Bad API, hAPI Hackers! by jr0ch17

  Рет қаралды 27,055

Bugcrowd

Bugcrowd

Күн бұрын

Recorded live on January 19, 2019 at LevelUp 0x03.
Learn more: www.bugcrowd.com/resources/ev...
Join Bugcrowd: bit.ly/invitesplz
Have a question related to this talk? Post it on our forum:
forum.bugcrowd.com/t/levelup-...
Abstract:
In this presentation I'd show my methodology of looking at APIs from both black box and white box perspectives. White box meaning that I already have the Postman collection in hand so I already have all the endpoints. I'll show how I test for technical bugs starting off by trying to leak information and error messages that discloses the framework by either changing HTTP methods, sending malformed JSON, putting it integers when it's expecting a string, putting a string when it's expecting an integer, etc. From there, I use what I've gotten and start testing for RCE, SQLi, XXE, stored XSS, etc. After the technical vulnerabilities, I'll dig deeper into the IDORs and try to access stuff you're not supposed to view/change, look for sensitive information leakage, etc. Sometimes it looks like there's nothing interesting and juicy, however by combining a few endpoints together, you're able to get something quite nice like a complete account takeover, or authentication bypass, unauthorized access, credentials and API key leaks, etc.

Пікірлер: 12
@alexandrmaximenko3794
@alexandrmaximenko3794 5 жыл бұрын
Thank you, sir, found a few wonderful things after your video. Cheers!
@abhaychandrachede7280
@abhaychandrachede7280 5 жыл бұрын
Thanks a lot bugcrowd...
@suhass414
@suhass414 4 жыл бұрын
amazing! loved it.
@p-monay5636
@p-monay5636 3 жыл бұрын
Those commands at the intro 😍
@Tekionemission
@Tekionemission Жыл бұрын
(7:07)-interested input 'using special character' to cause an API to throw an error and disclosed information. Interesting use of automated scan off of repeater and error msg plugin.
@DheerajMadhukar
@DheerajMadhukar 4 жыл бұрын
If possible.. please share the presentation slides also. Thanks
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked 4 ай бұрын
Thanks. Shalom. :3
@RAGHAVENDRASINGH17
@RAGHAVENDRASINGH17 5 жыл бұрын
How to brutrforce ID , can you share wordlist?
@scarytruths01
@scarytruths01 Жыл бұрын
Idk if you can brute force a ID you can Brute force passwords using wordlist's an rainbow tables or a program like hydra to crack it.
@WilmyDanguya
@WilmyDanguya 3 жыл бұрын
cool
@Krypt0n_hs
@Krypt0n_hs 2 жыл бұрын
2021.12.04 watch this mark
@RobertoOrtis
@RobertoOrtis 4 жыл бұрын
Maybe it's just me but it's kinda hard to understand what you're saying. If you could make your voice clear next time, it would be great. Thanks for the video!
WHO DO I LOVE MOST?
00:22
dednahype
Рет қаралды 79 МЛН
OMG🤪 #tiktok #shorts #potapova_blog
00:50
Potapova_blog
Рет қаралды 18 МЛН
Did you believe it was real? #tiktok
00:25
Анастасия Тарасова
Рет қаралды 25 МЛН
What's in my hacking tool box? by Richard Rushing
1:02:12
Bugcrowd
Рет қаралды 3,4 М.
Analyzing The OWASP API Security Top 10 For Pen Testers
1:00:23
SANS Offensive Operations
Рет қаралды 26 М.
API Hacking 101, w/ Dr. Katie Paxton-Fear | by Traceable AI
54:34
Traceable AI
Рет қаралды 45 М.
Testing and Hacking APIs   INON SHKEDY
28:18
OWASP Foundation
Рет қаралды 9 М.
Real Bugs - API Information Disclosure
17:32
The Cyber Mentor
Рет қаралды 33 М.
The Only Unbreakable Law
53:25
Molly Rocket
Рет қаралды 317 М.
LevelUp 0x04 - OWASP Amass - Discovering Internet Exposure
58:28
API Security 101 by Sadako
20:58
Bugcrowd
Рет қаралды 51 М.
Урна с айфонами!
0:30
По ту сторону Гугла
Рет қаралды 8 МЛН
Choose a phone for your mom
0:20
ChooseGift
Рет қаралды 4,5 МЛН