Files
Operator de56d1f494 Initial public release
HTTP/AI adversarial fuzzer. Stripped finding database and internal
testing framework references. Configs sanitized.
2026-06-23 16:23:20 -04:00

34 lines
1007 B
YAML

# ── Fuzzer Config: OAuth2 client credentials -> API endpoint ──────────────
#
# Placeholders:
# {{FUZZ}} — replaced with each payload from your wordlist
# {{AUTH}} — bearer token (auto-filled after auth step)
# {{KEY}} — any key from your vars file ({{TOKEN}}, {{USERNAME}}, etc.)
name: "OAuth2 API Fuzz"
auth:
url: "https://auth.example.com/oauth2/token"
# method: POST # default
# headers:
# Authorization: "Basic {{CLIENT_CREDS}}"
# Content-Type: "application/x-www-form-urlencoded"
# body: "grant_type=client_credentials" # default
token_field: "access_token"
cache: 280
request:
url: "https://api.example.com/v1/query"
method: POST
headers:
Authorization: "Bearer {{AUTH}}"
Content-Type: "application/json"
body: '{"prompt": "{{FUZZ}}"}'
fuzz_encoding: json
settings:
skip_tls_verify: false
timeout: 30
delay: 0
# proxy: "http://127.0.0.1:8080"