Dana Epp's Blog
Security (de)engineering for fun and profit
Learn how to reverse engineer an Electron app to find artifacts like source code and API endpoints, and capture live traffic with Burp Suite.
Learn how to weaponize developer tools used for API linting to find attack vectors in the APIs you are hacking.
Follow my journey as I try Bruno for the first time and see if it’s a good alternative to Postman for API hacking.
Learn everything you need to know about how to get started writing API security tests in Javascript using Postman.
Learn how to improve the performance of your port scans against API servers with the use of Project Discovery’s Naabu scanner.
Learn how to improve your recon process with the use of apkleaks to find hidden API servers, secrets, and endpoints embedded in mobile apps.
Check out these five Burp Suite extensions that can help your API hacking. From bypassing WAFs to generating wordlists, it can all help.
Let me show you how Nuclei can be used for more than vulnerability scanning. Learn how to leverage it as a tool for your API hacking.
Learn how to leverage curlconverter to write API exploits in Python using payloads you generated in Burp Suite.
Learn how to detect API endpoints and extract source code from web app frontends using JS Miner, a FREE Burp Suite Professional extension.