index.md (2746B)
1 --- 2 title: "HTTP Hidden Parameters" 3 topic: "Hidden Parameters" 4 topicSlug: "hidden-parameters" 5 sourcePath: "Hidden Parameters/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Hidden%20Parameters/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # HTTP Hidden Parameters 12 13 > Web applications often have hidden or undocumented parameters that are not exposed in the user interface. Fuzzing can help discover these parameters, which might be vulnerable to various attacks. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [Bruteforce Parameters](#bruteforce-parameters) 20 * [Old Parameters](#old-parameters) 21 * [References](#references) 22 23 ## Tools 24 25 * [PortSwigger/param-miner](https://github.com/PortSwigger/param-miner) - Burp extension to identify hidden, unlinked parameters. 26 * [s0md3v/Arjun](https://github.com/s0md3v/Arjun) - HTTP parameter discovery suite 27 * [Sh1Yo/x8](https://github.com/Sh1Yo/x8) - Hidden parameters discovery suite 28 * [tomnomnom/waybackurls](https://github.com/tomnomnom/waybackurls) - Fetch all the URLs that the Wayback Machine knows about for a domain 29 * [devanshbatham/ParamSpider](https://github.com/devanshbatham/ParamSpider) - Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing 30 31 ## Methodology 32 33 ### Bruteforce Parameters 34 35 * Use wordlists of common parameters and send them, look for unexpected behavior from the backend. 36 37 ```ps1 38 x8 -u "https://example.com/" -w <wordlist> 39 x8 -u "https://example.com/" -X POST -w <wordlist> 40 ``` 41 42 Wordlist examples: 43 44 * [Arjun/large.txt](https://github.com/s0md3v/Arjun/blob/master/arjun/db/large.txt) 45 * [Arjun/medium.txt](https://github.com/s0md3v/Arjun/blob/master/arjun/db/medium.txt) 46 * [Arjun/small.txt](https://github.com/s0md3v/Arjun/blob/master/arjun/db/small.txt) 47 * [samlists/sam-cc-parameters-lowercase-all.txt](https://github.com/the-xentropy/samlists/blob/main/sam-cc-parameters-lowercase-all.txt) 48 * [samlists/sam-cc-parameters-mixedcase-all.txt](https://github.com/the-xentropy/samlists/blob/main/sam-cc-parameters-mixedcase-all.txt) 49 50 ### Old Parameters 51 52 Explore all the URL from your targets to find old parameters. 53 54 * Browse the [Wayback Machine](http://web.archive.org/) 55 * Look through the JS files to discover unused parameters 56 57 ## References 58 59 * [Hacker tools: Arjun – The parameter discovery tool - Intigriti - May 17, 2021](https://web.archive.org/web/20230930093635/https://blog.intigriti.com/2021/05/17/hacker-tools-arjun-the-parameter-discovery-tool/) 60 * [Parameter Discovery: A quick guide to start - YesWeHack - April 20, 2022](http://web.archive.org/web/20220420123306/https://blog.yeswehack.com/yeswerhackers/parameter-discovery-quick-guide-to-start)