Metadata
- File: Hacking APIs by Ball (2022).pdf
- Zotero: View Item
- Type: Book
- Title: Hacking APIs: breaking web application programming interfaces,
- Author: Ball, Corey;
- Publisher: No Starch Press,
- Location: San Francisco,
- Year: 2022
- ISBN: 978-1-71850-245-1
Abstract
”Teaches how to penetration-test APIs, make APIs more secure, set up a streamlined API testing lab with Burp Suite and Postman, and master tools for reconnaissance, endpoint analysis, and fuzzing. Topics covered include REST and GraphQL APIs, API authentication mechanisms, vulnerabilities, and techniques for bypassing protections. Includes nine guided labs”—
Tags and Collections
- Keywords: 03 In Progress; API; API Security; Application Security; Cyber Security; No Starch Press 2023 Bundle
Comments
Includes index Preparing for API security testing — How web applications work — The anatomy of web APIs — API insecurities — Setting up vulnerable API targets for testing — Analysis and attribution — Discovering APIs — Endpoint analysis — Authentication attacks — Fuzzing — Exploiting API authorization — Exploiting mass assignment — API injection — Evasive techniques and rate limit testing — Hacking APIs — Breaches and bounties