)**,** [**Joomla**](/hacktricks/network-services-pentesting/pentesting-web/joomla)**,** [**Moodle**](/hacktricks/network-services-pentesting/pentesting-web/moodle)**, Silverstripe,** [**Wordpress**](/hacktricks/network-services-pentesting/pentesting-web/wordpress)
    169 
    170 ```bash
    171 cmsmap [-f W] -F -d <URL>
    172 wpscan --force update -e --url <URL>
    173 joomscan --ec -u <URL>
    174 joomlavs.rb #https://github.com/rastating/joomlavs
    175 ```
    176 
    177 > At this point you should already have some information of the web server being used by the client (if any data is given) and some tricks to keep in mind during the test. If you are lucky you have even found a CMS and run some scanner.
    178 
    179 ## Step-by-step Web Application Discovery
    180 
    181 > From this point we are going to start interacting with the web application.
    182 
    183 ### Initial checks
    184 
    185 **Default pages with interesting info:**
    186 
    187 - /robots.txt
    188 - /sitemap.xml
    189 - /crossdomain.xml
    190 - /clientaccesspolicy.xml
    191 - /.well-known/
    192 - Check also comments in the main and secondary pages.
    193 
    194 **Forcing errors**
    195 
    196 Web servers may behave unexpectedly when malformed data is sent to them. This may expose vulnerabilities or disclose sensitive information.
    197 
    198 - Access **fake pages** like /whatever_fake.php (.aspx,.html,.etc)
    199 - **Add "[]", "]]", and "[["** in **cookie values** and **parameter** values to create errors
    200 - Generate error by giving input as **`/~randomthing/%s`** at the **end** of **URL**
    201 - Try **different HTTP Verbs** like PATCH, DEBUG or wrong like FAKE
    202 
    203 #### **Check if you can upload files (**[**PUT verb, WebDav**](/hacktricks/network-services-pentesting/pentesting-web/put-method-webdav)**)**
    204 
    205 If you find that **WebDav** is **enabled** but you don't have enough permissions for **uploading files** in the root folder try to:
    206 
    207 - **Brute Force** credentials
    208 - **Upload files** via WebDav to the **rest** of **found folders** inside the web page. You may have permissions to upload files in other folders.
    209 
    210 ### SSL/TLS vulnerabilities
    211 
    212 - If the application does not enforce HTTPS for sensitive functionality, it may be vulnerable to man-in-the-middle attacks.
    213 - If the application is **sending sensitive data (passwords) using HTTP**. Then it's a high vulnerability.
    214 
    215 Use [**testssl.sh**](https://github.com/drwetter/testssl.sh) to check for vulnerabilities and [**a2sv**](https://github.com/hahwul/a2sv) to verify findings. Many bug-bounty programs do not accept low-impact TLS configuration reports:
    216 
    217 ```bash
    218 ./testssl.sh [--htmlfile] 10.10.10.10:443
    219 #Use the --htmlfile to save the output inside an htmlfile also
    220 
    221 # You can also use other tools, by testssl.sh at this momment is the best one (I think)
    222 sslscan <host:port>
    223 sslyze --regular <ip:port>
    224 ```
    225 
    226 Information about SSL/TLS vulnerabilities:
    227 
    228 - [https://www.gracefulsecurity.com/tls-ssl-vulnerabilities/](https://www.gracefulsecurity.com/tls-ssl-vulnerabilities/)
    229 - [https://www.acunetix.com/blog/articles/tls-vulnerabilities-attacks-final-part/](https://www.acunetix.com/blog/articles/tls-vulnerabilities-attacks-final-part/)
    230 
    231 ### Spidering
    232 
    233 Launch a **spider** against the application. Combine crawling with external sources to discover as many valid paths as possible.
    234 
    235 - [**gospider**](https://github.com/jaeles-project/gospider) (go): HTML spider, LinkFinder in JS files and external sources (Archive.org, CommonCrawl.org, VirusTotal.com).
    236 - [**hakrawler**](https://github.com/hakluke/hakrawler) (Go): HTML spider with LinkFinder-style JavaScript discovery and Archive.org as an external source.
    237 - [**dirhunt**](https://github.com/Nekmo/dirhunt) (python): HTML spider, also indicates "juicy files".
    238 - [**evine** ](https://github.com/saeeddhqan/evine)(go): Interactive CLI HTML spider. It also searches in Archive.org
    239 - [**meg**](https://github.com/tomnomnom/meg) (go): This tool isn't a spider but it can be useful. You can just indicate a file with hosts and a file with paths and meg will fetch each path on each host and save the response.
    240 - [**urlgrab**](https://github.com/IAmStoxe/urlgrab) (go): HTML spider with JS rendering capabilities. However, it looks like it's unmaintained, the precompiled version is old and the current code doesn't compile
    241 - [**gau**](https://github.com/lc/gau) (go): HTML spider that uses external providers (wayback, otx, commoncrawl)
    242 - [**ParamSpider**](https://github.com/devanshbatham/ParamSpider): This script will find URLs with parameter and will list them.
    243 - [**galer**](https://github.com/dwisiswant0/galer) (go): HTML spider with JS rendering capabilities.
    244 - [**LinkFinder**](https://github.com/GerbenJavado/LinkFinder) (python): HTML spider, with JS beautify capabilities capable of search new paths in JS files. It could be worth it also take a look to [JSScanner](https://github.com/dark-warlord14/JSScanner), which is a wrapper of LinkFinder.
    245 - [**goLinkFinder**](https://github.com/0xsha/GoLinkFinder) (go): To extract endpoints in both HTML source and embedded javascript files. Useful for bug hunters, red teamers, infosec ninjas.
    246 - [**JSParser**](https://github.com/nahamsec/JSParser) (python2.7): A python 2.7 script using Tornado and JSBeautifier to parse relative URLs from JavaScript files. Useful for easily discovering AJAX requests. Looks like unmaintained.
    247 - [**relative-url-extractor**](https://github.com/jobertabma/relative-url-extractor) (ruby): Given a file (HTML) it will extract URLs from it using nifty regular expression to find and extract the relative URLs from ugly (minify) files.
    248 - [**JSFScan**](https://github.com/KathanP19/JSFScan.sh) (bash, several tools): Gather interesting information from JS files using several tools.
    249 - [**subjs**](https://github.com/lc/subjs) (go): Find JS files.
    250 - [**page-fetch**](https://github.com/detectify/page-fetch) (go): Load a page in a headless browser and print out all the urls loaded to load the page.
    251 - [**Feroxbuster**](https://github.com/epi052/feroxbuster) (rust): Content discovery tool mixing several options of the previous tools
    252 - [**Javascript Parsing**](https://github.com/xnl-h4ck3r/burp-extensions): A Burp extension to find path and params in JS files.
    253 - [**BurpJSLinkFinder Enhanced**](https://github.com/panchocosil/burp-js-linkfinder-enhanced): Burp extension (Jython) that passively analyzes JavaScript responses (by MIME type and `/js` paths) to extract endpoints/links and optionally flag embedded secrets with severity.<sup>[[1]](#references)</sup>
    254 - [**Sourcemapper**](https://github.com/denandz/sourcemapper): Given a `.js.map` URL, retrieves the beautified JavaScript source.
    255 - [**xnLinkFinder**](https://github.com/xnl-h4ck3r/xnLinkFinder): This is a tool used to discover endpoints for a given target.
    256 - [**waymore**](https://github.com/xnl-h4ck3r/waymore)**:** Discover links from the wayback machine (also downloading the responses in the wayback and looking for more links)
    257 - [**HTTPLoot**](https://github.com/redhuntlabs/HTTPLoot) (go): Crawl (even by filling forms) and also find sensitive info using specific regexes.
    258 - [**SpiderSuite**](https://github.com/3nock/SpiderSuite): Spider Suite is an advance multi-feature GUI web security Crawler/Spider designed for cyber security professionals.
    259 - [**jsluice**](https://github.com/BishopFox/jsluice) (go): It's a Go package and [command-line tool](https://github.com/BishopFox/jsluice/blob/main/cmd/jsluice) for extracting URLs, paths, secrets, and other interesting data from JavaScript source code.
    260 - [**ParaForge**](https://github.com/Anof-cyber/ParaForge): A Burp Suite extension that extracts parameters and endpoints from requests to create custom wordlists for fuzzing and enumeration.
    261 - [**katana**](https://github.com/projectdiscovery/katana) (go): Awesome tool for this.
    262 - [**Crawley**](https://github.com/s0rg/crawley) (go): Print every link it's able to find.
    263 
    264 ### Brute Force directories and files
    265 
    266 Start **brute-forcing** from the root folder and be sure to brute-force **all** the **directories found** using **this method** and all the directories **discovered** by the **Spidering** (you can do this brute-forcing **recursively** and appending at the beginning of the used wordlist the names of the found directories).\
    267 Tools:
    268 
    269 - **Dirb** / **Dirbuster** - Included in Kali; old and slow, but functional. They support self-signed certificates and recursive search.
    270 - [**Dirsearch**](https://github.com/maurosoria/dirsearch) (python)**: It doesn't allow auto-signed certificates but** allows recursive search.
    271 - [**Gobuster**](https://github.com/OJ/gobuster) (go): It allows auto-signed certificates, it **doesn't** have **recursive** search.
    272 - [**Feroxbuster**](https://github.com/epi052/feroxbuster) **- Fast, supports recursive search.**
    273 - [**wfuzz**](https://github.com/xmendez/wfuzz) `wfuzz -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt https://domain.com/api/FUZZ`
    274 - [**ffuf** ](https://github.com/ffuf/ffuf)- Fast: `ffuf -c -w /usr/share/wordlists/dirb/big.txt -u http://10.10.10.10/FUZZ`
    275 - [**uro**](https://github.com/s0md3v/uro) (Python): Not a spider; it normalizes a list of discovered URLs and removes functionally duplicated entries.
    276 - [**Scavenger**](https://github.com/0xDexter0us/Scavenger): Burp Extension to create a list of directories from the burp history of different pages
    277 - [**TrashCompactor**](https://github.com/michael1026/trashcompactor): Remove URLs with duplicated functionalities (based on js imports)
    278 - [**Chamaleon**](https://github.com/iustin24/chameleon): It uses wapalyzer to detect used technologies and select the wordlists to use.
    279 
    280 **Recommended dictionaries:**
    281 
    282 - [https://github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/bf_directories.txt](https://github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/bf_directories.txt)
    283 - [**Dirsearch** included dictionary](https://github.com/maurosoria/dirsearch/blob/master/db/dicc.txt)
    284 - [http://gist.github.com/jhaddix/b80ea67d85c13206125806f0828f4d10](http://gist.github.com/jhaddix/b80ea67d85c13206125806f0828f4d10)
    285 - [Assetnote wordlists](https://wordlists.assetnote.io)
    286 - [https://github.com/danielmiessler/SecLists/tree/master/Discovery/Web-Content](https://github.com/danielmiessler/SecLists/tree/master/Discovery/Web-Content)
    287   - raft-large-directories-lowercase.txt
    288   - directory-list-2.3-medium.txt
    289   - RobotsDisallowed/top10000.txt
    290 - [https://github.com/random-robbie/bruteforce-lists](https://github.com/random-robbie/bruteforce-lists)
    291 - [https://github.com/google/fuzzing/tree/master/dictionaries](https://github.com/google/fuzzing/tree/master/dictionaries)
    292 - [https://github.com/six2dez/OneListForAll](https://github.com/six2dez/OneListForAll)
    293 - [https://github.com/ayoubfathi/leaky-paths](https://github.com/ayoubfathi/leaky-paths)
    294 - _/usr/share/wordlists/dirb/common.txt_
    295 - _/usr/share/wordlists/dirb/big.txt_
    296 - _/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt_
    297 
    298 _Note that anytime a new directory is discovered during brute-forcing or spidering, it should be Brute-Forced._
    299 
    300 ### What to check on each file found
    301 
    302 - [**Broken link checker**](https://github.com/stevenvachon/broken-link-checker): Finds broken links in HTML that may be susceptible to takeover.
    303 - **File Backups**: Once you have found all the files, look for backups of all the executable files ("_.php_", "_.aspx_"...). Common variations for naming a backup are: _file.ext\~, #file.ext#, \~file.ext, file.ext.bak, file.ext.tmp, file.ext.old, file.bak, file.tmp and file.old._ You can also use the tool [**bfac**](https://github.com/mazen160/bfac) **or** [**backup-gen**](https://github.com/Nishantbhagat57/backup-gen)**.**
    304 - **Discover new parameters**: You can use tools like [**Arjun**](https://github.com/s0md3v/Arjun)**,** [**parameth**](https://github.com/maK-/parameth)**,** [**x8**](https://github.com/sh1yo/x8) **and** [**Param Miner**](https://github.com/PortSwigger/param-miner) **to discover hidden parameters. If you can, you could try to search** hidden parameters on each executable web file.
    305   - _Arjun all default wordlists:_ [https://github.com/s0md3v/Arjun/tree/master/arjun/db](https://github.com/s0md3v/Arjun/tree/master/arjun/db)
    306   - _Param-miner “params” :_ [https://github.com/PortSwigger/param-miner/blob/master/resources/params](https://github.com/PortSwigger/param-miner/blob/master/resources/params)
    307   - _Assetnote “parameters_top_1m”:_ [https://wordlists.assetnote.io/](https://wordlists.assetnote.io)
    308   - _nullenc0de “params.txt”:_ [https://gist.github.com/nullenc0de/9cb36260207924f8e1787279a05eb773](https://gist.github.com/nullenc0de/9cb36260207924f8e1787279a05eb773)
    309 - **Comments:** Check the comments of all the files, you can find **credentials** or **hidden functionality**.
    310   - If you are playing **CTF**, a "common" trick is to **hide** **information** inside comments at the **right** of the **page** (using **hundreds** of **spaces** so you don't see the data if you open the source code with the browser). Other possibility is to use **several new lines** and **hide information** in a comment at the **bottom** of the web page.
    311 - **API keys**: If you find an API key, use platform-specific guidance and secret-scanning tools such as [**keyhacks**](https://github.com/streaak/keyhacks), [**zile**](https://github.com/xyele/zile.git), [**TruffleHog**](https://github.com/trufflesecurity/truffleHog), [**SecretFinder**](https://github.com/m4ll0k/SecretFinder), [**RegHex**](https://github.com/l4yton/RegHex), [**DumpsterDiver**](https://github.com/securing/DumpsterDiver), and [**EarlyBird**](https://github.com/americanexpress/earlybird).
    312   - Google API keys: If you find any API key looking like **AIza**SyA-qLheq6xjDiEIRisP_ujUseYLQCHUjik you can use the project [**gmapapiscanner**](https://github.com/ozguralp/gmapsapiscanner) to check which apis the key can access.
    313 - **S3 Buckets**: While spidering look if any **subdomain** or any **link** is related with some **S3 bucket**. In that case, [**check** the **permissions** of the bucket](buckets/index.html).
    314 
    315 ### Special findings
    316 
    317 **While** performing the **spidering** and **brute-forcing** you could find **interesting** **things** that you have to **notice**.
    318 
    319 **Interesting files**
    320 
    321 - Look for **links** to other files inside the **CSS** files.
    322 - [If you find an exposed _**.git**_ directory, recover and inspect its repository data](/hacktricks/network-services-pentesting/pentesting-web/git).
    323 - An exposed _**.env**_ file may contain API keys, database passwords, and other secrets.
    324 - If you find **API endpoints** you [should also test them](/hacktricks/network-services-pentesting/pentesting-web/web-api-pentesting). These aren't files, but will probably "look like" them.
    325 - **JS files**: The spidering section lists tools that extract paths from JavaScript. Monitor discovered JavaScript files because a change may introduce vulnerable functionality; [**JSMon**](https://github.com/robre/jsmon) can help.
    326   - You should also check discovered JS files with [**RetireJS**](https://github.com/retirejs/retire.js/) or [**JSHole**](https://github.com/callforpapers-source/jshole) to find if it's vulnerable.
    327   - **Javascript Deobfuscator and Unpacker:** [https://lelinhtinh.github.io/de4js/](https://lelinhtinh.github.io/de4js/), [https://www.dcode.fr/javascript-unobfuscator](https://www.dcode.fr/javascript-unobfuscator)
    328   - **Javascript Beautifier:** [http://jsbeautifier.org/](https://beautifier.io), [http://jsnice.org/](http://jsnice.org)
    329   - **JsFuck deobfuscation** (javascript with chars:"\[]!+" [https://enkhee-osiris.github.io/Decoder-JSFuck/](https://enkhee-osiris.github.io/Decoder-JSFuck/))
    330   - [**TrainFuck**](https://github.com/taco-c/trainfuck)**:** `+72.+29.+7..+3.-67.-12.+55.+24.+3.-6.-8.-67.-23.`
    331   - On several occasions, you will need to **understand the regular expressions** used. This will be useful: [https://regex101.com/](https://regex101.com) or [https://pythonium.net/regex](https://pythonium.net/regex)
    332 - Monitor files where forms were detected; a parameter change or the appearance of a new form may indicate new, potentially vulnerable functionality.
    333 
    334 **403 Forbidden/Basic Authentication/401 Unauthorized (bypass)**
    335 
    336 [403 And 401 Bypasses](/hacktricks/network-services-pentesting/pentesting-web/403-and-401-bypasses)
    337 
    338 **502 Proxy Error**
    339 
    340 A `502` response may indicate a misconfigured reverse proxy. Test whether it improperly accepts an absolute-form request target such as `GET https://google.com HTTP/1.1`; if it fetches the supplied host, investigate the behavior as potential SSRF.
    341 
    342 **NTLM Authentication - Info disclosure**
    343 
    344 If the running server asking for authentication is **Windows** or you find a login asking for your **credentials** (and asking for **domain** **name**), you can provoke an **information disclosure**.\
    345 **Send** the **header**: `“Authorization: NTLM TlRMTVNTUAABAAAAB4IIAAAAAAAAAAAAAAAAAAAAAAA=”` and due to how the **NTLM authentication works**, the server will respond with internal info (IIS version, Windows version...) inside the header "WWW-Authenticate".\
    346 You can **automate** this using the **nmap plugin** "_http-ntlm-info.nse_".
    347 
    348 **HTTP Redirect (CTF)**
    349 
    350 It is possible to **put content** inside a **Redirection**. This content **won't be shown to the user** (as the browser will execute the redirection) but something could be **hidden** in there.
    351 
    352 ### Web Vulnerabilities Checking
    353 
    354 Now that a comprehensive enumeration of the web application has been performed it's time to check for a lot of possible vulnerabilities. You can find the checklist here:
    355 
    356 [Web Vulnerabilities Methodology](/hacktricks/pentesting-web/web-vulnerabilities-methodology)
    357 
    358 Find more info about web vulns in:
    359 
    360 - [https://six2dez.gitbook.io/pentest-book/others/web-checklist](https://six2dez.gitbook.io/pentest-book/others/web-checklist)
    361 - [https://kennel209.gitbooks.io/owasp-testing-guide-v4/content/en/web_application_security_testing/configuration_and_deployment_management_testing.html](https://kennel209.gitbooks.io/owasp-testing-guide-v4/content/en/web_application_security_testing/configuration_and_deployment_management_testing.html)
    362 - [https://owasp-skf.gitbook.io/asvs-write-ups/kbid-111-client-side-template-injection](https://owasp-skf.gitbook.io/asvs-write-ups/kbid-111-client-side-template-injection)<sup>[[2]](#references)</sup>
    363 
    364 ### Monitor Pages for changes
    365 
    366 You can use tools such as [https://github.com/dgtlmoon/changedetection.io](https://github.com/dgtlmoon/changedetection.io) to monitor pages for modifications that might insert vulnerabilities.
    367 
    368 ### HackTricks Automatic Commands
    369 
    370 <details>
    371 <summary>HackTricks Automatic Commands</summary>
    372 
    373 ```yaml
    374 Protocol_Name: Web    #Protocol Abbreviation if there is one.
    375 Port_Number:  80,443     #Comma separated if there is more than one.
    376 Protocol_Description: Web         #Protocol Abbreviation Spelled out
    377 
    378 Entry_1:
    379   Name: Notes
    380   Description: Notes for Web
    381   Note: |
    382     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-web/index.html
    383 
    384 Entry_2:
    385   Name: Quick Web Scan
    386   Description: Nikto and GoBuster
    387   Command: nikto -host {Web_Proto}://{IP}:{Web_Port} &&&& gobuster dir -w {Small_Dirlist} -u {Web_Proto}://{IP}:{Web_Port} && gobuster dir -w {Big_Dirlist} -u {Web_Proto}://{IP}:{Web_Port}
    388 
    389 Entry_3:
    390   Name: Nikto
    391   Description: Basic Site Info via Nikto
    392   Command: nikto -host {Web_Proto}://{IP}:{Web_Port}
    393 
    394 Entry_4:
    395   Name: WhatWeb
    396   Description: General purpose auto scanner
    397   Command: whatweb -a 4 {IP}
    398 
    399 Entry_5:
    400   Name: Directory Brute Force Non-Recursive
    401   Description:  Non-Recursive Directory Brute Force
    402   Command: gobuster dir -w {Big_Dirlist} -u {Web_Proto}://{IP}:{Web_Port}
    403 
    404 Entry_6:
    405   Name: Directory Brute Force Recursive
    406   Description: Recursive Directory Brute Force
    407   Command: python3 {Tool_Dir}dirsearch/dirsearch.py -w {Small_Dirlist} -e php,exe,sh,py,html,pl -f -t 20 -u {Web_Proto}://{IP}:{Web_Port} -r 10
    408 
    409 Entry_7:
    410   Name: Directory Brute Force CGI
    411   Description: Common Gateway Interface Brute Force
    412   Command: gobuster dir -u {Web_Proto}://{IP}:{Web_Port}/ -w /usr/share/seclists/Discovery/Web-Content/CGIs.txt -s 200
    413 
    414 Entry_8:
    415   Name: Nmap Web Vuln Scan
    416   Description: Tailored Nmap Scan for web Vulnerabilities
    417   Command: nmap -vv --reason -Pn -sV -p {Web_Port} --script=`banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)` {IP}
    418 
    419 Entry_9:
    420   Name: Drupal
    421   Description: Drupal Enumeration Notes
    422   Note: |
    423     git clone https://github.com/immunIT/drupwn.git for low hanging fruit and git clone https://github.com/droope/droopescan.git for deeper enumeration
    424 
    425 Entry_10:
    426   Name: WordPress
    427   Description: WordPress Enumeration with WPScan
    428   Command: |
    429     ?What is the location of the wp-login.php? Example: /Yeet/cannon/wp-login.php
    430     wpscan --url {Web_Proto}://{IP}{1} --enumerate ap,at,cb,dbe && wpscan --url {Web_Proto}://{IP}{1} --enumerate u,tt,t,vp --passwords {Big_Passwordlist} -e
    431 
    432 Entry_11:
    433   Name: WordPress Hydra Brute Force
    434   Description: Need User (admin is default)
    435   Command: hydra -l admin -P {Big_Passwordlist} {IP} -V http-form-post '/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log In&testcookie=1:S=Location'
    436 
    437 Entry_12:
    438   Name: Ffuf Vhost
    439   Description: Simple Scan with Ffuf for discovering additional vhosts
    440   Command: ffuf -w {Subdomain_List}:FUZZ -u {Web_Proto}://{Domain_Name} -H "Host:FUZZ.{Domain_Name}" -c -mc all {Ffuf_Filters}
    441 ```
    442 
    443 </details>
    444 
    445 ## References
    446 
    447 - [1] [BurpJSLinkFinder Enhanced](https://github.com/panchocosil/burp-js-linkfinder-enhanced)
    448 - [2] [owasp-skf.gitbook.io - Kbid 111 Client Side Template Injection](https://owasp-skf.gitbook.io/asvs-write-ups/kbid-111-client-side-template-injection)