Главная
Study mode:
on
1
Introduction
2
Agenda
3
Greg Patton Introduction
4
Why is API security important
5
Security is often overlooked
6
Key things to consider
7
Things to collect
8
Two key things
9
HTTP
10
Common Things
11
Testing Steps
12
Developer Tips
13
Information Leakage
14
RSA Mobile
15
Review API Responses
16
Mobile App Example
17
Things to Consider
18
Hidden Functionality
19
Other Verbs
20
Protection
21
Access Control
22
Transport Security
23
Injection Concerns
24
Fuzzing
25
Validate Parameters
26
Manage API Keys
27
Mobile Application Assessment
28
Key Management
29
Takeaways
30
Least Privilege
31
Resources
32
Contact Greg
33
References
34
Questions
Description:
Explore the fundamentals of API security assessment in this 39-minute conference talk from AppSecEU 2015 in Amsterdam. Delve into why API security is crucial and often overlooked, learn key considerations for API testing, and discover common vulnerabilities. Gain insights on developer tips, information leakage prevention, and mobile app security. Examine topics such as hidden functionality, access control, transport security, and injection concerns. Understand the importance of fuzzing, parameter validation, and API key management. Conclude with takeaways on implementing least privilege and valuable resources for further learning in API security.

The API Assessment Primer

OWASP Foundation
Add to list