ENGLISH

Hacking APIS. Breaking Web Application Programming Interface

Book information

Publisher
No Starch Press
Year
2022
ISBN
9781718502444, 9781718502451, 2021061101, 2021061102
Language
english
Format
PDF
Filesize
24 MB (25161622 bytes)
Pages
\363
Time added
2023-02-22 23:57:55

Description

About the Author About the Technical Reviewer Foreword Acknowledgments Introduction The Allure of Hacking Web APIs This Book’s Approach Hacking the API Restaurant Part I: How Web API Security Works 0: Preparing for Your Security Tests Receiving Authorization Threat Modeling an API Test Which API Features You Should Test API Authenticated Testing Web Application Firewalls Mobile Application Testing Auditing API Documentation Rate Limit Testing Restrictions and Exclusions Security Testing Cloud APIs DoS Testing Reporting and Remediation Testing A Note on Bug Bounty Scope Summary 1: How Web Applications Work Web App Basics The URL HTTP Requests HTTP Responses HTTP Status Codes HTTP Methods Stateful and Stateless HTTP Web Server Databases SQL NoSQL How APIs Fit into the Picture Summary 2: The Anatomy of Web APIs How Web APIs Work Standard Web API Types RESTful APIs GraphQL REST API Specifications API Data Interchange Formats JSON XML YAML API Authentication Basic Authentication API Keys JSON Web Tokens HMAC OAuth 2.0 No Authentication APIs in Action: Exploring Twitter’s API Summary 3: Common API Vulnerabilities Information Disclosure Broken Object Level Authorization Broken User Authentication Excessive Data Exposure Lack of Resources and Rate Limiting Broken Function Level Authorization Mass Assignment Security Misconfigurations Injections Improper Assets Management Business Logic Vulnerabilities Summary Part II: Building an API Testing Lab 4: Your API Hacking System Kali Linux Analyzing Web Apps with DevTools Capturing and Modifying Requests with Burp Suite Setting Up FoxyProxy Adding the Burp Suite Certificate Navigating Burp Suite Intercepting Traffic Altering Requests with Intruder Crafting API Requests in Postman, an API Browser The Request Builder Environments Collections The Collection Runner Code Snippets The Tests Panel Configuring Postman to Work with Burp Suite Supplemental Tools Performing Reconnaissance with OWASP Amass Discovering API Endpoints with Kiterunner Scanning for Vulnerabilities with Nikto Scanning for Vulnerabilities with OWASP ZAP Fuzzing with Wfuzz Discovering HTTP Parameters with Arjun Summary Lab #1: Enumerating the User Accounts in a REST API 5: Setting Up Vulnerable API Targets Creating a Linux Host Installing Docker and Docker Compose Installing Vulnerable Applications The completely ridiculous API (crAPI) OWASP DevSlop’s Pixi OWASP Juice Shop Damn Vulnerable GraphQL Application Adding Other Vulnerable Apps Hacking APIs on TryHackMe and HackTheBox Summary Lab #2: Finding Your Vulnerable APIs Part III: Attacking APIs 6: Discovery Passive Recon The Passive Recon Process Google Hacking ProgrammableWeb’s API Search Directory Shodan OWASP Amass Exposed Information on GitHub Active Recon The Active Recon Process Baseline Scanning with Nmap Finding Hidden Paths in Robots.txt Finding Sensitive Information with Chrome DevTools Validating APIs with Burp Suite Crawling URIs with OWASP ZAP Brute-Forcing URIs with Gobuster Discovering API Content with Kiterunner Summary Lab #3: Performing Active Recon for a Black Box Test 7: Endpoint Analysis Finding Request Information Finding Information in Documentation Importing API Specifications Reverse Engineering APIs Adding API Authentication Requirements to Postman Analyzing Functionality Testing Intended Use Performing Privileged Actions Analyzing API Responses Finding Information Disclosures Finding Security Misconfigurations Verbose Errors Poor Transit Encryption Problematic Configurations Finding Excessive Data Exposures Finding Business Logic Flaws Summary Lab #4: Building a crAPI Collection and Discovering Excessive Data Exposure 8: Attacking Authentication Classic Authentication Attacks Password Brute-Force Attacks Password Reset and Multifactor Authentication Brute-Force Attacks Password Spraying Including Base64 Authentication in Brute-Force Attacks Forging Tokens Manual Load Analysis Live Token Capture Analysis Brute-Forcing Predictable Tokens JSON Web Token Abuse Recognizing and Analyzing JWTs The None Attack The Algorithm Switch Attack The JWT Crack Attack Summary Lab #5: Cracking a crAPI JWT Signature 9: Fuzzing Effective Fuzzing Choosing Fuzzing Payloads Detecting Anomalies Fuzzing Wide and Deep Fuzzing Wide with Postman Fuzzing Deep with Burp Suite Fuzzing Deep with Wfuzz Fuzzing Wide for Improper Assets Management Testing Request Methods with Wfuzz Fuzzing “Deeper” to Bypass Input Sanitization Fuzzing for Directory Traversal Summary Lab #6: Fuzzing for Improper Assets Management Vulnerabilities 10: Exploiting Authorization Finding BOLAs Locating Resource IDs A-B Testing for BOLA Side-Channel BOLA Finding BFLAs A-B-A Testing for BFLA Testing for BFLA in Postman Authorization Hacking Tips Postman’s Collection Variables Burp Suite Match and Replace Summary Lab #7: Finding Another User’s Vehicle Location 11: Mass Assignment Finding Mass Assignment Targets Account Registration Unauthorized Access to Organizations Finding Mass Assignment Variables Finding Variables in Documentation Fuzzing Unknown Variables Blind Mass Assignment Attacks Automating Mass Assignment Attacks with Arjun and Burp Suite Intruder Combining BFLA and Mass Assignment Summary Lab #8: Changing the Price of Items in an Online Store 12: Injection Discovering Injection Vulnerabilities Cross-Site Scripting (XSS) Cross-API Scripting (XAS) SQL Injection Manually Submitting Metacharacters SQLmap NoSQL Injection Operating System Command Injection Summary Lab #9: Faking Coupons Using NoSQL Injection Part IV: Real-World API Hacking 13: Applying Evasive Techniques and Rate Limit Testing Evading API Security Controls How Security Controls Work API Security Control Detection Using Burner Accounts Evasive Techniques Automating Evasion with Burp Suite Automating Evasion with Wfuzz Testing Rate Limits A Note on Lax Rate Limits Path Bypass Origin Header Spoofing Rotating IP Addresses in Burp Suite Summary 14: Attacking GraphQL GraphQL Requests and IDEs Active Reconnaissance Scanning Viewing DVGA in a Browser Using DevTools Reverse Engineering the GraphQL API Directory Brute-Forcing for the GraphQL Endpoint Cookie Tampering to Enable the GraphiQL IDE Reverse Engineering the GraphQL Requests Reverse Engineering a GraphQL Collection Using Introspection GraphQL API Analysis Crafting Requests Using the GraphiQL Documentation Explorer Using the InQL Burp Extension Fuzzing for Command Injection Summary 15: Data Breaches and Bug Bounties The Breaches Peloton USPS Informed Visibility API T-Mobile API Breach The Bounties The Price of Good API Keys Private API Authorization Issues Starbucks: The Breach That Never Was An Instagram GraphQL BOLA Summary Conclusion A: API Hacking Checklist B: Additional Resources Chapter 0: Preparing for Your Security Tests Chapter 1: How Web Applications Work Chapter 2: The Anatomy of Web APIs Chapter 3: Common API Vulnerabilities Chapter 4: Your API Hacking System Chapter 5: Setting Up Vulnerable API Targets Chapter 6: Discovery Chapter 7: Endpoint Analysis Chapter 8: Attacking Authentication Chapter 9: Fuzzing Chapter 10: Exploiting Authorization Chapter 11: Mass Assignment Chapter 12: Injection Chapter 13: Applying Evasive Techniques and Rate Limit Testing Chapter 14: Attacking GraphQL Chapter 15: Data Breaches and Bug Bounties Index

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF