โ† All cheat sheets

ARJUN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

HTTP parameter discovery tool. Finds hidden/undocumented query
parameters and POST body parameters in web applications.

INSTALLATION#

pip install arjun

# From source
git clone https://github.com/s0md3v/Arjun
cd Arjun
pip install .

BASIC USAGE#

# GET parameter discovery
arjun -u "https://example.com/page"

# POST parameter discovery
arjun -u "https://example.com/page" -m POST

# JSON body parameter discovery
arjun -u "https://example.com/api" -m JSON

# XML parameter discovery
arjun -u "https://example.com/api" -m XML

# Multiple methods
arjun -u URL -m GET POST JSON

INPUT OPTIONS#

# Single URL
arjun -u "https://example.com/page"

# Multiple URLs from file
arjun --urls targets.txt

# From stdin
echo "https://example.com/page" | arjun

# Import from Burp/ZAP (parse request file)
arjun -u URL --import request.txt

WORDLISTS#

# Default wordlist (~25,000 parameters)
# Included with Arjun installation

# Custom wordlist
arjun -u URL -w custom_params.txt

# Append to default wordlist
arjun -u URL -w custom_params.txt --include

# Generate wordlist from URL
arjun --generate wordlist.txt -u URL

OUTPUT OPTIONS#

# JSON output
arjun -u URL -oJ results.json

# Text output
arjun -u URL -oT results.txt

# Burp-compatible output
arjun -u URL -oB results.txt

# Quiet mode
arjun -u URL -q

TUNING OPTIONS#

# Chunk size (parameters per request)
arjun -u URL -c 250                         # Default: 250

# Threads
arjun -u URL -t 10                          # Default: 5

# Timeout
arjun -u URL --timeout 15                   # Request timeout (seconds)

# Delay between requests
arjun -u URL --delay 1                      # Seconds

# Rate limiting
arjun -u URL --rate-limit 30                # Requests per second

# Stable mode (slower but more accurate)
arjun -u URL --stable

AUTHENTICATION#

# Custom headers
arjun -u URL --headers "Authorization: Bearer TOKEN"
arjun -u URL --headers "Cookie: session=abc123"

# Multiple headers (JSON format)
arjun -u URL --headers '{"Authorization": "Bearer TOKEN", "Cookie": "session=abc"}'

PROXY#

arjun -u URL --proxy http://127.0.0.1:8080
arjun -u URL --proxy socks5://127.0.0.1:9050

DETECTION METHODS#

# How Arjun discovers parameters:

# 1. Baseline request
#    Sends a request without any extra parameters
#    Records response length, status, headers, reflection patterns

# 2. Chunked testing
#    Sends parameters in chunks (default 250 per request)
#    Compares responses to baseline
#    If response differs, the chunk contains valid parameters

# 3. Narrowing down
#    Splits positive chunks into smaller groups
#    Narrows down to individual valid parameters

# 4. Anomaly detection
#    Detects parameters that change:
#    - Response size
#    - Response code
#    - Content type
#    - Reflected in response

PARAMETER TYPES FOUND#

  - Query parameters (?key=value)
  - POST form parameters
  - JSON body parameters
  - XML attributes
  - Hidden/debug parameters
  - Undocumented API parameters
  - Admin/test parameters left in production

COMMON HIDDEN PARAMETERS#

# Debug/test parameters
debug, test, verbose, dev, staging, internal, admin

# Functionality toggles
callback, redirect, url, next, return, goto, ref

# Output control
format, output, type, content, view, render, template

# Authentication bypass
role, admin, isAdmin, privilege, access, auth

# Data access
id, uid, user_id, account, file, path, dir, page

# API parameters
api_key, token, secret, key, version, v, fields

PIPELINE INTEGRATION#

# Discover params, then test for XSS
arjun -u URL -oJ params.json
# Parse params.json and feed to Dalfox

# Katana โ†’ Arjun
katana -u URL -jc -silent | arjun --urls /dev/stdin -oJ params.json

# With Nuclei
arjun -u URL -oT urls_with_params.txt
nuclei -l urls_with_params.txt -tags sqli,xss

COMMON WORKFLOWS#

# 1. Basic parameter discovery
arjun -u "https://target.com/search" -oJ results.json

# 2. API endpoint testing
arjun -u "https://target.com/api/v1/users" -m GET POST JSON

# 3. Authenticated discovery
arjun -u URL --headers "Cookie: session=TOKEN" -m GET POST

# 4. Stable mode for WAF-protected targets
arjun -u URL --stable --delay 1 --rate-limit 10

# 5. Batch discovery
arjun --urls endpoints.txt -t 5 --delay 1 -oJ all_params.json

# 6. Custom wordlist for specific tech
arjun -u URL -w wordpress_params.txt
arjun -u URL -w django_params.txt

TIPS#

  - Default wordlist covers most common parameters
  - Use --stable flag on rate-limited or WAF-protected targets
  - JSON method (-m JSON) essential for REST APIs
  - Chunk size affects speed vs accuracy (lower = more accurate)
  - Route through proxy to see Arjun's requests in Burp/Caido
  - Hidden debug parameters often bypass security controls
  - Parameters like "debug=true" can reveal stack traces
  - Combine with Dalfox for XSS on discovered parameters
  - Combine with SQLMap for injection on discovered parameters
  - Check both GET and POST on the same endpoint
  - Custom wordlists for specific frameworks improve results