Dana Epp's Blog
Security (de)engineering for fun and profit
Learn how to improve your application security code reviews with the help of tools like graudit.
Explore the misconceptions and anti-patterns of applying security testing to APIs, and how to address them.
Learn why Human Application Security Testing (HAST) is important to API hackers.
Learn how to write Burp Suite extensions using the new Montoya API with Kotlin and Visual Studio Code (VS Code)
Learn how to use artificial intelligence (AI) to discover sensitive data in the APIs you are hacking with the help of Microsoft Presidio.
Learn how to reverse engineer an Electron app to find artifacts like source code and API endpoints, and capture live traffic with Burp Suite.
Explore why bug hunters should be more patient as vendors try to improve their application security maturity from a VDP to a BBP.
Learn how to weaponize developer tools used for API linting to find attack vectors in the APIs you are hacking.
Check out these five tips to help you pick your first target when starting bug bounty hunting against APIs.
Follow my journey as I try Bruno for the first time and see if it’s a good alternative to Postman for API hacking.