api-fuzzing-bug-bounty
Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.
By sickn33 · 677 installs
npx skills add sickn33/agentic-awesome-skills --skill api-fuzzing-bug-bounty
Source repository · Upstream listing
⚠️ AUTHORIZED USE ONLY
This skill is for educational purposes or authorized security assessments only.
You must have explicit, written permission from the system owner before using this tool.
Misuse of this tool is illegal and strictly prohibited.
Mandatory confirmation gate
Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
1. Ask the user to state the exact target URL, IP, account, or resource.
2. Ask the user to confirm written authorization and the permitted scope.
3. Show the exact command(s) and explain their expected effect.
4. Wait for explicit confirmation in the current conversation.
Without that confirmation, remain read only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
API Fuzzing for Bug Bounty
Purpose
Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API specific attack vectors.
Inputs/Prerequisites
Burp Suite or similar proxy tool
API wordlists (SecLists, api wordlist)
Understanding of REST/GraphQL/SOAP protocols
Python for scripting
Target API endpoints and documentation (if available)
Outputs/Deliverables
Identified API vulnerabilities
IDOR exploitation proofs
Authentication bypass techniques
SQL injection points
Unauthorized data access documentation
API Types Overview
Type Protocol Data Format Structure
SOAP HTTP XML Header + Body
REST HTTP JSON/XML/URL Defined endpoints
GraphQL HTTP Custom Query Single endpoint
Core Workflow
Step 1: API Reconnaissance
Identify API type and enumerate endpoints:
Step 2: Authentication Testing
Step 3: IDOR Testing
Insecure Direct Object Reference is the most common API vulnerability:
IDOR Bypass Techniques:
Step 4: Injection Testing
SQL Injection in JSON:
Command Injection:
XXE Injection:
SSRF via API:
.NET Path.Combine Vulnerability:
Step 5: Method Testing
GraphQL Specific Testing
Introspection Query
Fetch entire backend schema:
URL encoded version:
GraphQL IDOR
GraphQL SQL/NoSQL Injection
Rate Limit Bypass (Batching)
GraphQL DoS (Nested Queries)
GraphQL XSS
GraphQL Tools
Tool Purpose
GraphCrawler Schema discovery
graphw00f Fingerprinting
clairvoyance Schema reconstruction
InQL Burp extension
GraphQLmap Exploitation
Endpoint Bypass Techniques
When receiving 403/401, try these bypasses:
Output Exploitation
PDF Export Attacks
DoS via Limits
Common API Vulnerabilities Checklist
Vulnerability Description
API Exposure Unprotected endpoints exposed publicly
Misconfigured Caching Sensitive data cached incorrectly
Exposed Tokens API keys/tokens in responses or URLs
JWT Weaknesses Weak signing, no expiration, algorithm confusion
IDOR / BOLA Broken Object Level Authorization
Undocumented Endpoints Hidden admin/debug endpoints
Different Versions Security gaps in older API versions
Rate Limiting Missing or bypassable rate limits
Race Conditions TOCTOU vulnerabilities
XXE Injection XML parser exploitation
Content Type Issues Switching between JSON/XML
HTTP Method Tampering GET→DELETE/PUT abuse
Quick Reference
Vulnerability Test Payload Risk
IDOR Change user id parameter High
SQLi ' OR 1=1 in JSON Critical
Command Injection ; ls / Critical
XXE DOCTYPE with ENTITY High
SSRF Internal IP in params High
Rate Limit Bypass Batch requests Medium
Method Tampering GET→DELETE High
Tools Reference
Category Tool URL
API Fuzzing Fuzzapi github.com/Fuzzapi/fuzzapi
API Fuzzing API fuzzer github.com/Fuzzapi/API fuzzer
API Fuzzing Astra github.com/flipkart incubator/Astra
API Security apicheck github.com/BBVA/apicheck
API Discovery Kiterunner github.com/assetnote/kiterunner
API Discovery openapi security scanner github.com/ngalongc/openapi security scanner
API Toolkit APIKit github.com/API Security/APIKit
API Keys API Guesser api guesser.netlify.app
GUID GUID Guesser gist.github.com/DanaEpp/8c6803e542f094da5c4079622f9b4d18
GraphQL InQL github.com/doyensec/inql
GraphQL GraphCrawler github.com/gsmith257 cyber/GraphCrawler
GraphQL graphw00f github.com/dolevf/graphw00f
GraphQL clairvoyance github.com/nikitastupin/clairvoyance
GraphQL batchql github.com/assetnote/batchql
GraphQL graphql cop github.com/dolevf/graphql cop
Wordlists SecLists github.com/danielmiessler/SecLists
Swagger Parser Swagger EZ rhinosecuritylabs.github.io/Swagger EZ
Swagger Routes swagroutes github.com/amalmurali47/swagroutes
API Mindmap MindAPI dsopas.github.io/MindAPI/play
JSON Paths json2paths github.com/s0md3v/dump/tree/master/json2paths
Constraints
Must:
Test mobile, web, and developer APIs separately
Check all API versions (/v1, /v2, /v3)
Validate both authenticated and unauthenticated access
Must Not:
Assume same security controls across API versions
Skip testing undocumented endpoints
Ignore rate limiting checks
Should:
Add X Requested With: XMLHttpRequest header to simulate frontend
Check archive.org for historical API endpoints
Test for race conditions on sensitive operations
Examples
Example 1: IDOR Exploitation
Example 2: GraphQL Introspection
Troubleshooting
Issue Solution
API returns nothing Add X Requested With: XMLHttpRequest header
401 on all endpoints Try adding ?user id=1 parameter
GraphQL introspection disabled Use clairvoyance for schema reconstruction
Rate limited Use IP rotation or batch requests
Can't find endpoints Check Swagger, archive.org, JS files
When to Use
This skill is applicable to execute the workflow or actions described in the overview.