
BlackHat Arsenal 2024 で発表 (Link)
/swagger-ui/index.html エンドポイントに対してのみ概念実証を生成APIDetector v3 には Python 3.x と以下のパッケージが必要です:
flask # Web フレームワーク
requests # HTTP クライアント
playwright # スクリーンショット用ブラウザ自動化
nest_asyncio # Async IO サポート
すべての依存関係は requirements.txt に記載されており、セットアップ時に自動的にインストールされます。
必要なパッケージをインストールした後、Playwright ブラウザをインストールする必要があります:
python -m playwright install
これはスクリーンショット機能を正しく動作させるために必要です。
git clone https://github.com/brinhosa/apidetector.git
cd apidetector
# macOS/Linux の場合:
python3 -m venv venv
source venv/bin/activate
# Windows の場合:
python -m venv venv
venv\Scripts\activate
pip install -r requirements.txt
playwright install
python app.py
python app.py --port 8080 --host 0.0.0.0
ブラウザを開き、ターミナルに表示された URL にアクセスします。
Web インターフェースの使い方:
スクリーンショットは後で参照できるよう screenshots ディレクトリに保存されます。
APIDetector v3 では、最新の Web インターフェース(v3 の新機能)と従来のコマンドラインインターフェース(オリジナル)の 2 つの操作方法を提供しています。
python app.py [options]
使用可能なオプション:
| オプション | 説明 | デフォルト |
|---|---|---|
-p, --port | ポート番号 | 5000 |
--host | ホストアドレス | 127.0.0.1 |
-d, --debug | デバッグモードを有効にする | False |
例:
# デフォルト設定で実行 (localhost:5000)
python app.py
# カスタムポートで実行
python app.py -p 8080
# 外部アクセスを許可
python app.py --host 0.0.0.0
# デバッグモードで実行
python app.py -d
Web インターフェースにアクセス:
結果を表示:
コマンドラインで APIDetector を実行します。以下に使用例を示します:
一般的な使用方法: 30 スレッド、Chrome ユーザーエージェントでサブドメインリストをスキャンし、結果をファイルに保存:
python apidetector.py -i list_of_company_subdomains.txt -o results_file.txt -t 30 -ua "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36"
単一ドメインのスキャン:
python apidetector.py -d example.com
ファイルから複数ドメインをスキャン:
python apidetector.py -i input_file.txt
出力ファイルを指定:
python apidetector.py -i input_file.txt -o output_file.txt
特定のスレッド数を使用:
python apidetector.py -i input_file.txt -t 20
HTTP と HTTPS の両方のプロトコルでスキャン:
python apidetector.py -m -d example.com
静音モードで実行(詳細出力を抑制):
python apidetector.py -q -d example.com
カスタムユーザーエージェントで実行:
python apidetector.py -d example.com -ua "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36"
APIDetector v2 を使用している場合は、コマンドを apidetectorv2.py に置き換えてください。
-d, --domain: テストする単一のドメイン。-i, --input: テストするサブドメインを含む入力ファイル。-o, --output: 有効な URL を書き込む出力ファイル。-t, --threads: スキャンに使用するスレッド数(デフォルトは 10)。-m, --mixed-mode: HTTP と HTTPS の両方のプロトコルをテスト。-q, --quiet: 詳細出力を無効にする(デフォルトモードは詳細)。-ua, --user-agent: リクエストのカスタム User-Agent 文字列。Swagger や OpenAPI のドキュメントエンドポイントを公開すると、主に情報漏洩に関連するさまざまなリスクが生じる可能性があります。以下は、潜在的なリスクレベルに基づいて並べたリストで、類似のエンドポイントを APIDetector がスキャンするグループとしてまとめています。
'/swagger-ui.html', '/swagger-ui/', '/swagger-ui/index.html', '/api/swagger-ui.html', '/documentation/swagger-ui.html', '/swagger/index.html', '/api/docs', '/docs', '/api/swagger-ui', '/documentation/swagger-ui''/openapi.json', '/swagger.json', '/api/swagger.json', '/swagger.yaml', '/swagger.yml', '/api/swagger.yaml', '/api/swagger.yml', '/api.json', '/api.yaml', '/api.yml', '/documentation/swagger.json', '/documentation/swagger.yaml', '/documentation/swagger.yml''/v2/api-docs', '/v3/api-docs', '/api/v2/swagger.json', '/api/v3/swagger.json', '/api/v1/documentation', '/api/v2/documentation', '/api/v3/documentation', '/api/v1/api-docs', '/api/v2/api-docs', '/api/v3/api-docs', '/swagger/v2/api-docs', '/swagger/v3/api-docs', '/swagger-ui.html/v2/api-docs', '/swagger-ui.html/v3/api-docs', '/api/swagger/v2/api-docs', '/api/swagger/v3/api-docs''/swagger-resources', '/swagger-resources/configuration/ui', '/swagger-resources/configuration/security', '/api/swagger-resources', '/api.html'