Hidden in Plain Site: Disclosing Information via Your APIs - Peter Yaworski, Bugcrowd's LevelUp 2017

  Рет қаралды 13,692

Bugcrowd

Bugcrowd

Күн бұрын

In this presentation, I'll walk through a number of information disclosure vulnerabilities I've found in mature programs overlooked by other researchers specifically in HTML page sources and APIs. In doing so, I'll demonstrate the design pattern in Rails that makes this an easy mistake to make, especially when combined with a front end JavaScript library like React or Angular.
Have questions? Ask them on the Bugcrowd forum: bgcd.co/2thaRxc
Join Bugcrowd today: bgcd.co/2up2fUH

Пікірлер: 6
@oai9106
@oai9106 4 жыл бұрын
Thanks to Bugcrowd as well as Mr. Peter Yaworski .
@sowhatsupeirik
@sowhatsupeirik 4 жыл бұрын
Great talk Peter! Your a treat in webhacking and security in general.
@eliasibrahim1055
@eliasibrahim1055 6 жыл бұрын
Thank you Peter, this lesson really expanded my way of hunting.
@decalresponds3066
@decalresponds3066 7 жыл бұрын
This issue of failing to remove the proper column extracts from data returned by API operations created via code reuse requires really detailed table security to even begin to prevent. Aside from GRANT and REVOKE, I'm not sure ANSI SQL offers any other access control statements. Various technology-specific extensions to the DAL, DDL and DML (Data Access, Data Definition and Data Modification Languages) may exist depending on the RDBMS and DBA. However, even the most comprehensive security policies/constraints aren't going to stop application business logic errors--no excuses can be made for the developers there.
@watchlistsclips3196
@watchlistsclips3196 3 жыл бұрын
You are so sweet like the hacker who saved the internet marcus hutchins.
@huzifaahmed1426
@huzifaahmed1426 Жыл бұрын
your ideas stil dangourase ✌ still high
Do you like fuzzing? - Abhijeth, Bugcrowd's LevelUp 2017
25:40
Пробую самое сладкое вещество во Вселенной
00:41
🌊Насколько Глубокий Океан ? #shorts
00:42
Me: Don't cross there's cars coming
00:16
LOL
Рет қаралды 13 МЛН
МАМА И STANDOFF 2 😳 !FAKE GUN! #shorts
00:34
INNA SERG
Рет қаралды 4,5 МЛН
Real Bugs - API Information Disclosure
17:32
The Cyber Mentor
Рет қаралды 33 М.
Front End Mock Technical Interview | JavaScript, CSS, React, and Algorithms
1:33:39
Remix Crash Course 2023 (React Framework)
2:07:00
Academind
Рет қаралды 92 М.
The Only Unbreakable Law
53:25
Molly Rocket
Рет қаралды 318 М.
Finding Bugs with Burp Plugins & Bug Bounty 101
47:48
Bugcrowd
Рет қаралды 39 М.
YOTAPHONE 2 - СПУСТЯ 10 ЛЕТ
15:13
ЗЕ МАККЕРС
Рет қаралды 175 М.
Choose a phone for your mom
0:20
ChooseGift
Рет қаралды 5 МЛН
ПОКУПКА ТЕЛЕФОНА С АВИТО?🤭
1:00
Корнеич
Рет қаралды 3,6 МЛН
Мой инст: denkiselef. Как забрать телефон через экран.
0:54