logo
logo
Sign in

How to Find Hidden HTTP Parameters to Discover Weaknesses in Web Application

avatar
jack henry
How to Find Hidden HTTP Parameters to Discover Weaknesses in Web Application

HTTP parameters most of time also called query strings, and it is also part of URL may takes input and enable it to web application here are the example that looks like.

http://example.com/name?id=1

When your server receives your request, then it will procedure the query then return to a valid name with ID. Most of the time, in the web form; several fields have been submitted to start the query. Here are the examples that look like.

http://example.com/form?field1=v1&field2=v2

In some cases, a few of the parameters may be hidden in the list. For example, when anunseen parameter admin was setting as True, then there may be another function of that regular user.

Arjun tools are a command-line device that discovers unseen HTTP parameters through a wordlist on Parameter names. Its feature has several-threading, limit handling rate, and allows customer header to added requests. It support POST, JSON, and GET methods, it also making precious resource for issuing web app.

Download and Setup

Here you can use Metaspoitable 2 is a huge Kali Linux into local machine, and you can also use what you want to comfortable with the following along.

The first obsession you need to do is downloading Arjun from GitHub. You can simply clone a copy of the depository through git clone command.

Here are the steps on how to download setup:

Source: https://medium.com/@mcafeecloudsecurity/how-to-find-hidden-http-parameters-to-discover-weaknesses-in-web-application-10cd424e1a39

collect
0
avatar
jack henry
guide
Zupyak is the world’s largest content marketing community, with over 400 000 members and 3 million articles. Explore and get your content discovered.
Read more