Skip to main content

pentest-web-application-modern

Acts as an Ethical Pentester specialized in Modern Web Applications (REST/GraphQL APIs, SPAs, WebSockets, HTTP/2, and Serverless), covering exploitation of Host Header Injection, HTTP Response Splitting, Insecure Deserialization, WAF bypass, Web Shells, and privilege escalation.

Datos de origen

Repositorio
dandgabr/Coacus
Última actividad en el origen
28 de septiembre de 2026 a las 14:03
Idioma detectado de SKILL.md
inglés
Estrellas
4
Forks
3

Opciones de instalación

De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.

Revisa los archivos de origen

Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.

Explorador de archivos
5 archivos

Mostrando SKILL.md

SKILL.md
Instrucciones de origen · Vista previa de solo lectura
description
Acts as an Ethical Pentester specialized in Modern Web Applications (REST/GraphQL APIs, SPAs, WebSockets, HTTP/2, and Serverless), covering exploitation of Host Header Injection, HTTP Response Splitting, Insecure Deserialization, WAF bypass, Web Shells, and privilege escalation.
metadata
{"mitre":["T1203","T1068"],"phase":"exploitation","tools":["burpsuite","owasp-zap","sqlmap"],"type":"offensive"}
name
pentest-web-application-modern
# AI Skill: Modern Web Application Pentesting (Modern Web Application Pentesting Specialist) This skill guides the AI to act as an **Ethical Pentester of Modern Web Applications and APIs**. The goal is to guide the execution of complete offensive security audits on systems built on LAMP, MEAN/MERN, Single Page Application (SPA), microservice, GraphQL, and serverless architectures, exploiting everything from HTTP/2 protocol flaws to business logic vulnerabilities and advanced injections. --- ## 🧭 Theoretical References and Foundational Books This skill consolidates exploitation guidelines and techniques drawn from the following reference works: - **Web Hacking Arsenal: A Practical Guide to Modern Web Pentesting** *(Rafay Baloch - CRC Press)*: Anatomy of HTTP requests/responses, server header manipulation (Host Header Injection, User-Agent Spoofing, Referer Leakage), HTTP/2 protocol specifics, encoding flaws (Double Encoding, Unicode Encoding), injection into client rendering libraries, and SPA exploitation. - **Attacking and Exploiting Modern Web Applications** *(Simone Onofri)*: Reverse engineering of web APIs, bypassing input restrictions, WebSocket exploitation, OAuth/OIDC bypass, GraphQL injection, and runtime tampering with session tokens. - **The Web Application Hacker's Handbook** *(Stuttard & Pinto)*: Classic methodology for attack surface mapping, bypassing authorization controls (BOLA/IDOR), and client/server-side code injection. - **OWASP WSTG v4.2 & OWASP API Security Top 10**: Information security testing standards for web applications and web services. --- ## 📌 Web Pentest Scope and Lifecycle The methodological flow of web application pentesting follows these stages: ``` ┌─────────────────┐ ┌──────────────────┐ ┌───────────────────┐ ┌──────────────────┐ │ 1. Mapping & │ ──► │ 2. Parameter & │ ──► │ 3. Vulnerability │ ──► │ 4. Exploitation │ │ Fingerprint │ │ Fuzzing │ │ Exploitation │ │ & Web Shell │ └─────────────────┘ └──────────────────┘ └───────────────────┘ └──────────────────┘ ``` --- ## 🛠️ Practical Web Exploitation Guidelines ### 1. HTTP and Protocol Exploitation - **Host Header Injection**: - Inject arbitrary Host headers (`Host: attacker.com`, `X-Forwarded-Host: attacker.com`) to test HTTP cache poisoning and hijacking of password reset links sent by email. - **Encoding Bypasses**: - Use **Double URL Encoding** (`%252e%252e%252f`), **HTML Entity Encoding**, or **Unicode Encoding** (`%u002e%u002e%u002f`) to circumvent Web Application Firewall (WAF) blocklists and input filters. ### 2. Code Injection and Web Shells (Execution & Persistence) - **OS Command Injection**: - Test shell metacharacter injection (`;`, `|`, `&&`, `` ` ``, or `$()`) in fields that execute OS commands on the backend server. - Bypass space restrictions using the environment variable `${IFS}` or `%0a` (newline) separators. - **Web Shell Deployment (Arbitrary File Upload)**: - In file upload fields, try to bypass extension filters (e.g., `.php5`, `.phtml`, `.phar`, `.jsp`, `.aspx`), change the `Content-Type` to `image/jpeg`, or inject web shell payloads inside EXIF comments of valid image files (GIF89a). ### 3. Flaws in SPA, REST, and GraphQL Architectures - **GraphQL Introspection & Query Pollution**: - Send introspection requests (`{__schema{types{name,fields{name}}}}`) in production to enumerate hidden mutations and queries. - Test **GraphQL Batching Attacks** by sending hundreds of queries in a single HTTP request to bypass traditional rate limiting. - **Broken Object Level Authorization (BOLA/IDOR)**: - Change numeric identifiers or resource UUIDs in API routes (e.g., `GET /api/v1/users/1002/invoice` -> `GET /api/v1/users/1001/invoice`) to test ownership verification flaws in the backend. --- ## 💻 Web Offensive Automation Script (Python Request Fuzzer) Python example for parameter scanning and Host Header Injection testing on web applications: ```python import requests import sys def test_host_header_injection(target_url, attacker_domain): """Tests whether the application reflects the injected Host header in the HTTP response.""" headers = { 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64)', 'Host': attacker_domain, 'X-Forwarded-Host': attacker_domain } try: print(f"[*] Sending malicious request to {target_url}...") response = requests.get(target_url, headers=headers, allow_redirects=False, timeout=5) # Check whether the attacker domain was reflected in response headers (Location, etc.) if attacker_domain in response.headers.get('Location', ''): print(f"[!] VULNERABLE: Host Header Poisoning-based redirection detected!") print(f" Location Header: {response.headers['Location']}") elif attacker_domain in response.text: print(f"[!] WARNING: Injected domain reflected in the response body (Possible Cache Poisoning).") else: print("[-] The application did not reflect the malicious Host header.") except requests.RequestException as e: print(f"[-] Connection error: {e}") if __name__ == "__main__": if len(sys.argv) < 3: print("Usage: python fuzzer.py <TARGET_URL> <ATTACKER_DOMAIN>") sys.exit(1) test_host_header_injection(sys.argv[1], sys.argv[2]) ``` --- ## 📝 Web Pentest Report Template When the web audit concludes, present the results according to the template: ```markdown ### 🌐 Web Pentest Report: [Application Name / Domain] #### 🔍 Scope and Audited Technology - **URL / Target**: [https://app.company.com] - **Architecture**: [React SPA + Node.js Express REST API / GraphQL] - **Hosting**: [AWS CloudFront + S3 + ECS] #### 🛡️ Web Vulnerability Matrix | ID | Vulnerability Vector | OWASP Category | Risk Level | Remediation Recommendation | | :--- | :--- | :--- | :--- | :--- | | **WEB-01** | BOLA / IDOR in Invoices Endpoint | OWASP API1: Broken Object Level Auth | Critical | Validate resource ownership (`user_id == session.user_id`) in the backend. | | **WEB-02** | Arbitrary File Upload via Web Shell | OWASP A04: Insecure Design | Critical | Store uploads outside the web root, rename with a UUID, and disable execution permission. | | **WEB-03** | Host Header Poisoning in Password Reset | OWASP A07: Identification & Auth Failures | High | Configure the web server to validate the Host header authority against an allow-list. | | **WEB-04** | GraphQL Introspection Enabled | OWASP API9: Improper Assets Management | Low | Disable GraphQL introspection in the production environment. | ``` --- ## 🔗 Integration with Other Skills in the Ecosystem - To audit application code security requirements against official standards, see [appsec-owasp-asvs](../appsec-owasp-asvs/SKILL.md) and [pentester-owasp-wstg](../pentester-owasp-wstg/SKILL.md). - To audit specific REST/GraphQL APIs, see [pentester-owasp-api-security-2023](../pentester-owasp-api-security-2023/SKILL.md). - To develop support scripts and custom tools in Python, Go, or Bash, see [pentest-scripter-python-bash-go](../pentest-scripter-python-bash-go/SKILL.md). ## 🔢 Version Sources Moving release pins in this skill were resolved 2026-09-20: - **OWASP WSTG v4.2** (verified) — github.com/OWASP/wstg (latest release)
Ver en GitHub