Dana Epp's Blog
Security (de)engineering for fun and profit
Learn three reasons why QA people should get into API hacking to help secure their company’s apps.
Learn how to find exploitable vulnerabilities in your APIs using taint analysis.
Check out the 3 cyber warfare books every API hacker should read to learn about offensive security, past, present, and future.
Learn how to predict and pwn GUIDs used in APIs.
Learn the rules of engagement when pentesting APIs.
Check out the coolest extensions to help out when hacking APIs in Burp.
Avoid these beginner mistakes as you start your API hacking journey.
Learn how you can leverage the data in a software bill of materials (SBOM) document to find vulnerabilities in API dependencies.
Learn how to use Postman to attack the Microsoft Graph API.
Learn how to find authorization vulnerabilities in APIs using Burp and Autorize.