Evade IP blocking by using residential proxies

Evade IP blocking by using residential proxies

Learn how to use upstream residential and mobile proxies in Burp Suite to evade IP blocking during your API security testing. The post Evade IP blocking by using residential proxies appeared first ...
Hacking API discovery with a custom Burp extension

Hacking API discovery with a custom Burp extension

| | API Hacking Tools
Learn how to improve your API discovery with a custom Burp Suite extension dedicated to automatically finding API document artifacts for you. The post Hacking API discovery with a custom Burp extension ...
Hacking Modern Android Mobile Apps & APIs with Burp Suite

Hacking Modern Android Mobile Apps & APIs with Burp Suite

Learn how to set up your hacking environment to attack mobile apps & APIs running on modern versions of Android with Burp Suite. The post Hacking Modern Android Mobile Apps & APIs ...
Detecting new API endpoints with oasdiff

Detecting new API endpoints with oasdiff

Gain a competitive edge over other security researchers by detecting changes to APIs before others even know about them by using oasdiff. The post Detecting new API endpoints with oasdiff appeared first ...
Fuzzing JSON to find API security flaws

Fuzzing JSON to find API security flaws

Learn how to fuzz JSON to find security vulnerabilities in the APIs you are hacking with the help of a custom wordlist and Param Miner. The post Fuzzing JSON to find API ...
Finding hidden API parameters

Finding hidden API parameters

Learn how to use Param Miner to find hidden parameters that may help manipulate an API in unintended ways, revealing potential security flaws. The post Finding hidden API parameters appeared first on ...
Weaponizing API discovery metadata

Weaponizing API discovery metadata

Learn how to weaponize API discovery metadata to improve your recon of the APIs you are hacking or conducting security testing on. The post Weaponizing API discovery metadata appeared first on Dana ...
Hacking APIs with HTTPie

Hacking APIs with HTTPie

Learn why HTTPie is a great replacement for curl and how to use it when conducting your own API security testing. The post Hacking APIs with HTTPie appeared first on Dana Epp's ...
3 ways to improve appsec code auditing with graudit

3 ways to improve appsec code auditing with graudit

Learn how to improve your application security code reviews with the help of tools like graudit. The post 3 ways to improve appsec code auditing with graudit appeared first on Dana Epp's ...
Writing Burp extensions in Kotlin

Writing Burp extensions in Kotlin

Learn how to write Burp Suite extensions using the new Montoya API with Kotlin and Visual Studio Code (VS Code) The post Writing Burp extensions in Kotlin appeared first on Dana Epp's ...