filmov
tv
Topics of Interest: vAPI: Vulnerable Adversely Programmed Interface (OWASP API Top 10) - T. Kulkarni
Показать описание
Topics of Interest: vAPI: Vulnerable Adversely Programmed Interface (OWASP API Top 10)
SPEAKER
Tushar Kulkarni
ABSTRACT
We have seen developers move from traditional 2 tier application architecture to a 3 tier architecture that involves an API talking to front-end and backend services. The API used or developed might ease the development process but a lot of vulnerabilities can come up if not developed or configured properly. vAPI is a Vulnerable Interface in a Lab-like environment that mimics the scenarios from OWASP API Top 10 and helps the user understand and exploit the vulnerabilities according to OWASP API Top 10 2019. It might be useful for Developers as well as Penetration Testers to understand the type of vulnerabilities in APIs. The lab is divided into 10 exercises that sequentially demonstrate the vulnerabilities and give a flag if exploited successfully.
Managed by the OWASP® Foundation
SPEAKER
Tushar Kulkarni
ABSTRACT
We have seen developers move from traditional 2 tier application architecture to a 3 tier architecture that involves an API talking to front-end and backend services. The API used or developed might ease the development process but a lot of vulnerabilities can come up if not developed or configured properly. vAPI is a Vulnerable Interface in a Lab-like environment that mimics the scenarios from OWASP API Top 10 and helps the user understand and exploit the vulnerabilities according to OWASP API Top 10 2019. It might be useful for Developers as well as Penetration Testers to understand the type of vulnerabilities in APIs. The lab is divided into 10 exercises that sequentially demonstrate the vulnerabilities and give a flag if exploited successfully.
Managed by the OWASP® Foundation
Topics of Interest: vAPI: Vulnerable Adversely Programmed Interface (OWASP API Top 10) - T. Kulkarni
Topics of Interest vAPI Vulnerable Adversely Programmed Interface OWASP API Top 10 T Kulkarni
vAPI - Vulnerable Adversely Programmed Interface (Blackhat Europe 2022 Arsenal)
vAPI - Vulnerable Adversely Programmed Interface (Blackhat Europe 2021 Arsenal)
Improper Assets Management - API Top 10
vAPI: Live API Hacking
Api Broken Object Level Authorization Part 2
The @OWASPGLOBAL API Top 10 - DEMO [COMPILATION]
API Security Part 2 - Mitigating OSWAP Top 10 threats for APIs
AP 120 Vulnerable API
Broken Object Level Authorization (BOLA) Explained
Broken Object Level Authorization
Prerequest Scripts | API Testing
Broken Object Level Authorization - 2023 OWASP Top 10 API Security Risks
Practical Application of the API Security Top 10 with Rajni Hatti! - OWASP DevSlop
Owasp top ten APIs
Pentesting API Top 10 by @Tushar Kulkarni
Secure your API! The OWASP API Security Top 10
API9:2019 Improper Assets Management| Practical Lab | 2022 | Kontra | ApplicationSecurity.io
BlackHat Arsenal Presentation | Open-Source API Security
TryHackMe | OWASP Top 10 - Day 2 (Broken Authentication)
API Security OWASP Top 10
How BOLA in API Endpoint can lead to Account Takeover | Postman | API Security
An urgent call to protect the world's 'Third Pole' | Tshering Tobgay
Комментарии