تلاش کے نتائج: "#APIHacking"

20 نتائج
vulnX
vulnX@vuln_X·
Bug Bounty tip 🧵 Don't just swap IDs — wrap them. ❌ {"Account": 1111} ✅ {"Account": {"Account": 3333}} Auth validates the outer key. Business logic executes the inner one. Scanners miss it. You won't. #BugBounty #IDOR #APIHacking
English
1
28
147
4.2K
SecPro
SecPro@SecProInt·
🎥New video: What Are API Microservices and Why Separating REST Matters 👋We invite you to watch our new video. ▶️Learn what microservices and REST APIs are, how they work, and why they are the foundation of modern architectures.⬇️ #API #apihacking youtu.be/PAT1L213RyE
YouTube video
YouTube
English
0
0
0
24
MAYUR SAPKALE
MAYUR SAPKALE@localhost12001·
Day 14 — Moving on from JWT — API2: Broken User Auth 🔐 Today: switched focus to API2 (Broken User Authentication). Tried brute-forcing OTP in my lab, but DVWA/crAPI rate-limit blocked requests (api/auth/v3 enforced limits). #Day14 #APIHacking #BUSA #JWT #crAPI #MayurLearns
MAYUR SAPKALE tweet media
English
0
0
0
20
MAYUR SAPKALE
MAYUR SAPKALE@localhost12001·
Day 11 — API1: Broken Object Level Auth (BOLA) 🛡️ Today I practiced BOLA (IDOR) on crAPI — found endpoints where changing an ID returned other users’ data. Lesson: always check object-level access controls. #Day11 #APIHacking #BOLA #crAPI #MayurLearns
MAYUR SAPKALE tweet media
English
0
0
0
17