
This course will teach you how to test web APIs for authorization and access control related security flaws. You will learn how to map API functionality, identify authentication and authorization flaws, and exploit common API vulnerabilities.
Course Length: 4 Hours
Includes a Certificate of Completion
Next scheduled date:
Notify me when available
Description
This course will teach you how to test web APIs for authorization and access control related security flaws. You will learn how to map API functionality, identify authentication and authorization flaws, and exploit common API vulnerabilities.
You will also gain hands-on experience with tools and techniques for testing API authorization mechanisms and access control models. By the end of this course, you will be able to:
- Perform API reconnaissance and endpoint analysis
- Scan APIs for security misconfigurations and excessive data exposure
- Attack API authentication schemes
- Test API authorization mechanisms for vulnerabilities like insecure direct object references and privilege escalation
- Test APIs for rate limiting and business logic flaws
- Combine tools and techniques to exploit API weaknesses
-
Student Requirements
- Students will need a computer capable of running the local SamuraiWTF VM lab environment.
FAQ
Explore OWASP API Security Top 10 2019
How to attack REST APIs
How to prevent API security flaws
Explore and attack OAuth and JWTs
Understand that strong data validation is key to API security
This course is suitable for anyone who wants to learn how to hack web APIs or improve their API security skills. You should have some basic knowledge of web application security, HTTP requests, and common API testing tools.
Anyone with an interest in REST API security will benefit from this course. The course is aimed at teaching students how to think about REST API security from an attacker mindset, which is useful for defenders and attackers alike.
Students will be provided access to download an OVA image of the SamuraiWTF lab environment virtual machine. Students will be able to continue to use this VM after the course to practice labs on their own time.
About the Instructor
Secure Ideas
Bio
Founded in 2010 by Kevin Tackett, Secure Ideas is a “professionally evil” cybersecurity consulting firm specializing in penetration testing, application security, and PCI compliance. With consults averaging 10+ years of experience in IT/Cybersecurity, the team has tested Fortune 100 companies and government agencies worldwide. CREST-certified and PCI QSA-qualified, Secure Ideas instructors are active practitioners who work real engagements, speak at DEF CON and Black Hat, and contribute to open-source security tools year-round.
– Kevin Tackett is a lifetime OWASP member and global board member, serving as Vice Chair of the Projects Committee since 2020
– Founded open-source security projects including SamuraiWTF, Laudanum, Yokoso, and MObiSec
– Kevin authored three SANS Institute courses prior to founding Secure Ideas
– Provides expert witness services in cybersecurity-related legal and compliance matters
Related products
-
Dale HobbsLive4 Hrs
Workshop: Intro to Active Directory
View Course This product has multiple variants. The options may be chosen on the product page -
Hal DentonLive4 Hrs
Workshop: Telemetry to Tactics: A Hands-On Detection Engineering Workshop with Hal Denton
View Course This product has multiple variants. The options may be chosen on the product page -
Kevin TackettLiveOD12 Hrs
Practical OWASP TOP 10
View Course -
Secure IdeasLive4 Hrs
Professionally Evil API Testing: GraphQL, SOAP, and REST Fundamentals and Techniques
View Course
