
멀티스레드 스캐너로, 웹 도메인 및 서브도메인에서 노출된 Swagger/OpenAPI 엔드포인트를 탐지하며, 자동 XSS 탐지, PoC 생성, 오탐 필터링 기능을 갖춘 API 보안 평가 도구입니다.
BlackHat Arsenal 2024에서 발표됨 (링크)
/swagger-ui/index.html 엔드포인트에 대해서만 개념 증명 생성APIDetector v3는 Python 3.x와 다음 패키지가 필요합니다:
flask # 웹 프레임워크
requests # HTTP 클라이언트
playwright # 스크린샷을 위한 브라우저 자동화
nest_asyncio # Async IO 지원
모든 종속성은 requirements.txt에 나열되어 있으며 설정 중에 자동으로 설치할 수 있습니다.
필요한 패키지를 설치한 후, Playwright 브라우저를 설치해야 합니다:
python -m playwright install
스크린샷 기능이 제대로 작동하려면 이 작업이 필요합니다.
git clone https://github.com/brinhosa/apidetector.git
cd apidetector
# macOS/Linux:
python3 -m venv venv
source venv/bin/activate
# Windows:
python -m venv venv
venv\Scripts\activate
pip install -r requirements.txt
playwright install
python app.py
python app.py --port 8080 --host 0.0.0.0
브라우저를 열고 터미널에 표시된 URL로 이동합니다.
웹 인터페이스 사용:
스크린샷은 나중에 참조할 수 있도록 screenshots 디렉토리에 저장됩니다.
APIDetector v3는 최신 웹 인터페이스(v3의 새로운 기능)와 기존 명령줄 인터페이스(원본)라는 두 가지 상호 작용 방법을 제공합니다.
python app.py [옵션]
사용 가능한 옵션:
| 옵션 | 설명 | 기본값 |
|---|---|---|
-p, --port | 포트 번호 | 5000 |
--host | 호스트 주소 | 127.0.0.1 |
-d, --debug | 디버그 모드 활성화 | False |
예시:
# 기본 설정으로 실행 (localhost:5000)
python app.py
# 사용자 지정 포트로 실행
python app.py -p 8080
# 외부 액세스 허용
python app.py --host 0.0.0.0
# 디버그 모드로 실행
python app.py -d
웹 인터페이스 접속:
결과 보기:
명령줄을 사용하여 APIDetector를 실행하세요. 몇 가지 사용 예시는 다음과 같습니다:
일반적인 사용: Chrome 사용자 에이전트를 사용하여 30개 스레드로 서브도메인 목록을 스캔하고 결과를 파일에 저장:
python apidetector.py -i list_of_company_subdomains.txt -o results_file.txt -t 30 -ua "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36"
단일 도메인 스캔:
python apidetector.py -d example.com
파일에서 여러 도메인 스캔:
python apidetector.py -i input_file.txt
출력 파일 지정:
python apidetector.py -i input_file.txt -o output_file.txt
특정 스레드 수 사용:
python apidetector.py -i input_file.txt -t 20
HTTP 및 HTTPS 프로토콜 모두 스캔:
python apidetector.py -m -d example.com
자동 모드로 스크립트 실행 (자세한 출력 억제):
python apidetector.py -q -d example.com
사용자 정의 사용자 에이전트로 스크립트 실행:
python apidetector.py -d example.com -ua "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36"
APIDetector v2를 사용하는 경우 명령어를 apidetectorv2.py로 바꾸세요.
-d, --domain: 테스트할 단일 도메인.-i, --input: 테스트할 서브도메인이 포함된 입력 파일.-o, --output: 유효한 URL을 쓸 출력 파일.-t, --threads: 스캔에 사용할 스레드 수 (기본값은 10).-m, --mixed-mode: HTTP와 HTTPS 프로토콜 모두 테스트.-q, --quiet: 자세한 출력 비활성화 (기본 모드는 자세한 모드).-ua, --user-agent: 요청에 사용할 사용자 정의 User-Agent 문자열.Swagger 또는 OpenAPI 문서 엔드포인트를 노출하면 주로 정보 공개와 관련된 다양한 위험이 발생할 수 있습니다. 다음은 잠재적 위험 수준에 따라 정렬된 목록으로, 유사한 엔드포인트를 함께 그룹화했습니다. APIDetector가 스캔합니다:
'/swagger-ui.html', '/swagger-ui/', '/swagger-ui/index.html', '/api/swagger-ui.html', '/documentation/swagger-ui.html', '/swagger/index.html', '/api/docs', '/docs', '/api/swagger-ui', '/documentation/swagger-ui''/openapi.json', '/swagger.json', '/api/swagger.json', '/swagger.yaml', '/swagger.yml', '/api/swagger.yaml', '/api/swagger.yml', '/api.json', '/api.yaml', '/api.yml', '/documentation/swagger.json', '/documentation/swagger.yaml', '/documentation/swagger.yml''/v2/api-docs', '/v3/api-docs', '/api/v2/swagger.json', '/api/v3/swagger.json', '/api/v1/documentation', '/api/v2/documentation', '/api/v3/documentation', '/api/v1/api-docs', '/api/v2/api-docs', '/api/v3/api-docs', '/swagger/v2/api-docs', '/swagger/v3/api-docs', '/swagger-ui.html/v2/api-docs', '/swagger-ui.html/v3/api-docs', '/api/swagger/v2/api-docs', '/api/swagger/v3/api-docs''/swagger-resources', '/swagger-resources/configuration/ui', '/swagger-resources/configuration/security', '/api/swagger-resources', '/api.html'APIDetector에 대한 기여를 환영합니다! 저장소를 포크하고, 변경하고, 풀 리퀘스트를 제출해 주십시오. 테스트와 기능 제안에 도움을 준 기여자분들께 특별히 감사드립니다: