API and Web Application Logic Abuse: practice machines and key commands
APIs expose application logic directly, so flaws are usually about authorisation rather than memory safety. Map every endpoint from documentation, JavaScript files and traffic in Burp, then test each one for missing access control: change object identifiers to read other users data (IDOR), call admin routes with a normal token and replay requests without authentication. Check JSON bodies for mass assignment by adding unexpected fields such as role or isAdmin. JWTs need their algorithm and secret examined, and GraphQL introspection can reveal the full schema. Exposed .git directories and old API versions often leak source and credentials. Rate limits and verbose errors are also worth noting. The machines listed centre on web application and API weaknesses. Test with at least two accounts so access control gaps become obvious.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
GraphQL Schema Introspection Query
Query GraphQL endpoint for full type schema, queries, mutations, and hidden fields.
curl -s -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name,fields{name}}}}"}' http://{TARGET_IP}/graphql | jq .JWT Secret Key HMAC-SHA256 Cracking
Crack HS256 signed JSON Web Token secrets offline using rockyou wordlist.
hashcat -m 16500 jwt.txt /usr/share/wordlists/rockyou.txtExposed .git Source Code Extraction
Dump full repository commits and source code from misconfigured public /.git/ directory.
git-dumper http://{TARGET_IP}/.git/ ./git-dumpffuf Parameter Discovery (GET/POST)
Fuzz hidden query parameters on target page.
ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -u "http://{TARGET_IP}/index.php?FUZZ=test" -acffuf Directory & Endpoint Fuzzing
High-speed directory enumeration with auto-calibrated filtering and extension recursion.
ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak,.js -ac -mc 200,301,302,403
Keep going
- Methodology: Phase 03: Vulnerability Identification & Threat Modeling
- Cheatsheet: Web & Directory Fuzzing
API and Web Application Logic Abuse machines (13)
3 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 13 Linux.
Very Easy (1)
| Machine | Platform | OS |
|---|---|---|
| Oopsie | HTB | Linux |
Easy (7)
| Machine | Platform | OS |
|---|---|---|
| Cap | HTB | Linux |
| Corridor | THM | Linux |
| Neighbour | THM | Linux |
| Busqueda | HTB | Linux |
| Help | HTB | Linux |
| Vulnversity | THM | Linux |
| Whiterose | THM | Linux |
Medium (4)
| Machine | Platform | OS |
|---|---|---|
| Git Happens | THM | Linux |
| Harder | THM | Linux |
| Instant | HTB | Linux |
| UltraTech | THM | Linux |
Hard (1)
| Machine | Platform | OS |
|---|---|---|
| Borderlands | THM | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox