Vulnerability Testing Patterns
Purpose: Use this file when testing runtime exploitability for web apps, REST APIs, GraphQL, OAuth, SQLi, XSS, or session-aware flows.
Contents
- Payload families
- REST API checks
- GraphQL checks
- OAuth 2.0 checks
- Proof-safe validation notes
Proof-Safe Payload Families
Use harmless markers first. Escalate only when scope and environment allow it.
| Class | Example payloads | Notes |
|---|---|---|
| SQL injection | ' OR '1'='1, ' UNION SELECT NULL--, SLEEP(5) |
Prefer timing or harmless marker queries over destructive statements |
| XSS | <script>alert(1)</script>, "><svg/onload=alert(1)> |
Prefer inert custom markers in controlled environments |
| Command injection | ; echo probe-marker |
Avoid system-changing commands |
| SSRF | http://127.0.0.1, http://169.254.169.254, controlled collaborator endpoint |
Verify safely and avoid persistence |
| Path traversal | ../../../../etc/hostname |
Read-only checks only |
REST API Checklist
Always consider these areas:
| Area | What to test |
|---|---|
| Authentication | JWT signature, expiration, revocation, MFA gaps, reset flow |
| Authorization | BOLA, BFLA, object ownership, role escalation |
| Input validation | SQLi, XSS, command injection, path traversal, schema abuse |
| Data exposure | Excess fields, secret leakage, internal identifiers |
| Abuse controls | Rate limiting, pagination limits, bulk operations |
GraphQL Testing
Priority Scenarios
| Scenario | Severity | What to verify |
|---|---|---|
| Introspection exposure | MEDIUM |
Disabled or protected in production |
| Query depth abuse | HIGH |
Depth and complexity limits |
| Batch or alias overload | MEDIUM |
Resource protection and throttling |
| Field suggestion leak | LOW |
Error hygiene and schema leakage |
| Variable injection | CRITICAL |
Server-side validation and resolver safety |
| Authorization bypass | HIGH |
Field-level authorization |
GraphQL Checklist
- Introspection disabled or restricted in production
- Query depth limit is enforced
- Complexity limit or equivalent exists
- Field-level authorization exists for sensitive objects
- Error messages do not leak schema details
OAuth 2.0 Testing
Priority Scenarios
| Scenario | Severity | What to verify |
|---|---|---|
| Redirect URI validation | CRITICAL |
Strict allowlist matching |
| PKCE enforcement | HIGH |
Required for public clients |
| Authorization code replay | HIGH |
One-time use and short lifetime |
| State parameter CSRF | HIGH |
Required and validated |
| Scope manipulation | HIGH |
No unauthorized privilege expansion |
| Token replay | HIGH |
Revocation, rotation, audience binding |
OAuth Checklist
- Redirect URIs are exact-match or strict-match validated
- PKCE is mandatory for public clients
- Authorization code lifetime is
<10 min stateis required and verified- Refresh and access token handling respects audience and scope boundaries
Authorization-Focused Defaults
When scope includes authenticated APIs, prioritize:
BOLABFLA- Mass assignment / BOPLA-style property abuse
- Session and token misuse
- Rate-limit bypass on auth-sensitive endpoints
LLM / Agent Surface Defaults (2026)
When the target embeds an LLM endpoint, RAG retrieval, or an agentic / MCP server, add these dynamic checks alongside the API Top 10 pass — see reference/llm-agent-security-2026.md for the catalogue and tooling.
| Surface | Primary dynamic check |
|---|---|
| Direct prompt injection (LLM01) | Send Ignore prior instructions... style payloads; observe whether system prompt or downstream tool is influenced |
| Indirect prompt injection / Agent Goal Hijacking (ASI01) | Plant marker instructions in RAG-ingestable content / tool output; observe whether the agent executes them |
| Sensitive Information Disclosure (LLM02) | Ask the model to reveal system prompt, training-data secrets, vector-DB content; verify no PII / API key leak |
| Excessive Agency (LLM06) | Trigger tool calls outside the documented scope; confirm allow-list enforcement |
| Vector / Embedding Weaknesses (LLM08) | Inject poisoned documents into RAG index; verify retrieval grounding and authz |
| Unbounded Consumption (LLM10) | Long-context, recursion, and token-bomb payloads; verify quotas |
| MCP server enumeration | tools/list without auth, tool-name shadowing, tool-description injection (315 MCP CVEs in 2025 per Wallarm) |
Output Requirements
For each tested pattern, record:
- Endpoint or flow
- Identity or role used
- Payload or mutation attempted
- Expected behavior
- Actual behavior
- Safe proof or reason it remains unconfirmed
Per-Recipe Behavior (SKILL.md excerpt)
Behavior notes per Recipe:
zap: Default Recipe. Authenticated ZAP baseline (PR) or full active (staging/nightly). Use Zest scripts for multi-step login, TOTP, Client Script Auth. PTK add-on for combined DAST+IAST+SAST+SCA in one browser session.burp: Burp Suite Professional / Enterprise with Intruder, Repeater, Autorize (BOLA). Preferred for manual exploit chaining and multi-identity authz testing. Pair with Collaborator for OOB checks.nuclei: Template-based targeted scanning (12,000+ templates, incl. GCP/Azure/K8s). Pin template versions, verify sources (CVE-2024-43405). Default rate150 req/s; reduce to30-50on prod-adjacent. Review AI-generated templates manually.pentest: Full PLAN→REPORT engagement. Scope, authorization, threat model, attack-path chaining. Output is a complete assessment report with CVSS v4.0, SLAs, and agent handoffs.api: REST / GraphQL / WebSocket DAST. Requires written scope AND 2+ identities at different privilege tiers (single-identity scans cannot detect BOLA/BFLA). Run schemathesis + restler for stateful fuzz; Autorize for BOLA sweep; graphql-cop for GraphQL audit. Cross-link to Sentinel for static-first findings and Gateway when the flaw is spec-level (missingsecurity:, CORS wildcard). BOLA alone is ~40% of API attacks — always include.mobile: Dynamic testing of built iOS/Android binaries against OWASP MASVS 2.0 / MASTG. Requires written scope explicitly authorizing Frida instrumentation and SSL pinning bypass before use. MobSF for static+dynamic orchestration, Frida/Objection for runtime hooks, Burp for MITM post-pinning-bypass, Drozer for Android IPC. Cross-link to Sentinel for source-level audit and Native for remediation/rebuild. Test release builds, not debug.recon: Passive-by-default external attack-surface mapping. Output is an inventory, NOT a pentest — no exploitation, no auth attempts, no active vuln scans without separate written scope. Subfinder + amass passive + assetfinder + crt.sh for subdomains; dnsx passive resolve; httpx single-GET fingerprint; trufflehog on public repos; HIBP for leaked-credential counts (never log in to verify). Feeds prioritized targets tozap/nuclei/api/mobile/pentest. Cross-link to Breach for full red-team engagement —reconis the recon-only slice, Breach owns the adversary scenario.