0x30 - Hidden API Endpoints in WADL Files
0x30 - Hidden API Endpoints in WADL Files
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know you can find hidden API endpoints in the Web Application Description Language (WADL) files?Application.wadl is an XML file that describes the resources exposed by a web service.
Very similar with Swagger to some extent, but less-known.
Common paths include:
GET
/application.wadlGET
/api/application.wadlGET
/application.wadl?detail=true
The Application.wadl file can contain details about:
Available endpoint paths
Description of each function
Required parameters
Type and content of response
How to do it
Check if the app is hosting an
application.wadlfile on the common pathsDownload the
application.wadlfile from target domainUse
SOAP UIto import the WADL fileExplore discovered endpoints
(Optional) Import to Burp using
SwaggerParserextension