Hacking APIs breaking web application programming interfaces
"Teaches how to penetration-test APIs, make APIs more secure, set up a streamlined API testing lab with Burp Suite and Postman, and master tools for reconnaissance, endpoint analysis, and fuzzing. Topics covered include REST and GraphQL APIs, API authentication mechanisms, vulnerabilities, and...
Otros Autores: | |
---|---|
Formato: | Libro electrónico |
Idioma: | Inglés |
Publicado: |
San Francisco :
No Starch Press
[2022]
|
Materias: | |
Ver en Biblioteca Universitat Ramon Llull: | https://discovery.url.edu/permalink/34CSUC_URL/1im36ta/alma991009664706306719 |
Tabla de Contenidos:
- Preparing for API security testing
- How web applications work
- The anatomy of web APIs
- API insecurities
- Setting up vulnerable API targets for testing
- Analysis and attribution
- Discovering APIs
- Endpoint analysis
- Authentication attacks
- Fuzzing
- Exploiting API authorization
- Exploiting mass assignment
- API injection
- Evasive techniques and rate limit testing
- Hacking APIs
- Breaches and bounties.