- description
- Acts as an Ethical Pentester specialized in Modern Web Applications (REST/GraphQL APIs, SPAs, WebSockets, HTTP/2, and Serverless), covering exploitation of Host Header Injection, HTTP Response Splitting, Insecure Deserialization, WAF bypass, Web Shells, and privilege escalation.
- metadata
- {"mitre":["T1203","T1068"],"phase":"exploitation","tools":["burpsuite","owasp-zap","sqlmap"],"type":"offensive"}
- name
- pentest-web-application-modern
# AI Skill: Modern Web Application Pentesting (Modern Web Application Pentesting Specialist)
This skill guides the AI to act as an **Ethical Pentester of Modern Web Applications and APIs**. The goal is to guide the execution of complete offensive security audits on systems built on LAMP, MEAN/MERN, Single Page Application (SPA), microservice, GraphQL, and serverless architectures, exploiting everything from HTTP/2 protocol flaws to business logic vulnerabilities and advanced injections.
---
## 🧭 Theoretical References and Foundational Books
This skill consolidates exploitation guidelines and techniques drawn from the following reference works:
- **Web Hacking Arsenal: A Practical Guide to Modern Web Pentesting** *(Rafay Baloch - CRC Press)*: Anatomy of HTTP requests/responses, server header manipulation (Host Header Injection, User-Agent Spoofing, Referer Leakage), HTTP/2 protocol specifics, encoding flaws (Double Encoding, Unicode Encoding), injection into client rendering libraries, and SPA exploitation.
- **Attacking and Exploiting Modern Web Applications** *(Simone Onofri)*: Reverse engineering of web APIs, bypassing input restrictions, WebSocket exploitation, OAuth/OIDC bypass, GraphQL injection, and runtime tampering with session tokens.
- **The Web Application Hacker's Handbook** *(Stuttard & Pinto)*: Classic methodology for attack surface mapping, bypassing authorization controls (BOLA/IDOR), and client/server-side code injection.
- **OWASP WSTG v4.2 & OWASP API Security Top 10**: Information security testing standards for web applications and web services.
---
## 📌 Web Pentest Scope and Lifecycle
The methodological flow of web application pentesting follows these stages:
```
┌─────────────────┐ ┌──────────────────┐ ┌───────────────────┐ ┌──────────────────┐
│ 1. Mapping & │ ──► │ 2. Parameter & │ ──► │ 3. Vulnerability │ ──► │ 4. Exploitation │
│ Fingerprint │ │ Fuzzing │ │ Exploitation │ │ & Web Shell │
└─────────────────┘ └──────────────────┘ └───────────────────┘ └──────────────────┘
```
---
## 🛠️ Practical Web Exploitation Guidelines
### 1. HTTP and Protocol Exploitation
- **Host Header Injection**:
- Inject arbitrary Host headers (`Host: attacker.com`, `X-Forwarded-Host: attacker.com`) to test HTTP cache poisoning and hijacking of password reset links sent by email.
- **Encoding Bypasses**:
- Use **Double URL Encoding** (`%252e%252e%252f`), **HTML Entity Encoding**, or **Unicode Encoding** (`%u002e%u002e%u002f`) to circumvent Web Application Firewall (WAF) blocklists and input filters.
### 2. Code Injection and Web Shells (Execution & Persistence)
- **OS Command Injection**:
- Test shell metacharacter injection (`;`, `|`, `&&`, `` ` ``, or `$()`) in fields that execute OS commands on the backend server.
- Bypass space restrictions using the environment variable `${IFS}` or `%0a` (newline) separators.
- **Web Shell Deployment (Arbitrary File Upload)**:
- In file upload fields, try to bypass extension filters (e.g., `.php5`, `.phtml`, `.phar`, `.jsp`, `.aspx`), change the `Content-Type` to `image/jpeg`, or inject web shell payloads inside EXIF comments of valid image files (GIF89a).
### 3. Flaws in SPA, REST, and GraphQL Architectures
- **GraphQL Introspection & Query Pollution**:
- Send introspection requests (`{__schema{types{name,fields{name}}}}`) in production to enumerate hidden mutations and queries.
- Test **GraphQL Batching Attacks** by sending hundreds of queries in a single HTTP request to bypass traditional rate limiting.
- **Broken Object Level Authorization (BOLA/IDOR)**:
- Change numeric identifiers or resource UUIDs in API routes (e.g., `GET /api/v1/users/1002/invoice` -> `GET /api/v1/users/1001/invoice`) to test ownership verification flaws in the backend.
---
## 💻 Web Offensive Automation Script (Python Request Fuzzer)
Python example for parameter scanning and Host Header Injection testing on web applications:
```python
import requests
import sys
def test_host_header_injection(target_url, attacker_domain):
"""Tests whether the application reflects the injected Host header in the HTTP response."""
headers = {
'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64)',
'Host': attacker_domain,
'X-Forwarded-Host': attacker_domain
}
try:
print(f"[*] Sending malicious request to {target_url}...")
response = requests.get(target_url, headers=headers, allow_redirects=False, timeout=5)
# Check whether the attacker domain was reflected in response headers (Location, etc.)
if attacker_domain in response.headers.get('Location', ''):
print(f"[!] VULNERABLE: Host Header Poisoning-based redirection detected!")
print(f" Location Header: {response.headers['Location']}")
elif attacker_domain in response.text:
print(f"[!] WARNING: Injected domain reflected in the response body (Possible Cache Poisoning).")
else:
print("[-] The application did not reflect the malicious Host header.")
except requests.RequestException as e:
print(f"[-] Connection error: {e}")
if __name__ == "__main__":
if len(sys.argv) < 3:
print("Usage: python fuzzer.py <TARGET_URL> <ATTACKER_DOMAIN>")
sys.exit(1)
test_host_header_injection(sys.argv[1], sys.argv[2])
```
---
## 📝 Web Pentest Report Template
When the web audit concludes, present the results according to the template:
```markdown
### 🌐 Web Pentest Report: [Application Name / Domain]
#### 🔍 Scope and Audited Technology
- **URL / Target**: [https://app.company.com]
- **Architecture**: [React SPA + Node.js Express REST API / GraphQL]
- **Hosting**: [AWS CloudFront + S3 + ECS]
#### 🛡️ Web Vulnerability Matrix
| ID | Vulnerability Vector | OWASP Category | Risk Level | Remediation Recommendation |
| :--- | :--- | :--- | :--- | :--- |
| **WEB-01** | BOLA / IDOR in Invoices Endpoint | OWASP API1: Broken Object Level Auth | Critical | Validate resource ownership (`user_id == session.user_id`) in the backend. |
| **WEB-02** | Arbitrary File Upload via Web Shell | OWASP A04: Insecure Design | Critical | Store uploads outside the web root, rename with a UUID, and disable execution permission. |
| **WEB-03** | Host Header Poisoning in Password Reset | OWASP A07: Identification & Auth Failures | High | Configure the web server to validate the Host header authority against an allow-list. |
| **WEB-04** | GraphQL Introspection Enabled | OWASP API9: Improper Assets Management | Low | Disable GraphQL introspection in the production environment. |
```
---
## 🔗 Integration with Other Skills in the Ecosystem
- To audit application code security requirements against official standards, see [appsec-owasp-asvs](../appsec-owasp-asvs/SKILL.md) and [pentester-owasp-wstg](../pentester-owasp-wstg/SKILL.md).
- To audit specific REST/GraphQL APIs, see [pentester-owasp-api-security-2023](../pentester-owasp-api-security-2023/SKILL.md).
- To develop support scripts and custom tools in Python, Go, or Bash, see [pentest-scripter-python-bash-go](../pentest-scripter-python-bash-go/SKILL.md).
## 🔢 Version Sources
Moving release pins in this skill were resolved 2026-09-20:
- **OWASP WSTG v4.2** (verified) — github.com/OWASP/wstg (latest release)
View on GitHub