0x14 - Hidden Endpoints via Link Headers
0x14 - Hidden Endpoints via Link Headers
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know you can find additional API endpoints during the recon phase by checking the HTTP Link headers in the server response?
Finding undocumented API endpoints is a critical part of the pentest recon process.
They can reveal vulnerable functions or features that are disabled in the user-interface, making them a great target for unauthorized access attacks.
Based on how the app is configured, it may be easy to overlook empty responses or 204 No Content statuses.
One less-known place to discover new endpoints is in the Link HTTP response headers.
While this is not very common, during one of my pentests I was able to find 25+ API endpoints using this technique, which greatly increased the attack surface.
How to do it
Navigate the app
Apply the Bambda filter linked below
Check the
Notestab for new endpoints