• We just launched and are currently in beta. Join us as we build and grow the community.

Hacking APIs: Breaking Web Application Programming Interfaces

fortybro

SaaS Builder
F Rep
0
0
0
Rep
0
F Vouches
0
0
0
Vouches
0
Posts
92
Likes
182
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 400 XP
hacking_apis-png.184668




Hacking APIs: Breaking Web Application Programming Interfaces
by Corey J. Ball




yH5BAEAAAAALAAAAAABAAEAAAIBRAA7
LEAVE A LIKE.DON'T BE A LEECH.
yH5BAEAAAAALAAAAAABAAEAAAIBRAA7




:::l i n k :::



You must upgrade your account or reply in the thread to view hidden text.




You must upgrade your account or reply in the thread to view hidden text.

]

You must upgrade your account or reply in the thread to view hidden text.




You must upgrade your account or reply in the thread to view hidden text.





yH5BAEAAAAALAAAAAABAAEAAAIBRAA7
LEAVE A LIKE.DON'T BE A LEECH.
yH5BAEAAAAALAAAAAABAAEAAAIBRAA7



Book Summary

An Application Programming Interface (API) is a software connection that allows applications to communicate and share services.Hacking APIswill teach you how to test web APIs for security vulnerabilities. You’ll learn how the common API types, REST, SOAP, and GraphQL, work in the wild. Then you’ll set up a streamlined API testing lab and perform common attacks, like those targeting an API’s authentication mechanisms, and the injection vulnerabilities commonly found in web applications. In the book’s guided labs, which target intentionally vulnerable APIs, you’ll practice:
  • Enumerating API users and endpoints using fuzzing techniques
  • Using Postman to discover an excessive data exposure vulnerability
  • Performing a JSON Web Token attack against an API authentication process
  • Combining multiple API attack techniques to perform a NoSQL injection
  • Attacking a GraphQL API to uncover a broken object level authorization vulnerability

By the end of the book, you’ll be prepared to uncover those high-payout API bugs that other hackers aren’t finding, and improve the security of applications on the web.

Author Bio

Corey Ball is a cybersecurity consulting manager at Moss Adams, where he leads its penetration testing services. He has over ten years of experience working in IT and cybersecurity across several industries, including aerospace, agribusiness, energy, financial tech, government services, and healthcare. In addition to a bachelor’s degree in English and philosophy from Sacramento State University, Corey holds the OSCP, CCISO, CEH, CISA, CISM, CRISC, and CGEIT industry certifications.

:: IF YOUDOWNLOADTHIS, PLEASE LEAVE ALIKE!
::IF YOU FOUND IT USEFUL, PLEASE LEAVE A RATING!
1f5a4.png
-BIG THANKS!

spkrfrqr-sig.png
 

422,212

310,551

310,560

Top