SilverStr

Dana Epp's Blog

Security (de)engineering for fun and profit

  • About
  • Blog
  • Home
  • April 9, 2024

    Breaking APIs with Naughty Strings

    Breaking APIs with Naughty Strings

    Learn how to leverage the Big List of Naughty Strings (BLNS) to break APIs using nothing more than Postman.

  • April 2, 2024

    The Beginners Guide to Writing API Security Tests in Postman

    The Beginners Guide to Writing API Security Tests in Postman

    Learn everything you need to know about how to get started writing API security tests in Javascript using Postman.

  • March 26, 2024

    Improving port scans against API servers

    Improving port scans against API servers

    Learn how to improve the performance of your port scans against API servers with the use of Project Discovery’s Naabu scanner.

  • March 19, 2024

    Discovering API secrets & endpoints using APKLeaks

    Discovering API secrets & endpoints using APKLeaks

    Learn how to improve your recon process with the use of apkleaks to find hidden API servers, secrets, and endpoints embedded in mobile apps.

  • March 12, 2024

    5 more Burp extensions for API hacking

    5 more Burp extensions for API hacking

    Check out these five Burp Suite extensions that can help your API hacking. From bypassing WAFs to generating wordlists, it can all help.

  • March 5, 2024

    Is Nuclei any good for API hacking?

    Is Nuclei any good for API hacking?

    Let me show you how Nuclei can be used for more than vulnerability scanning. Learn how to leverage it as a tool for your API hacking.

  • February 27, 2024

    5 mistakes beginners make during app recon

    5 mistakes beginners make during app recon

    Learn about the five mistakes beginners make during their app recon that limit their ability to find vulns during their API security testing.

  • February 20, 2024

    Writing API exploits in Python

    Writing API exploits in Python

    Learn how to leverage curlconverter to write API exploits in Python using payloads you generated in Burp Suite.

  • February 13, 2024

    Endpoints vs Routes: What every API hacker needs to know

    Endpoints vs Routes: What every API hacker needs to know

    Learn the difference between API endpoints and routes and how to think about it as an API hacker during your security testing.

  • February 6, 2024

    Detecting API endpoints and source code with JS Miner

    Detecting API endpoints and source code with JS Miner

    Learn how to detect API endpoints and extract source code from web app frontends using JS Miner, a FREE Burp Suite Professional extension.

←Previous Page
1 2 3 4 5 6 … 13
Next Page→
 

Loading Comments...