← Intel
Oct 5, 2026 · HackerOnStreet

Where to Get Rear Api End Points for pentesting testing

This article will help you to understand about exploiting Apis so if you are having issues related to finding word list or endpoints Where to Get Rear Api End Points for pentesting testing This article will help you to understand about

rear apirear api pointsrearapipointspentestingtestingconstendpointscodestatusdocument
Where to Get Rear Api End Points for pentesting testing

Quick overview

FieldDetail
Topicconst
GuideWhere to Get Rear Api End Points for pentesting testing
Tagsconst, endpoints, code, status, api, document
LengthAbout 1036 words
Practice ruleAuthorized labs only — stay ethical

This article will help you to understand about exploiting Apis so if you are having issues related to finding word list or endpoints


Where to Get Rear Api End Points for pentesting testing

This article will help you to understand about exploiting Apis so if you are having issues related to finding word list or endpoints

My name is Imran Niaz and I have been doing pen testing since long time but I have experience but not that much with the time I am getting experience in multiple things.

API pen testing exploitation Collecting API and points

From all the collections that are methods I have been using it was so glare the data that is available on Github however that data is much better but sometimes API endpoints can be so much tricky.

Therefore if you want to find some kind of endpoints I would like to recommend you collect by yourself from all other 3rd party resources

3rd party resources Meaning is that that you have to go and search everywhere and collect these endpoints even it's GitHub or GitHub private Public reupholstery Would you ever have been developed any kind of endpoint or asking your friends that share the API dot PHP files that contain API endpoints

Collecting data from Google you can use Google dork result for collecting API endpoints.

Collection of Apis from 3rd party search engines like Shodan For my purpose I have been using Shodan since long time and I have a subscription base so if you have subscription should I sometime have Heavy sales ongoing so you can download many things from that.

Open Bhagbanti platform's

There can be no such a good thing rather than open bug bounty platform where people individually comes and submit their report. And you can collect from.

Collecting data from same page

Cracking endpoints from same page can be a good and one of the best ways so you cannot get the useless and junk if you want to test from same area I would like to recommend you if you are trying to collect the endpoint from same website so write a script that should be pasted in console and that will collect all the endpoints from internal JavaScript files and same page.

javascript:(function () {
const scripts = document.getElementsByTagName("script");
const regex = /(?<=["'`])\/[a-zA-Z0-9_\-\/.?&=%]+(?=["'`])/g;
const results = new Set();

// Extract from inline HTML
const html = document.documentElement.outerHTML;
const inlineMatches = html.matchAll(regex);
for (const match of inlineMatches) results.add(match[0]);

// Extract from external JS
for (let i = 0; i < scripts.length; i++) {
const src = scripts[i].src || "";
if (src) {
fetch(src)
.then(res => res.text())
.then(code => {
const matches = code.matchAll(regex);
for (let match of matches) results.add(match[0]);
})
.catch(err => console.warn("Script fetch error:", err));
}
}

function createTable(title, id, color) {
return `
<h3 style='color:${color};font-family:sans-serif;'>${title}</h3>
<table border='1' cellpadding='8' cellspacing='0' style='font-family:sans-serif;border-collapse:collapse;width:100%;margin-bottom:30px;'>
<thead style='background:#f0f0f0;'>
<tr>
<th>Status</th>
<th>Endpoint</th>
<th>Full URL</th>
</tr>
</thead>
<tbody id='${id}'></tbody>
</table>
`
;
}

function renderResults() {
document.body.innerHTML = `
<h2 style='font-family:sans-serif;'>🔍 Endpoint Scanner Results</h2>
${createTable("✅ 200 OK Endpoints", "table_200", "green")}
${createTable("❌ Other Error Statuses", "table_other", "orange")}
${createTable("❌ Fetch or Network Errors", "table_fail", "red")}
`
;

const table200 = document.getElementById("table_200");
const tableOther = document.getElementById("table_other");
const tableFail = document.getElementById("table_fail");

results.forEach(path => {
if (path.includes('{') || path.includes('#') || path.includes('<')) return;
const fullUrl = window.location.origin + path;

fetch(fullUrl)
.then(res => {
const row = document.createElement("tr");
const status = res.status;
const statusText = res.status === 200 ? "✅ 200" : `❌ ${status}`;
const color = res.status === 200 ? "green" : "orange";

row.innerHTML = `
<td style='color:${color};text-align:center;'>${statusText}</td>
<td><code>${path}</code></td>
<td>${res.status === 200 ? `<a href="${fullUrl}" target="_blank">${fullUrl}</a>` : `<code>${fullUrl}</code>`}</td>
`
;

if (status === 200) {
table200.appendChild(row);
} else {
tableOther.appendChild(row);
}
})
.catch(() => {
const row = document.createElement("tr");
row.innerHTML = `
<td style='color:red;text-align:center;'>❌ ERR</td>
<td><code>${path}</code></td>
<td><code>${window.location.origin + path}</code></td>
`
;
tableFail.appendChild(row);
});
});
}

setTimeout(renderResults, 3000); // Wait for JS fetching
})();

This simple script will help you to understand one thing that it will collect the endpoint and automatically test and all the endpoint with the status result so you don't have to test out them

Past Script in webssie console

! How can we clean this whole thing

Once you collect this all data and save into a TXT file or which file you want to save then use Python script write a script that can clean all the endpoints and save into another TXT file and then replace or remove the duplicate from that so each endpoint you get that will be removed remember putting the logic that time sometime logic can remove the duplicate domains and the same domains.

A message from our Founder

Hey, Sunil here. I wanted to take a moment to thank you for reading until the end and for being a part of this community.

Did you know that our team run these publications as a volunteer effort to over 3.5m monthly readers? We don’t receive any funding, we do this to support the community. ❤️

If you want to show some love, please take a moment to follow me on LinkedIn, TikTok, Instagram. You can also subscribe to our weekly newsletter.

And before you go, don’t forget to clap and follow the writer️!

Frequently asked questions

What is this guide about const?

Where to Get Rear Api End Points for pentesting testing explains practical, ethical notes on const. Use it as a structured walkthrough — then practice only in authorized labs.

Who is this const article for?

Readers who want clear, street-level guidance on const without hype. Beginners and intermediate practitioners both benefit.

How do I practice const safely?

Stay in scope: systems you own or have written permission to test. Keep notes, verify findings, and never attack live targets without authorization.