New OWASP API Top 10 for Hackers

preview_player
Показать описание
Blog article isn’t done yet but I’ll get it up ASAP!

Today we explore the new OWASP API Top 10 in detail, the new version is much more hacker friendly and focuses on bugs we can find rather than defenders but how can we start to study these bugs and actually find them? Let’s take a look at some of the changes in the new OWASP API top 10 2023, which ones I recommend for beginners just starting out with API hacking and when to look out for specific bugs

There are a ton of vulnerabilities out there, like Prototype Pollution, SQL Injection, and remote code execution. And while they can be fun to exploit during CTFs but when they are lurking in our code…it’s not as fun

But that’s where our sponsor Snyk comes in - Snyk scans your code, dependencies, containers, and configs, all in real time. Snyk not only finds but also fixes vulnerabilities on the fly.

Plus, it does it all from your existing toolkit – IDEs, CLI, repos, pipelines, Docker Hub, and more.

Рекомендации по теме
Комментарии
Автор

amazing video so many people only talk about the surface level of bug finding theres not enough information on the actual functional testing and specific places to search like in this video

shiiswii
Автор

Mam please also continue bug bounty zero to hero series

orbitxyz
Автор

Id love to see some move videos, maybe one of you going through a ctf/bug bounty live. Seeing that live recon helps a lot

eyephpmyadmin
Автор

Great video! Is the blog article up yet?

anukiranghosh
Автор

love from a college student in the philippines! thank you for this

tsuryu
Автор

You're the best!! I hope you have a healthy and happy 2025 young lady :-)

MFoster
Автор

oh sweet haven't seen these changes yet

comosaycomosah
Автор

Amazing content amazing explanation love from Pakistan

SohaibKhan-hpoe
Автор

What are common vulnerabilities i would find in a COTS product like salesforce CRM's API's?

bigboycdznutz
Автор

Mam can you tell me which books I needed to reffer for api hacking, not outdated, please

jxkz