Request a Demo Contact Us
Bugcrowd Acquires Informer to Enhance Offerings Across Attack Surface Management and Penetration Testing
Learn More

API Security Testing For Hackers

 

In this talk, I will be discussing the primary domains of API security, with notable examples of security flaws for each. I will also discuss some basic methodology for testing and fuzzing services, by approaching with educated guesses to how the backend actually works. Finally, I will discuss two major bugs that I was involved in finding, and the domains in which they fall under, discussing methodology and impact. I plan to have a follow up page on my website with links to resources for people who want to explore this space more. This talk is aimed more at the beginner audience, with some intermediate concepts involved.

More resources

Report

Scopes: Where Bigger is Better

Read More
Report

Inside the Mind of a CISO

Read More
Report

The Total Economic Impact™ Of Bugcrowd Managed Bug Bounty

Read More

Get Started with Bugcrowd

Every minute that goes by, your unknown vulnerabilities leave you more exposed to cyber attacks.