2024 Guide: Hacking APIs

preview_player
Показать описание

💵 Support the Channel:
You can support the channel by becoming a member and get access exclusive content, behind the scenes, live hacking session and more!
☕️ Buy Me Coffee:

JOIN DISCORD:

🆓 🆓 🆓 $200 DigitalOcean Credit:

💬 Social Media

00:00 Introduction
00:47 Different approaches
2:07 - Approach 1: Browsing the website
04:34 - Objectives
6:20 - Looking at Javascript Files
8:02 - Authentication
10:16 - Content Discovery
11:32 - API Documentation
12:15 - Example Vulnerability
14:22 - Using Different HTTP Methods
17:57 - Content Types

#api #apihacking #bugbounty #ethicalhacking #infosec #cybersecurity #redteam #webapp
Рекомендации по теме
Комментарии
Автор

Coincidently, I was reading a book related to API hacking (Black hat graphql), when I got the notification from youtube for this. Thanks :)

shriyanssudhi
Автор

ApI hacking 5 week course. Cant wait for next Wednesday. ❤

bugrd_hunter
Автор

Been following you for years. Just want to say thank you. You and Haddix and Dirkjan have leveled my game up. 👏 your a 💎

showupshowout
Автор

I saw CAIDO UI for the first time and it has the left hand approach to tool bars, thas really smart if it was intentional. This supports the right arm's left movement and gives unmatched response times, move your dashboards or windows bar to the left to find out. nice vid btw

MianHizb
Автор

nice catch buddy, try with dev and gotcha the production. what kind of this vulnerability and the impact ?

GiatSilaban
Автор

Thanks for the clear explanation and workflow showcase

nolongeravailable
Автор

Bruh u are the best your contents amazing love from IRAQ 🇮🇶 ❤❤

MustafaGains
Автор

Couldn't find red-api uding Ffuf. Any help?

derekfrancisnoronha
Автор

how do you bypass rate limiting when directory bruteforcing? Akamai or cloudfront always bans me after like 5 min even with like 2-5 threads

catman
Автор

You can let me hack a website's Api or buy a replacement

ChannelR
Автор

Sir i am unable to see the live stream of api hacking

musawerkhan
Автор

Sir how can I find some small bug on my mobile?

Response please 😢

mdshahadothossen-xvpo
Автор

Hi, I just have joined the 5w, do I miss any? Please continue the program, at least don't remove any stuff on the server

ricardoklement
Автор

I lost access to the udemy course (Intro to Bug Bounty Hunting and Web Application Hacking) when I lost my business udemy account by changing jobs. 🥺

kylemcgowan
Автор

thx very good tutorial, keep it up so, very quality content

alientec
Автор

What do you do if all the JS is minified and not as nice as this example?

MCarlitos
Автор

you named your proxy named burp and using cido 🤣🤣

badhackerx