vulns.co
/
GKData.io MCP

Back to Playbooks

Archive-to-Live Surface Delta

Compare historical public surface against the current authorized application to find live legacy routes, stale client artifacts, and security-relevant drift without treating archived content as live proof.

Tags: archive, recon, deprecated, api, javascript

Level: intermediate

Method

  1. Build a dated historical corpus

    Collect archived URLs, documented releases, old public JS filenames, and API/version references. Keep source date and origin; canonicalize and deduplicate paths separately from parameter values.

    waymore -i target.example -mode U -oU historical.txt; cat historical.txt | uro > historical-unique.txt

    Tools: waymore, gau, uro

  2. Create a current observed corpus

    Crawl only approved live starting URLs and collect public route manifests, robots/sitemaps, and first-party JavaScript endpoints. Fingerprint current framework/version behavior before testing.

    katana -u https://target.example -jc -silent | uro > current-urls.txt

    Tools: katana, httpx, getJS

  3. Diff paths and semantics

    Prioritize archive-only candidates that map to current hosts, old API versions, admin/support routes, uploads, redirects, OAuth callbacks, and outdated bundles. A historical URL is a lead; verify method, auth behavior, response type, and current ownership before deeper work.

    cat historical-unique.txt | httpx -silent -sc -ct -title -o historical-live.txt

    Tools: httpx

  4. Investigate drift safely

    Compare current versus old authorization, caching, redirects, schemas, and client routes. Use low-rate GET/HEAD where permitted and owned accounts for any authenticated check. Avoid bulk requests, destructive verbs, and testing third-party archived hosts.

    Tools: Burp Suite

  5. Turn deltas into evidence

    Record archive source/date, current response, ownership/scope confirmation, and the exact behavior difference. Report only a presently reproducible issue, not an exposed historical snapshot.

Field notes

  • Historical JavaScript is excellent for endpoint names and feature archaeology, but expired secrets and dead hosts are not findings.
  • Separate discovery evidence from current validation evidence in notes and reports.

References