Главная
Study mode:
on
1
Intro
2
Who am I
3
Methodology
4
Where do I start
5
Testing for API
6
Information Gathering
7
API Key
8
Automate
9
File uploads
10
Shawn Tweet
11
Example
12
SQL Injection
13
How I play
14
An example
15
Personal information
16
Testing
17
Privilege Escalation
18
I doors
19
Postman
20
Questions
Description:
Explore a comprehensive methodology for testing APIs from both black box and white box perspectives in this 24-minute conference talk by jr0ch17 at LevelUp 0x03. Dive into techniques for uncovering technical vulnerabilities, including information leakage, error message disclosure, and framework identification. Learn how to test for Remote Code Execution (RCE), SQL Injection (SQLi), XML External Entity (XXE), and stored Cross-Site Scripting (XSS). Discover strategies for identifying Insecure Direct Object References (IDORs), sensitive information leakage, and how to combine endpoints to achieve high-impact vulnerabilities such as account takeovers and authentication bypasses. Gain insights into information gathering, API key handling, automation, file uploads, and privilege escalation. Follow along with real-world examples and learn how to leverage tools like Postman for effective API testing.

Bad API, HAPI Hackers!

Bugcrowd
Add to list
0:00 / 0:00