ARJUN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
HTTP parameter discovery tool. Finds hidden/undocumented query parameters and POST body parameters in web applications.
INSTALLATION#
pip install arjun # From source git clone https://github.com/s0md3v/Arjun cd Arjun pip install .
BASIC USAGE#
# GET parameter discovery arjun -u "https://example.com/page" # POST parameter discovery arjun -u "https://example.com/page" -m POST # JSON body parameter discovery arjun -u "https://example.com/api" -m JSON # XML parameter discovery arjun -u "https://example.com/api" -m XML # Multiple methods arjun -u URL -m GET POST JSON
INPUT OPTIONS#
# Single URL arjun -u "https://example.com/page" # Multiple URLs from file arjun --urls targets.txt # From stdin echo "https://example.com/page" | arjun # Import from Burp/ZAP (parse request file) arjun -u URL --import request.txt
WORDLISTS#
# Default wordlist (~25,000 parameters) # Included with Arjun installation # Custom wordlist arjun -u URL -w custom_params.txt # Append to default wordlist arjun -u URL -w custom_params.txt --include # Generate wordlist from URL arjun --generate wordlist.txt -u URL
OUTPUT OPTIONS#
# JSON output arjun -u URL -oJ results.json # Text output arjun -u URL -oT results.txt # Burp-compatible output arjun -u URL -oB results.txt # Quiet mode arjun -u URL -q
TUNING OPTIONS#
# Chunk size (parameters per request) arjun -u URL -c 250 # Default: 250 # Threads arjun -u URL -t 10 # Default: 5 # Timeout arjun -u URL --timeout 15 # Request timeout (seconds) # Delay between requests arjun -u URL --delay 1 # Seconds # Rate limiting arjun -u URL --rate-limit 30 # Requests per second # Stable mode (slower but more accurate) arjun -u URL --stable
AUTHENTICATION#
# Custom headers
arjun -u URL --headers "Authorization: Bearer TOKEN"
arjun -u URL --headers "Cookie: session=abc123"
# Multiple headers (JSON format)
arjun -u URL --headers '{"Authorization": "Bearer TOKEN", "Cookie": "session=abc"}'
PROXY#
arjun -u URL --proxy http://127.0.0.1:8080 arjun -u URL --proxy socks5://127.0.0.1:9050
DETECTION METHODS#
# How Arjun discovers parameters: # 1. Baseline request # Sends a request without any extra parameters # Records response length, status, headers, reflection patterns # 2. Chunked testing # Sends parameters in chunks (default 250 per request) # Compares responses to baseline # If response differs, the chunk contains valid parameters # 3. Narrowing down # Splits positive chunks into smaller groups # Narrows down to individual valid parameters # 4. Anomaly detection # Detects parameters that change: # - Response size # - Response code # - Content type # - Reflected in response
PARAMETER TYPES FOUND#
- Query parameters (?key=value) - POST form parameters - JSON body parameters - XML attributes - Hidden/debug parameters - Undocumented API parameters - Admin/test parameters left in production
COMMON HIDDEN PARAMETERS#
# Debug/test parameters debug, test, verbose, dev, staging, internal, admin # Functionality toggles callback, redirect, url, next, return, goto, ref # Output control format, output, type, content, view, render, template # Authentication bypass role, admin, isAdmin, privilege, access, auth # Data access id, uid, user_id, account, file, path, dir, page # API parameters api_key, token, secret, key, version, v, fields
PIPELINE INTEGRATION#
# Discover params, then test for XSS arjun -u URL -oJ params.json # Parse params.json and feed to Dalfox # Katana โ Arjun katana -u URL -jc -silent | arjun --urls /dev/stdin -oJ params.json # With Nuclei arjun -u URL -oT urls_with_params.txt nuclei -l urls_with_params.txt -tags sqli,xss
COMMON WORKFLOWS#
# 1. Basic parameter discovery arjun -u "https://target.com/search" -oJ results.json # 2. API endpoint testing arjun -u "https://target.com/api/v1/users" -m GET POST JSON # 3. Authenticated discovery arjun -u URL --headers "Cookie: session=TOKEN" -m GET POST # 4. Stable mode for WAF-protected targets arjun -u URL --stable --delay 1 --rate-limit 10 # 5. Batch discovery arjun --urls endpoints.txt -t 5 --delay 1 -oJ all_params.json # 6. Custom wordlist for specific tech arjun -u URL -w wordpress_params.txt arjun -u URL -w django_params.txt
TIPS#
- Default wordlist covers most common parameters - Use --stable flag on rate-limited or WAF-protected targets - JSON method (-m JSON) essential for REST APIs - Chunk size affects speed vs accuracy (lower = more accurate) - Route through proxy to see Arjun's requests in Burp/Caido - Hidden debug parameters often bypass security controls - Parameters like "debug=true" can reveal stack traces - Combine with Dalfox for XSS on discovered parameters - Combine with SQLMap for injection on discovered parameters - Check both GET and POST on the same endpoint - Custom wordlists for specific frameworks improve results