Главная
Study mode:
on
1
Introduction
2
About Peter Yaworski
3
Agenda
4
What is API
5
Why we care
6
Why this happens
7
Rails example
8
Removing information from view
9
The JSON file
10
The handy method merge
11
Adding a sensitive parameter
12
Personal anecdote
13
How do we find it
14
Examples
15
Customer ID
16
Vulnerability
17
Private Address
18
Wrapup
Description:
Explore information disclosure vulnerabilities in APIs and HTML page sources often overlooked by researchers in mature programs. Learn about the design pattern in Rails that makes these vulnerabilities easy to introduce, especially when combined with front-end JavaScript libraries like React or Angular. Discover how to identify and exploit these vulnerabilities through real-world examples, including customer ID exposure and private address leaks. Gain insights into why these issues occur and how to prevent them in your own applications. Perfect for security researchers, developers, and anyone interested in improving API security.

Hidden in Plain Site - Disclosing Information via Your APIs - Peter Yaworski, Bugcrowd's LevelUp 2017

Bugcrowd
Add to list
0:00 / 0:00