1印度演讲.pdf

编号:620920 PDF 28页 1.95MB 下载积分:VIP专享
下载报告请您先登录!

1印度演讲.pdf

1、Hacking APIsRisks,Techniques,Real world examples and DefenseSecure The Backbone Of Modern Application2025/01/11Muthu DAbout MeMost Valuable Security Researcher at Microsoft in 2023 and 2024,recognized globally for contributions to improving security.Ranked 24th on the Microsoft Security Researcher L

2、eaderboard in 2023.Consistently recognized as a Top Security Researcher in Microsoft across multiple quarters(2023 Q1,Q2,Q3,Q4)(2024 Q1,Q2).Recognized and rewarded by Cloudflare,GitHub,and Coinbase for impactful security research.Multiple Hall of Fame recognitions and rewards from Apple,Google,and o

3、thers.Invited by Airtel to NullCon Goa 2023 for a live hacking event.Twitter XLinkedInAgenda1.What is an API?2.Why APIs are critical3.Common API vulnerabilities4.Real-world examples5.Securing APIs6.ConclusionWhat is an API?Definition:An API(Application Programming Interface)allows communication betw

4、een software applications.Examples:-REST-GraphQL-SOAPWhy APIs Are Critical-APIs power modern apps(e.g.,social media,payment gateways,IoT).-Connect systems and expose data to partners,developers,or customers.Fun Fact:APIs account for 83%of web traffic(source:Akamai).Common API Vulnerabilities1.Mass A

5、ssignment2.Excessive Data Exposure3.API Authentication Vulnerabilities4.API Authorization Vulnerabilities(BOLA&BFLA)5.Rate Limit Bypass6.Header Injection BypassMass AssignmentDefinition:Unauthorized parameter inclusion in requests to alter object properties or privileges.Example:Sending a parameter

6、like isAdmin:true,during account creation to elevate user privileges.admin:true,admin:1,isadmin:true,role:admin,role:administrator,MFA:True,Common places to discover:-Account registration-Unauthorized Access to Organization-Finding Variables in Documentation-Fuzzing unknown variables-Blind Mass Assi

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(1印度演讲.pdf)为本站 (张5G) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠