vulns.co
/
GKData.io MCP

Back to Playbooks

API Hunting Methodology

Discover, understand, and abuse API surface - usually where the real vulns hide.

Tags: api, rest, graphql

Level: intermediate

Method

  1. Discover endpoints

    Pull JS, historical URLs, and Swagger/OpenAPI docs to build the endpoint map.

    katana -u https://target.com -jc -silent | anew urls.txt; gau target.com | anew urls.txt

    Tools: katana, gau, getJS, LinkFinder

  2. Find hidden parameters

    Infer undocumented parameters on interesting endpoints.

    arjun -u https://target.com/api/v1/user -oT params.txt

    Tools: arjun

  3. Probe authz per endpoint

    Test every endpoint unauthenticated, as a low-priv user, and cross-tenant. BOLA/BFLA are the top API risks.

    Tools: Burp Suite

  4. Check versioning & docs

    Old versions (/api/v1 vs /v2) and exposed Swagger often reveal deprecated, less-protected routes.

    ffuf -u https://target.com/api/FUZZ -w api-wordlist.txt -mc 200,401,403

    Tools: ffuf

Field notes

  • GraphQL: try introspection, then batch/alias abuse and field-level authz.
  • Mass assignment: add extra JSON fields (role, is_admin) and see if they stick.

References