Is the latest book on “Pentesting APIs” any good?

Is the latest book on “Pentesting APIs” any good?

| | API Hacking Fundamentals
Let's explore the latest book by Packt Publishing on "Pentesting APIs" and see if it's worth putting on an API hacker's bookshelf. The post Is the latest book on “Pentesting APIs” any ...
KEV + CWE = Attack Vector ❤️‍🔥

KEV + CWE = Attack Vector ❤️‍🔥

| | API Hacking Fundamentals
Learn how to cross-reference Known Exploit Vulnerabilities (KEV) against CWE to find the best attack vectors to use during security testing. The post KEV + CWE = Attack Vector ❤️‍🔥 appeared first ...
This Bug Got Me A $30,000 Bounty

From Exploit to Extraction: Data Exfil in Blind RCE Attacks

Learn how to write exploits that take advantage of blind command injection vulnerabilities using a time-delayed boolean oracle attack. The post From Exploit to Extraction: Data Exfil in Blind RCE Attacks appeared ...
5 tips to improve your API exploits

5 tips to improve your API exploits

| | API Hacking Fundamentals
Learn five tips that will help improve the API exploits you submit into security triage as part of your vulnerability research. The post 5 tips to improve your API exploits appeared first ...
Level Up Your Vulnerability Reports With CWEs

Level Up Your Vulnerability Reports With CWEs

| | API Hacking Fundamentals
Learn how to use MITRE's Common Weakness Enumerations (CWE) entries to level up your vulnerability reports. The post Level Up Your Vulnerability Reports With CWEs appeared first on Dana Epp's Blog ...
Fuzzing JSON to find API security flaws

Fuzzing JSON to find API security flaws

Learn how to fuzz JSON to find security vulnerabilities in the APIs you are hacking with the help of a custom wordlist and Param Miner. The post Fuzzing JSON to find API ...
Hacking APIs with HTTPie

Hacking APIs with HTTPie

Learn why HTTPie is a great replacement for curl and how to use it when conducting your own API security testing. The post Hacking APIs with HTTPie appeared first on Dana Epp's ...
Tag Team - Whoomp! (There It Is)

Why HAST is important to API hackers

Learn why Human Application Security Testing (HAST) is important to API hackers. The post Why HAST is important to API hackers appeared first on Dana Epp's Blog ...
Writing Burp extensions in Kotlin

Writing Burp extensions in Kotlin

Learn how to write Burp Suite extensions using the new Montoya API with Kotlin and Visual Studio Code (VS Code) The post Writing Burp extensions in Kotlin appeared first on Dana Epp's ...
Giving Yourself the Best Opportunity to Find a Bug

5 Tips for API Hackers on Picking Your First Target

Check out these five tips to help you pick your first target when starting bug bounty hunting against APIs. The post 5 Tips for API Hackers on Picking Your First Target appeared ...