Hacking APIs: Fuzzing 101

preview_player
Показать описание
00:00 Intro
00:34 What is Fuzzing?
02:00 Hands-on lab
13:18 Outro

📱Social Media📱
___________________________________________

💸Donate💸
___________________________________________
Like the channel? Please consider supporting me on Patreon:

Hacker Books:

My Build:

My Recording Equipment:

Рекомендации по теме
Комментарии
Автор

Oh wow! This is amazing and so quick. Thank you Alex, Heath and TCM!

chipko
Автор

Thanks for the content, really important and precise. TCM courses helped me a lot in my cybersec journey!

endless
Автор

Never knew about this up until now. Good job bro.

faadi
Автор

Been in the coding game for the past 20 years and made a lot of mistakes and had my successes. But, what I don’t understand at all, is, who on Earth would code a Web-API and include direct file access like this, basically creating a reverse shell? (more or less). Do we really have such a significant amount of software out there, featuring this kind of flaw?

nonlinearsound-
Автор

That was super informative. Thanks for thorough explanation.

Mrg-kjml
Автор

Thanks for this videos, I just begin in the API pentest wave, and Its very interesting.

Znd
Автор

(2:02, 5:21) Lab and Fuzz Parameter
(7:40) Wfuzz filter out 404
(11:33, 11:51) Wfuzz

Tekionemission
Автор

IF THE LFI DIDNT WORK ON "ID param" could work on "author param" ? ( like the vulnb could work depend on the param right? ) or it also works on the other params?

doshamitv
Автор

Nice video, sir, and thanks for sharing this valuable content with us.
please share moore videos about api enemuration and pentetst, with just basics

Alaa-kcrx
Автор

I have the same chair, I was expecting more confort.

bitminersouth
Автор

api endpoint give 404 error then what i do,
can anyone give me same tips?

varunfoodvlog