ZeroBox

API and Web Application Logic Abuse: practice machines and key commands

APIs expose application logic directly, so flaws are usually about authorisation rather than memory safety. Map every endpoint from documentation, JavaScript files and traffic in Burp, then test each one for missing access control: change object identifiers to read other users data (IDOR), call admin routes with a normal token and replay requests without authentication. Check JSON bodies for mass assignment by adding unexpected fields such as role or isAdmin. JWTs need their algorithm and secret examined, and GraphQL introspection can reveal the full schema. Exposed .git directories and old API versions often leak source and credentials. Rate limits and verbose errors are also worth noting. The machines listed centre on web application and API weaknesses. Test with at least two accounts so access control gaps become obvious.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

GraphQL Schema Introspection Query

Query GraphQL endpoint for full type schema, queries, mutations, and hidden fields.

curl -s -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name,fields{name}}}}"}' http://{TARGET_IP}/graphql | jq .

JWT Secret Key HMAC-SHA256 Cracking

Crack HS256 signed JSON Web Token secrets offline using rockyou wordlist.

hashcat -m 16500 jwt.txt /usr/share/wordlists/rockyou.txt

Exposed .git Source Code Extraction

Dump full repository commits and source code from misconfigured public /.git/ directory.

git-dumper http://{TARGET_IP}/.git/ ./git-dump

ffuf Parameter Discovery (GET/POST)

Fuzz hidden query parameters on target page.

ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -u "http://{TARGET_IP}/index.php?FUZZ=test" -ac

ffuf Directory & Endpoint Fuzzing

High-speed directory enumeration with auto-calibrated filtering and extension recursion.

ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak,.js -ac -mc 200,301,302,403

Keep going

API and Web Application Logic Abuse machines (13)

3 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 13 Linux.

Very Easy (1)

MachinePlatformOSTags
OopsieHTBLinuxIDOR, SUID

Easy (7)

MachinePlatformOSTags
CapHTBLinuxHTB, IDOR
CorridorTHMLinuxIDOR, Hashing, MD5
NeighbourTHMLinuxIDOR, Authentication
BusquedaHTBLinuxCPTS, RCE, Python, Searchor
HelpHTBLinuxGraphQL, HTB
VulnversityTHMLinuxOSCP, File Upload Bypass, Burp Suite, SUID
WhiteroseTHMLinuxTHM, nmap, gobuster, ffuf

Medium (4)

MachinePlatformOSTags
Git HappensTHMLinuxGit, Information-Disclosure, Source-Code-Analysis
HarderTHMLinuxGit, HMAC, GPG
InstantHTBLinuxCPTS, Mobile, Android APK, API
UltraTechTHMLinuxNodeJS, API, Docker

Hard (1)

MachinePlatformOSTags
BorderlandsTHMLinuxPivoting, API, Docker

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox