Skip to main content

Discovered Parameters

Every request in a Fuzzing Hero scan undergoes parameter discovery. Our scan engine will parse HTTP requests and attempt to discover parameters and categorize them.

This allows the engine to fuzz every parameter with the appropriate test cases. Once a scan has been completed, the discovered parameters will be visible in the scan result.

Example​

Given the following request:

POST /api/users/dcc5049d-81c5-409f-bc14-e4ff76f33cb8/settings HTTP/1.1
Host: example.com
Content-Length: 92
Accept-Encoding: identity
Content-Type: application/json

{"name": "John Doe", "title": "CEO", "location": {"city": "San Francisco", "country": "US"}}

Fuzzing Hero's parameter discovery would detect parameters like the following:

  • dcc5049d-81c5-409f-bc14-e4ff76f33cb8
  • name
  • title
  • location
  • location.city
  • location.country

The parameter discovery will provide some categorization to help identify where a parameter is in the request, such as a header, query, json, etc. type of parameter.

Note that the engine may fuzz more than what the parameter discovery lists. Parameter discovery is a starting point.