BigHugger
sk Skill · mukul975

exploiting-mass-assignment-in-rest-apis

Discovers and exploits mass assignment (autobinding) in REST APIs by injecting unexpected or hidden parameters (e.g. role, isAdmin, plan) into create/update requests, using Burp Suite Intruder, Arjun, and param-miner to find bindable fields on ORM-backed endpoints (Rails, Django, Laravel, Spring). Use when testing REST APIs for privilege escalation or authorization bypass via unintended parameter binding.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonowasp-apiparameter-injectionbashrest-apiprivilege-escalationautobindingapi-securitymass-assignment
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python