API Fuzzing Bug Bounty

当在授权的漏洞赏金或渗透测试中需要对 REST/SOAP/GraphQL API 做侦察、模糊测试与越权挖掘时使用;做端点枚举、IDOR/BOLA、注入、鉴权绕过、403 绕过与 GraphQL 内省/批处理攻击并产出可复现 PoC 与漏洞清单;不适用于未授权目标、生产破坏性攻击或前端 UI/业务逻辑测试。触发词:API 模糊测试、IDOR、GraphQL 内省、鉴权绕过、Swagger 枚举、漏洞赏金

findscripter 6c3c75e 6.9 KB Updated

File contents

findscripter/everything-skills/tree/main/08-security/api-fuzzing-bug-bounty commit 6c3c75e627

Frequently asked questions

npx skillmds@latest add findscripter/api-fuzzing-bug-bounty