Hacking APIs : breaking web application programming interfaces /
"Teaches how to penetration-test APIs, make APIs more secure, set up a streamlined API testing lab with Burp Suite and Postman, and master tools for reconnaissance, endpoint analysis, and fuzzing. Topics covered include REST and GraphQL APIs, API authentication mechanisms, vulnerabilities, and...
Call Number: | Libro Electrónico |
---|---|
Main Author: | |
Format: | Electronic eBook |
Language: | Inglés |
Published: |
San Francisco :
No Starch Press,
[2022]
|
Subjects: | |
Online Access: | Texto completo (Requiere registro previo con correo institucional) |
Table of Contents:
- Preparing for API security testing
- How web applications work
- The anatomy of web APIs
- API insecurities
- Setting up vulnerable API targets for testing
- Analysis and attribution
- Discovering APIs
- Endpoint analysis
- Authentication attacks
- Fuzzing
- Exploiting API authorization
- Exploiting mass assignment
- API injection
- Evasive techniques and rate limit testing
- Hacking APIs
- Breaches and bounties.