API Hunting Methodology
Discover, understand, and abuse API surface - usually where the real vulns hide.
Tags: api, rest, graphql
Level: intermediate
Method
Discover endpoints
Pull JS, historical URLs, and Swagger/OpenAPI docs to build the endpoint map.
katana -u https://target.com -jc -silent | anew urls.txt; gau target.com | anew urls.txtTools: katana, gau, getJS, LinkFinder
Find hidden parameters
Infer undocumented parameters on interesting endpoints.
arjun -u https://target.com/api/v1/user -oT params.txtTools: arjun
Probe authz per endpoint
Test every endpoint unauthenticated, as a low-priv user, and cross-tenant. BOLA/BFLA are the top API risks.
Tools: Burp Suite
Check versioning & docs
Old versions (/api/v1 vs /v2) and exposed Swagger often reveal deprecated, less-protected routes.
ffuf -u https://target.com/api/FUZZ -w api-wordlist.txt -mc 200,401,403Tools: ffuf
Field notes
- GraphQL: try introspection, then batch/alias abuse and field-level authz.
- Mass assignment: add extra JSON fields (role, is_admin) and see if they stick.