Skip to content

App Mapping

Web application mapping is a critical phase in penetration testing, where the goal is to systematically identify and document all accessible endpoints, APIs, and hidden resources within a target application. This process involves analyzing HTTP requests and server responses to uncover the application's structure, potential vulnerabilities, and attack surfaces. By mapping the application, red teams can prioritize exploitation paths and understand how the system interacts with external services or internal components.


Automated Crawling and Discovery

Automated tools are essential for efficiently mapping large or complex web applications. These tools simulate browser behavior, follow links, and test for hidden endpoints.

Tools and Techniques

  • Burp Suite Spider: A built-in crawler in Burp Suite that maps URLs by following links and submitting forms.
    # Example: Use Burp Suite's Spider to crawl a target  
    # (Manual configuration in Burp Suite UI required)  
    
  • Dirsearch: A directory brute-forcing tool that tests common paths like /admin, /login, or /config.
    dirsearch -u https://target.com -e php,txt,html
    
  • Gospider: A fast, recursive spider for discovering endpoints.
    gospider -u https://target.com -o output.txt -d 3
    

Custom Scripts

Python scripts using requests or httpx libraries can automate crawling and filter responses.

import requests
url = "https://target.com"
response = requests.get(url)
print(response.status_code, response.url)


Manual Techniques and HTTP Analysis

Manual exploration complements automation by uncovering subtle clues in HTTP responses.

Checking for Hidden Directories

Test common directories and files:

curl -I https://target.com/admin
curl -I https://target.com/.git
curl -I https://target.com/robots.txt
Look for HTTP status codes (e.g., 200 for success, 403/404 for restricted paths).

Analyzing Server Responses

Inspect headers for metadata:

curl -I https://target.com/api/v1/users
Look for headers like Server, X-Content-Type-Options, or Link (which may indicate pagination or API endpoints).


API Discovery and Enumeration

APIs often expose sensitive endpoints, so dedicated discovery is crucial.

Testing API Endpoints

Use tools like curl or Postman to test endpoints:

curl -X GET https://target.com/api/v1/users
curl -X POST https://target.com/api/v1/login -d '{"username":"admin","password":"secret"}'
Check for authentication bypasses, rate limiting, or unexpected responses.

Leveraging Swagger/OpenAPI

If the API exposes a Swagger UI (e.g., /swagger-ui/), use it to explore endpoints programmatically.


Key takeaways

  • Use automated crawlers like Burp Suite, dirsearch, and gospider to map large applications.
  • Manually test common directories and analyze HTTP headers for hidden resources.
  • Focus on APIs by testing endpoints and leveraging tools like Swagger UI for structured exploration.
  • Always validate findings against authorization boundaries and avoid untargeted scanning.