de56d1f494
HTTP/AI adversarial fuzzer. Stripped finding database and internal testing framework references. Configs sanitized.
34 lines
1007 B
YAML
34 lines
1007 B
YAML
# ── Fuzzer Config: OAuth2 client credentials -> API endpoint ──────────────
|
|
#
|
|
# Placeholders:
|
|
# {{FUZZ}} — replaced with each payload from your wordlist
|
|
# {{AUTH}} — bearer token (auto-filled after auth step)
|
|
# {{KEY}} — any key from your vars file ({{TOKEN}}, {{USERNAME}}, etc.)
|
|
|
|
name: "OAuth2 API Fuzz"
|
|
|
|
auth:
|
|
url: "https://auth.example.com/oauth2/token"
|
|
# method: POST # default
|
|
# headers:
|
|
# Authorization: "Basic {{CLIENT_CREDS}}"
|
|
# Content-Type: "application/x-www-form-urlencoded"
|
|
# body: "grant_type=client_credentials" # default
|
|
token_field: "access_token"
|
|
cache: 280
|
|
|
|
request:
|
|
url: "https://api.example.com/v1/query"
|
|
method: POST
|
|
headers:
|
|
Authorization: "Bearer {{AUTH}}"
|
|
Content-Type: "application/json"
|
|
body: '{"prompt": "{{FUZZ}}"}'
|
|
fuzz_encoding: json
|
|
|
|
settings:
|
|
skip_tls_verify: false
|
|
timeout: 30
|
|
delay: 0
|
|
# proxy: "http://127.0.0.1:8080"
|