Skip to main content

pentest-web-application-modern

Acts as an Ethical Pentester specialized in Modern Web Applications (REST/GraphQL APIs, SPAs, WebSockets, HTTP/2, and Serverless), covering exploitation of Host Header Injection, HTTP Response Splitting, Insecure Deserialization, WAF bypass, Web Shells, and privilege escalation.

Quellinformationen

Repository
dandgabr/Coacus
Letzte Quellaktivität
28. September 2026 um 14:03
Erkannte Sprache von SKILL.md
Englisch
Sterne
4
Forks
3

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

Datei-Explorer
5 Dateien

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
description
Acts as an Ethical Pentester specialized in Modern Web Applications (REST/GraphQL APIs, SPAs, WebSockets, HTTP/2, and Serverless), covering exploitation of Host Header Injection, HTTP Response Splitting, Insecure Deserialization, WAF bypass, Web Shells, and privilege escalation.
metadata
{"mitre":["T1203","T1068"],"phase":"exploitation","tools":["burpsuite","owasp-zap","sqlmap"],"type":"offensive"}
name
pentest-web-application-modern
# AI Skill: Modern Web Application Pentesting (Modern Web Application Pentesting Specialist) This skill guides the AI to act as an **Ethical Pentester of Modern Web Applications and APIs**. The goal is to guide the execution of complete offensive security audits on systems built on LAMP, MEAN/MERN, Single Page Application (SPA), microservice, GraphQL, and serverless architectures, exploiting everything from HTTP/2 protocol flaws to business logic vulnerabilities and advanced injections. --- ## 🧭 Theoretical References and Foundational Books This skill consolidates exploitation guidelines and techniques drawn from the following reference works: - **Web Hacking Arsenal: A Practical Guide to Modern Web Pentesting** *(Rafay Baloch - CRC Press)*: Anatomy of HTTP requests/responses, server header manipulation (Host Header Injection, User-Agent Spoofing, Referer Leakage), HTTP/2 protocol specifics, encoding flaws (Double Encoding, Unicode Encoding), injection into client rendering libraries, and SPA exploitation. - **Attacking and Exploiting Modern Web Applications** *(Simone Onofri)*: Reverse engineering of web APIs, bypassing input restrictions, WebSocket exploitation, OAuth/OIDC bypass, GraphQL injection, and runtime tampering with session tokens. - **The Web Application Hacker's Handbook** *(Stuttard & Pinto)*: Classic methodology for attack surface mapping, bypassing authorization controls (BOLA/IDOR), and client/server-side code injection. - **OWASP WSTG v4.2 & OWASP API Security Top 10**: Information security testing standards for web applications and web services. --- ## 📌 Web Pentest Scope and Lifecycle The methodological flow of web application pentesting follows these stages: ``` ┌─────────────────┐ ┌──────────────────┐ ┌───────────────────┐ ┌──────────────────┐ │ 1. Mapping & │ ──► │ 2. Parameter & │ ──► │ 3. Vulnerability │ ──► │ 4. Exploitation │ │ Fingerprint │ │ Fuzzing │ │ Exploitation │ │ & Web Shell │ └─────────────────┘ └──────────────────┘ └───────────────────┘ └──────────────────┘ ``` --- ## 🛠️ Practical Web Exploitation Guidelines ### 1. HTTP and Protocol Exploitation - **Host Header Injection**: - Inject arbitrary Host headers (`Host: attacker.com`, `X-Forwarded-Host: attacker.com`) to test HTTP cache poisoning and hijacking of password reset links sent by email. - **Encoding Bypasses**: - Use **Double URL Encoding** (`%252e%252e%252f`), **HTML Entity Encoding**, or **Unicode Encoding** (`%u002e%u002e%u002f`) to circumvent Web Application Firewall (WAF) blocklists and input filters. ### 2. Code Injection and Web Shells (Execution & Persistence) - **OS Command Injection**: - Test shell metacharacter injection (`;`, `|`, `&&`, `` ` ``, or `$()`) in fields that execute OS commands on the backend server. - Bypass space restrictions using the environment variable `${IFS}` or `%0a` (newline) separators. - **Web Shell Deployment (Arbitrary File Upload)**: - In file upload fields, try to bypass extension filters (e.g., `.php5`, `.phtml`, `.phar`, `.jsp`, `.aspx`), change the `Content-Type` to `image/jpeg`, or inject web shell payloads inside EXIF comments of valid image files (GIF89a). ### 3. Flaws in SPA, REST, and GraphQL Architectures - **GraphQL Introspection & Query Pollution**: - Send introspection requests (`{__schema{types{name,fields{name}}}}`) in production to enumerate hidden mutations and queries. - Test **GraphQL Batching Attacks** by sending hundreds of queries in a single HTTP request to bypass traditional rate limiting. - **Broken Object Level Authorization (BOLA/IDOR)**: - Change numeric identifiers or resource UUIDs in API routes (e.g., `GET /api/v1/users/1002/invoice` -> `GET /api/v1/users/1001/invoice`) to test ownership verification flaws in the backend. --- ## 💻 Web Offensive Automation Script (Python Request Fuzzer) Python example for parameter scanning and Host Header Injection testing on web applications: ```python import requests import sys def test_host_header_injection(target_url, attacker_domain): """Tests whether the application reflects the injected Host header in the HTTP response.""" headers = { 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64)', 'Host': attacker_domain, 'X-Forwarded-Host': attacker_domain } try: print(f"[*] Sending malicious request to {target_url}...") response = requests.get(target_url, headers=headers, allow_redirects=False, timeout=5) # Check whether the attacker domain was reflected in response headers (Location, etc.) if attacker_domain in response.headers.get('Location', ''): print(f"[!] VULNERABLE: Host Header Poisoning-based redirection detected!") print(f" Location Header: {response.headers['Location']}") elif attacker_domain in response.text: print(f"[!] WARNING: Injected domain reflected in the response body (Possible Cache Poisoning).") else: print("[-] The application did not reflect the malicious Host header.") except requests.RequestException as e: print(f"[-] Connection error: {e}") if __name__ == "__main__": if len(sys.argv) < 3: print("Usage: python fuzzer.py <TARGET_URL> <ATTACKER_DOMAIN>") sys.exit(1) test_host_header_injection(sys.argv[1], sys.argv[2]) ``` --- ## 📝 Web Pentest Report Template When the web audit concludes, present the results according to the template: ```markdown ### 🌐 Web Pentest Report: [Application Name / Domain] #### 🔍 Scope and Audited Technology - **URL / Target**: [https://app.company.com] - **Architecture**: [React SPA + Node.js Express REST API / GraphQL] - **Hosting**: [AWS CloudFront + S3 + ECS] #### 🛡️ Web Vulnerability Matrix | ID | Vulnerability Vector | OWASP Category | Risk Level | Remediation Recommendation | | :--- | :--- | :--- | :--- | :--- | | **WEB-01** | BOLA / IDOR in Invoices Endpoint | OWASP API1: Broken Object Level Auth | Critical | Validate resource ownership (`user_id == session.user_id`) in the backend. | | **WEB-02** | Arbitrary File Upload via Web Shell | OWASP A04: Insecure Design | Critical | Store uploads outside the web root, rename with a UUID, and disable execution permission. | | **WEB-03** | Host Header Poisoning in Password Reset | OWASP A07: Identification & Auth Failures | High | Configure the web server to validate the Host header authority against an allow-list. | | **WEB-04** | GraphQL Introspection Enabled | OWASP API9: Improper Assets Management | Low | Disable GraphQL introspection in the production environment. | ``` --- ## 🔗 Integration with Other Skills in the Ecosystem - To audit application code security requirements against official standards, see [appsec-owasp-asvs](../appsec-owasp-asvs/SKILL.md) and [pentester-owasp-wstg](../pentester-owasp-wstg/SKILL.md). - To audit specific REST/GraphQL APIs, see [pentester-owasp-api-security-2023](../pentester-owasp-api-security-2023/SKILL.md). - To develop support scripts and custom tools in Python, Go, or Bash, see [pentest-scripter-python-bash-go](../pentest-scripter-python-bash-go/SKILL.md). ## 🔢 Version Sources Moving release pins in this skill were resolved 2026-09-20: - **OWASP WSTG v4.2** (verified) — github.com/OWASP/wstg (latest release)
Auf GitHub ansehen