01 Recon02 Vulnerabilidades03 Recursos

Recon

Enumeración pasiva

  • Certificate transparency: cada cert SSL es registro público (crt.sh).
  • Subfinder pasivo + assetfinder, merge y dedup.
copiar✕
# cert transparency
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | anew crtsh.txt
subfinder -d target.com -all -silent > subs_sf.txt
assetfinder --subs-only target.com > subs_af.txt
cat subs_*.txt | sort -u > all_subs.txt

Enumeración activa

  • Bruteforce DNS + permutación (puredns).
  • Monitoreo de cert transparency en vivo (gungnir).
  • Hosts vivos + enriquecimiento (httpx) y screenshots (gowitness).
  • Puertos + servicios (naabu).
  • Escaneo automatizado por templates (nuclei).
copiar✕
# puredns
puredns bruteforce $DNS_WORDLIST target.com -r resolvers.txt -o subs_pd.txt
# gungnir
gungnir -d target.com
copiar✕
cat all_subs.txt | httpx -silent -status-code -title -tech-detect -web-server -follow-redirects -o alive.txt
# screenshot para ver visualmente
gowitness file -f alive.txt -P ./shots/
copiar✕
naabu -list alive.txt -p - -rate 1000 -c 50 -nmap-cli 'nmap -sV -sC' -o ports.txt
copiar✕
nuclei -l alive.txt -t nuclei-templates/http/ -severity critical,high,medium -rl 30 -o nuclei.txt
nuclei -l alive.txt -t nuclei-templates/http/exposures/

JavaScript & Secretos

  • URLs históricas + crawling (gau, waybackurls, katana).
  • Categorizar URLs por clase de bug (grep).
  • Parámetros y endpoints ocultos (linkfinder, arjun).
  • Secretos / API keys en JS (mantra, trufflehog).
copiar✕
cat alive.txt | gau --threads 200 > urls_gau.txt
cat alive.txt | waybackurls > urls_wb.txt
# katana: JS crawler
katana -u alive.txt -jc -kf all -d 5 -headless -silent > urls_kat.txt
cat urls_*.txt | anew all_urls.txt
copiar✕
grep -iE '.js(?|$)' all_urls.txt > js_urls.txt
grep -Ei "login|signin|auth|oauth|reset" all_urls.txt > auth.txt
grep -Ei '[0-9]{2,}' all_urls.txt > idor_candidates.txt
grep -Ei "redirect|callback|goto|return|url=" all_urls.txt > openredir.txt
copiar✕
# linkfinder: endpoints dentro del JS
python3 linkfinder.py -i https://target.com/app.js -o cli
# arjun: parámetros GET/POST no documentados
arjun -u "https://target.com/api" -m GET --stable
copiar✕
# mantra: scanner de secretos en JS
cat js_urls.txt | mantra
# trufflehog: solo secretos verificados
trufflehog github --org=target --token=$GITHUB_TOKEN --only-verified

Enumeración de endpoints de API

  • Fuzz de rutas API con wordlist específica.
  • Probar versiones/prefijos: /api/v2, /api/internal, /api/beta.
copiar✕
ffuf -u https://api.target.com/FUZZ -w apiroutes.txt -mc 200,201,204,301,302,401,403 -ac -t 40

Fuzzing general

  • Fuzzing de directorios.
  • Fuzzing por extensión de archivo.
  • Fuzzing de VHOST / subdominios por Host header.
copiar✕
# directorios
ffuf -w /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u https://target.com/FUZZ
# por extensión
ffuf -w /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u https://target.com/FUZZ.js
copiar✕
# subdominios por Host header
ffuf -u https://target.com -H "Host: FUZZ.target.com" -w /usr/share/wordlists/subdomains.txt -t 100 -fc 403 | tee ffuf_subs.txt
02

Vulnerabilidades

Vulnerabilidades en APIs

  • IDOR: Objeto de otro usuario accesible cambiando un ID.
  • Mass assignment: mandás campos que el server no esperaba.
  • Broken auth: endpoints que no revalidan sesión/permiso.
  • Excessive data exposure: el endpoint devuelve más de lo que la UI muestra.

Configuraciones y headers

  • Headers de seguridad: CSP, HSTS, X-Frame-Options, X-Content-Type.
  • Archivos viejos/backup sin referencia (.bak, .old, .zip, .DS_Store).
  • Métodos HTTP habilitados (PUT, DELETE, TRACE).
  • Host Header Injection: Host, X-Forwarded-Host, X-Forwarded-For, X-HTTP-Host-Override.
copiar✕
nuclei -u https://target.com -t nuclei-templates/http/misconfiguration/ -t nuclei-templates/http/exposures/
curl -sk -i -X OPTIONS https://target.com | grep -i "allow|^x-|content-security"

Autenticación

  • Enum de usuarios (error o timing distinto en login/reset).
  • Bypass de auth, logins default.
  • Flujo de reset: token predecible/reusable, host header en el link.
  • MFA: bypass por response manipulation, sin rate-limit en el OTP.

Sesión & CSRF

  • Flags de cookie: httpOnly, Secure, SameSite; scope (path/domain).
  • Token nuevo al login y al cambiar de rol; invalidación real al logout.
  • Fixation, session puzzling, sesiones simultáneas.
  • CSRF en acciones sensibles (sin token o SameSite=None sin validar).
copiar✕
# aleatoriedad de tokens
curl -sk -I https://target.com | grep -i set-cookie

Autorización

  • Endpoints con ID (numérico o UUID): cambialo entre dos cuentas tuyas.
  • Escalada vertical (user -> admin) y horizontal (user -> otro user).
  • Path traversal, forced browsing a rutas admin, falta de authz.
  • Intentá acciones/permisos que suelen ser solo de admin.

Inyecciones

  • XXE (XML con DOCTYPE externo), NoSQL ([$ne]=), XPath.
  • Open Redirect, HTTP Request Smuggling, HTTP Verb Tampering.
  • HTTP Parameter Pollution, client-side vs server-side.
  • XSS
  • SQL Injection
  • Local File Inclusion
  • Server-Side Request Forgery
  • Command Injection
  • Server-Side Template Injection
copiar✕
# dalfox
cat params.txt | dalfox pipe -o xss.txt
dalfox url "https://target.com/?q=test"
copiar✕
# sqlmap: SQL Injection
sqlmap -u "https://target.com/item?id=1" --batch --random-agent --dbs
sqlmap -r request.txt --batch --level 3 --risk 2
# SSRF: metadata cloud
https://target.com/fetch?url=http://169.254.169.254/latest/meta-data/