API Enumeration - Endpoints Fuzzing ( Part - 3 ) | Shahul Hameed
API Enumeration - Fuzzing
The following of endpoints which can be test for Fuzzing Paths:
Command - 1:
wfuzz -c -z file,/usr/share/wordlists/dirb/common.txt --sc 200 'http://www.example.com/api/v1/books?show=FUZZ'
Command - 2:
gobuster dir -w /usr/share/wordlists/dirb/common.txt - u http://<IP>
API's Enumeration via Source code discovery
Finding the endpoints from the Source Code via Browser
Comments
Post a Comment