Skip to content

Latest commit

 

History

History
163 lines (115 loc) · 4.4 KB

File metadata and controls

163 lines (115 loc) · 4.4 KB

Manual Tools

PTK is not only a scanner. The manual tools help you inspect browser state, replay requests, test tokens, and build reproducible proof.

Proxy and Traffic Log

The Proxy/traffic log captures browser-generated HTTP traffic. Use it to understand how the app actually communicates.

Look for:

  • API routes with user IDs, object IDs, filters, search terms, and sort fields
  • state-changing requests
  • redirects and callback URLs
  • file upload/download routes
  • GraphQL or JSON APIs
  • role-specific endpoints
  • requests that include JWTs, session cookies, CSRF tokens, or custom auth headers

Send interesting requests to R-Builder for targeted testing.

R-Builder / Request Builder

R-Builder lets you edit, replay, clone, export, and scan individual requests.

Basic Workflow

  1. Select a request from the traffic log.
  2. Send it to R-Builder.
  3. Change one thing at a time: parameter, header, method, body field, cookie, or token.
  4. Replay the request.
  5. Compare response status, body, redirects, timing, and side effects.
  6. Save useful evidence.

Useful Manual Tests

  • change numeric IDs to another user's ID
  • remove or modify authorization headers
  • replay state-changing requests
  • test parameter pollution
  • change content type or method
  • remove CSRF tokens
  • change JSON types: string to array, object, null, number, or boolean
  • inject XSS, SQLi, command, or template payloads where authorized
  • test redirect parameters with same-origin and off-origin URLs

Copy as cURL

Use cURL export when you need:

  • a report reproduction command
  • a quick retest outside the browser
  • a handoff to another tool
  • evidence that can be replayed in a controlled environment

Redact cookies, tokens, and personal data before sharing.

JWT Inspector

Use JWT Inspector to decode, inspect, craft, and test JSON Web Tokens.

Watch: How to solve JWT PortSwigger labs using OWASP PTK

Where to Look

JWTs commonly appear in:

  • Authorization: Bearer ...
  • cookies
  • localStorage
  • sessionStorage
  • API responses
  • WebSocket or event-stream setup requests

JWT Checks

Common checks include:

  • alg: none acceptance
  • weak HMAC secrets
  • algorithm confusion
  • untrusted jku, jwk, or kid
  • missing issuer/audience validation
  • stale or overly long expiration
  • privilege claims accepted from client-controlled tokens
  • token accepted from an unexpected carrier, such as cookie vs header

JWT Evidence

Record:

  • token location
  • original header and claims
  • modified header and claims
  • exact request where the token was used
  • server response
  • why the behavior proves a security weakness

Never publish full live tokens in reports. Redact secrets and signatures when possible.

Cookies and Storage

Review cookies and browser storage because modern apps often split session state across multiple browser surfaces.

Cookie Checklist

  • Secure
  • HttpOnly
  • SameSite
  • domain and path scope
  • expiration
  • session vs persistent behavior
  • sensitive values readable by JavaScript
  • duplicate session cookies
  • weak or unsigned preference/auth cookies

Storage Checklist

Review:

  • localStorage
  • sessionStorage
  • IndexedDB
  • service-worker caches
  • tokens stored in JavaScript-readable locations
  • role, tenant, or feature flags controlled by storage

Test whether changing storage values affects authorization, feature access, or API calls.

Request Smuggling Research

Request smuggling tests can be disruptive. Only run them when explicitly authorized.

Watch: OWASP PTK #8 4 3 request smuggling

Safe workflow:

  1. Confirm scope and testing window.
  2. Use non-production if possible.
  3. Start with low request volume.
  4. Capture exact raw requests and responses.
  5. Stop immediately if instability appears.
  6. Report impact carefully and include infrastructure context.

Collect:

  • frontend and backend indicators
  • raw request pair
  • response timing and desynchronization evidence
  • affected host/path
  • reproducibility notes

Decoder, Encoder, Swagger, and Utilities

Use Decoder/Encoder for:

  • URL encoding/decoding
  • Base64
  • JSON escaping
  • hashing and comparison
  • payload normalization
  • nested token or parameter inspection

Use Swagger/API helpers when OpenAPI or Swagger definitions are available. Compare documented API routes with routes seen in traffic and routes discovered in JavaScript bundles.