Checklist

API Checklist

ko-fiarrow-up-right

To Test

https://x.com/intigriti/status/1928377914749313531arrow-up-right

  • Blind XSS in request header

XSSchevron-right
  • Legacy API endpoints - Replace "/api/v2" with "/api/v1", etc.

Improper Asset Managementchevron-right
  • SSRF

SSRFchevron-right
  • Find more endpoints: GitHub, Dorks, Swagger, JS Files

Git Dorkschevron-rightGoogle Dorkschevron-rightSwagger UIchevron-rightWeb Enumerationchevron-right
  • CSRF

CSRFchevron-right
  • Bypass 403/401

Bypass 403 / 401chevron-right

• Rate limiting & throttling checks

Rate Limitingchevron-right

• JWT misconfigurations/attacks

JWT Tokenchevron-right
  • CORS Misconfiguration

CORSchevron-right
  • Race conditions

Race Conditonschevron-right
  • XXE - API is only accepting data in JSON? Try changing the content type from "application/json" to "application/xml" and test for XXE vulnerabilities

XXE / XSLTchevron-right
  • NoSQL injection

NoSQL injectionchevron-right

• Endpoint discovery & parameter tampering • Data leakage & error handling flaws • API BAC on 3 levels • SQLi • Other injection

Interesting Books

Interesting Bookschevron-right
circle-info

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Support this Gitbook

I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.

ko-fiarrow-up-right

buymeacoffeearrow-up-right

Last updated