Главная
Study mode:
on
1
Intro
2
Common API Security Issues
3
Access Controls
4
Access Control Bugs
5
Access Control Bug - Panera Bread
6
Input Validation Bugs
7
Input Validation Bug - German eld System
8
Input Validation - Fuzzing
9
Rate Limiting
10
Restricting HTTP Methods
11
3rd Party API Abuse
12
Discord Bug - Concepts
13
Discord Bug - Methodology
14
Example Request
15
Discord Bug - Impact
16
Duda Mobile - Concepts
17
Duda Mobile - Impact
18
Follow Up
Description:
Explore API security fundamentals in this 21-minute conference talk from LevelUp 0x03. Dive into primary domains of API security, examining notable examples of security flaws for each. Learn basic methodology for testing and fuzzing services by approaching with educated guesses about backend operations. Discover two major bugs, including their discovery methodology and impact. Gain insights into common API security issues, access controls, input validation, rate limiting, HTTP method restrictions, and third-party API abuse. Examine real-world case studies involving Panera Bread, German eld System, Discord, and Duda Mobile. Perfect for beginners with some intermediate concepts, this talk provides a comprehensive introduction to API security testing and vulnerability discovery.

API Security 101 by Sadako

Bugcrowd
Add to list
0:00 / 0:00