ผลการค้นหา: "#APIHacking"

12 ผลลัพธ์
vulnX
vulnX@vuln_X·
Bug Bounty tip 🧵 Duplicate JSON keys can split auth from execution. ❌ {"Account": 2222} ✅ {"Account": 2222, "Account": 3333, "Account": 5555} Auth middleware reads the first key (yours). Backend processes the last one (victim's). #BugBounty #IDOR #APIHacking
English
0
1
1
19
vulnX
vulnX@vuln_X·
Bug Bounty tip 🧵 Don't just swap IDs — wrap them. ❌ {"Account": 1111} ✅ {"Account": {"Account": 3333}} Auth validates the outer key. Business logic executes the inner one. Scanners miss it. You won't. #BugBounty #IDOR #APIHacking
English
3
36
241
8.5K
SecPro
SecPro@SecProInt·
🎥New video: What Are API Microservices and Why Separating REST Matters 👋We invite you to watch our new video. ▶️Learn what microservices and REST APIs are, how they work, and why they are the foundation of modern architectures.⬇️ #API #apihacking youtu.be/PAT1L213RyE
YouTube video
YouTube
English
0
0
0
24
MAYUR SAPKALE
MAYUR SAPKALE@localhost12001·
Day 14 — Moving on from JWT — API2: Broken User Auth 🔐 Today: switched focus to API2 (Broken User Authentication). Tried brute-forcing OTP in my lab, but DVWA/crAPI rate-limit blocked requests (api/auth/v3 enforced limits). #Day14 #APIHacking #BUSA #JWT #crAPI #MayurLearns
MAYUR SAPKALE tweet media
English
0
0
0
20