Context#
A reachable /swagger-ui, /openapi.json, or similar endpoint publishes the contract the server thinks it implements. The offensive value is full path and parameter coverage for planning BOLA, injection, and function-level tests, often including deprecated or internal-tagged operations.
Theory#
Hand-written specs can diverge from code; codegen specs track code more closely. Either way, the file is a recon artifact. Browsers with an active session may issue “try it” requests from the same origin, which matters for how you chain with other issues in a lab; treat the doc endpoint as part of the same site model as the API for session and CSRF experiments when those are in scope.
Practice#
Fetch the machine-readable spec#
curl -sStheopenapi.jsonorswagger.jsonURL in scope, or download from the UI’s network tab. Parse paths and methods into a matrix for role testing.
Tag and version triage#
- Read
tags,x-internal, and path/v1vs/v2blocks. Older version blocks often keep weaker handlers live.
Tools#
- curl
- jq
- Burp Suite