Hack EVERY API! KiteRunner - Hacker Tools

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ส.ค. 2024
  • 👨‍💻🛠️​ In this week's episode of Hacker Tools, we will take a look at KiteRunner.
    00:00 Introduction
    00:15 Why do we need API enumeration?
    00:40 What is KiteRunner?
    01:40 Running KiteRunner
    03:00 Checking out KiteRunner wordlists and bruteforces
    06:15 Checking the results
    07:00 Outro
    ---
    📰 Check out the accompanying blog post here: blog.intigriti.com/2021/09/07...
    🧑‍💻 Sign up and start hacking right now - go.intigriti.com/register
    👾 Join our Discord - go.intigriti.com/discord
    🎙️ This show is hosted by / pinkdraconian & / intigriti
    👕 Do you want some Intigriti Swag? Check out swag.intigriti.com/

ความคิดเห็น • 30

  • @redteamgarage299
    @redteamgarage299 9 หลายเดือนก่อน

    Very informative ❤

    • @intigriti
      @intigriti  9 หลายเดือนก่อน

      Glad it was helpful!

  • @droidhackerr
    @droidhackerr 2 ปีที่แล้ว +1

    wow ... thanks for this.

    • @intigriti
      @intigriti  2 ปีที่แล้ว

      Glad you enjoyed it!

  • @seiv-
    @seiv- 2 ปีที่แล้ว +3

    What’s the difference of this one with gobuster for example ? What extra does this bring ?

    • @intigriti
      @intigriti  2 ปีที่แล้ว +4

      We actually had someone ask this in our Discord as well. So feel free to check that out. Gobuster just bruteforces directories whereas KiteRunner uses the context it's in more.

  • @fahadfaisal2383
    @fahadfaisal2383 2 ปีที่แล้ว +1

    Good!

  • @basitkhan3853
    @basitkhan3853 2 ปีที่แล้ว +1

    Sir I found a endpoint name"admin.sign up" but when I visit this endpoint in a browser I found a empty page in which there are only 2 HTML tag and whole page is empty can you give me some idea how I move on forward

    • @user-uj2km6zr7s
      @user-uj2km6zr7s 2 ปีที่แล้ว +3

      Lol

    • @intigriti
      @intigriti  2 ปีที่แล้ว +1

      This is highly dependent on implementation so without further contextual information, there isn't much I can do I'm afraid ;)

  • @tired409
    @tired409 ปีที่แล้ว

    the one simple scan is taking me just over 4hrs to complete am i doing something wrong?

    • @intigriti
      @intigriti  ปีที่แล้ว

      It could be that the website is very slow, the wordlist large and perhaps your internet a bit slower as well.

  • @juanjoivars3254
    @juanjoivars3254 ปีที่แล้ว

    Whats the difference between scan and brute?

    • @intigriti
      @intigriti  ปีที่แล้ว

      # Use a dirsearch style wordlist with %EXT%
      kr brute target.com/subapp/ -w dirsearch.txt -x 20 -j 1 -exml,asp,aspx,ashx -D
      # You have your own wordlist but you want assetnote wordlists too
      kr scan target.com -w routes.kite -A=apiroutes-210328:20000 -x 20 -j 1 --fail-status-codes 400,401,404,403,501,502,426,411

  • @deepaksaini3257
    @deepaksaini3257 ปีที่แล้ว

    How to download wordlist

    • @intigriti
      @intigriti  ปีที่แล้ว

      KiteRunner will do that for you!

  • @crusader_
    @crusader_ 2 ปีที่แล้ว +1

    Could you cover a waf detection tool

    • @intigriti
      @intigriti  2 ปีที่แล้ว

      Do you have any examples of tools for that?

    • @crusader_
      @crusader_ 2 ปีที่แล้ว

      Wafwoof. But I'm not sure if it's the best one out there.

    • @InsaneRecords997
      @InsaneRecords997 ปีที่แล้ว

      @@crusader_ bro wafw00f is used to detect waf technology behind web app

  • @tcib5055
    @tcib5055 2 ปีที่แล้ว

    'kr' is not recognized as an internal or external command

    • @intigriti
      @intigriti  2 ปีที่แล้ว

      Make sure the binary is in your PATH.

  • @yuhiahtyun5665
    @yuhiahtyun5665 2 ปีที่แล้ว +1

    noice

  • @tcib5055
    @tcib5055 2 ปีที่แล้ว

    " " or " "
    get error The filename, directory name, or volume label syntax is incorrect
    but type localhost:8080 to pass