daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (2746B)


      1 ---
      2 title: "HTTP Hidden Parameters"
      3 topic: "Hidden Parameters"
      4 topicSlug: "hidden-parameters"
      5 sourcePath: "Hidden Parameters/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Hidden%20Parameters/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # HTTP Hidden Parameters
     12 
     13 > Web applications often have hidden or undocumented parameters that are not exposed in the user interface. Fuzzing can help discover these parameters, which might be vulnerable to various attacks.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [Bruteforce Parameters](#bruteforce-parameters)
     20     * [Old Parameters](#old-parameters)
     21 * [References](#references)
     22 
     23 ## Tools
     24 
     25 * [PortSwigger/param-miner](https://github.com/PortSwigger/param-miner) - Burp extension to identify hidden, unlinked parameters.
     26 * [s0md3v/Arjun](https://github.com/s0md3v/Arjun) - HTTP parameter discovery suite
     27 * [Sh1Yo/x8](https://github.com/Sh1Yo/x8) - Hidden parameters discovery suite
     28 * [tomnomnom/waybackurls](https://github.com/tomnomnom/waybackurls) - Fetch all the URLs that the Wayback Machine knows about for a domain
     29 * [devanshbatham/ParamSpider](https://github.com/devanshbatham/ParamSpider) - Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
     30 
     31 ## Methodology
     32 
     33 ### Bruteforce Parameters
     34 
     35 * Use wordlists of common parameters and send them, look for unexpected behavior from the backend.
     36 
     37     ```ps1
     38     x8 -u "https://example.com/" -w <wordlist>
     39     x8 -u "https://example.com/" -X POST -w <wordlist>
     40     ```
     41 
     42 Wordlist examples:
     43 
     44 * [Arjun/large.txt](https://github.com/s0md3v/Arjun/blob/master/arjun/db/large.txt)
     45 * [Arjun/medium.txt](https://github.com/s0md3v/Arjun/blob/master/arjun/db/medium.txt)
     46 * [Arjun/small.txt](https://github.com/s0md3v/Arjun/blob/master/arjun/db/small.txt)
     47 * [samlists/sam-cc-parameters-lowercase-all.txt](https://github.com/the-xentropy/samlists/blob/main/sam-cc-parameters-lowercase-all.txt)
     48 * [samlists/sam-cc-parameters-mixedcase-all.txt](https://github.com/the-xentropy/samlists/blob/main/sam-cc-parameters-mixedcase-all.txt)
     49 
     50 ### Old Parameters
     51 
     52 Explore all the URL from your targets to find old parameters.
     53 
     54 * Browse the [Wayback Machine](http://web.archive.org/)
     55 * Look through the JS files to discover unused parameters
     56 
     57 ## References
     58 
     59 * [Hacker tools: Arjun – The parameter discovery tool - Intigriti - May 17, 2021](https://web.archive.org/web/20230930093635/https://blog.intigriti.com/2021/05/17/hacker-tools-arjun-the-parameter-discovery-tool/)
     60 * [Parameter Discovery: A quick guide to start - YesWeHack - April 20, 2022](http://web.archive.org/web/20220420123306/https://blog.yeswehack.com/yeswerhackers/parameter-discovery-quick-guide-to-start)