🐇
CheatSheet
Ctrlk
  • Inicio
  • Web Site
  • API
    • Recolección de Informacion
      • Directorios
      • OSINT
      • Enumeracion en Endpoints
    • Busqueda de Vulnerabilidades
  • Mobile
  • Miscelanio
  • Post Explotación
  • Configuraciones Burpsuite
Powered by GitBook
On this page
  1. API
  2. Recolección de Informacion

Enumeracion en Endpoints

Fuzz de Endpoints

https://domain.site/api/v1/FUZZ1.FUZZ2

actionObject
ActionObject
action_Object
action-object
action.object
...
LogoGitHub - chrislockard/api_wordlist: A wordlist of API names for web application assessmentsGitHub

JS Minning

Extension de burpsuite.

LogoGitHub - PortSwigger/js-miner: This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.GitHub

Fuzz de parametros

LogoGitHub - s0md3v/Arjun: HTTP parameter discovery suite.GitHub

Kite Runner

LogoGitHub - assetnote/kiterunner: Contextual Content Discovery ToolGitHub

Last updated 2 years ago

  • Fuzz de Endpoints
  • JS Minning
  • Fuzz de parametros
  • Kite Runner
arjun -u URL
kr scan hosts.txt -w routes.kite -x 20 -j 100