Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
API pentest requirements?
https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/

I found an interesting article here and have a few questions. https://www.getsecureworld.com/blog/what-are-the-api-pentest-requirements/ I understand that user credentials are required per profile to test vulnerabilities related to broken access controls. But what about an API dataset? Here is the info taken from that site. ​ An API dataset Now, what if the documentation does not exist and you need to perform an API pentest. In this situation, you will need to give as much dataset about the API communication as possible. A dataset is simply a history group of requests and responses between the developers and your API. This could be retrieved from the test phase of your API. The request should include all the needed parameters with their values, and all the required authentication cookies and tokens. In addition, you should include at least one valid response for each request. The more API dataset you give to your service provider, the more tests he would perform, and of course, the more likely to find vulnerabilities. However, offering the API documentation stay the best solution for better results. Here is an example of such dataset: Message type Example Request GET http://example.com:8090/tpmRest/v1/participants/participant?isHost=false&name=partner1&isActive=true Response Successful operation response:{“result”:”Operate successfully”}Failed operation response:{“errorMessage”:”XXXXXX”} What is the common practice when do you perform API pentest? Do you get an API dataset during initial meeting with your client? The reason I'm asking this is I found a bunch of articles and tutorials about API enumeration. e.g. API recon tutorials https://portswigger.net/support/using-burp-to-enumerate-a-rest-api https://www.redteamsecure.com/research/api-enumeration-with-redteam-securitys-tool-purl https://www.youtube.com/watch?v=fvcKwUS4PTE So, if we already have this API dataset, API enumeration is no longer required right? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/) [comments] (https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/)

___________________________
@hacking_Attack
@Hacking_Video
API pentest requirements?
https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/

I found an interesting article here and have a few questions. https://www.getsecureworld.com/blog/what-are-the-api-pentest-requirements/ I understand that user credentials are required per profile to test vulnerabilities related to broken access controls. But what about an API dataset? Here is the info taken from that site. ​ An API dataset Now, what if the documentation does not exist and you need to perform an API pentest. In this situation, you will need to give as much dataset about the API communication as possible. A dataset is simply a history group of requests and responses between the developers and your API. This could be retrieved from the test phase of your API. The request should include all the needed parameters with their values, and all the required authentication cookies and tokens. In addition, you should include at least one valid response for each request. The more API dataset you give to your service provider, the more tests he would perform, and of course, the more likely to find vulnerabilities. However, offering the API documentation stay the best solution for better results. Here is an example of such dataset: Message type Example Request GET http://example.com:8090/tpmRest/v1/participants/participant?isHost=false&name=partner1&isActive=true Response Successful operation response:{“result”:”Operate successfully”}Failed operation response:{“errorMessage”:”XXXXXX”} What is the common practice when do you perform API pentest? Do you get an API dataset during initial meeting with your client? The reason I'm asking this is I found a bunch of articles and tutorials about API enumeration. e.g. API recon tutorials https://portswigger.net/support/using-burp-to-enumerate-a-rest-api https://www.redteamsecure.com/research/api-enumeration-with-redteam-securitys-tool-purl https://www.youtube.com/watch?v=fvcKwUS4PTE So, if we already have this API dataset, API enumeration is no longer required right? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/) [comments] (https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Preferred VM for opening malware?

Hey all you hacking people, just wanted to know what your favorite sandbox for opening Malware is?

I got sent spam and would like to do OSINT on the attachments.

I am going to forward the email to a throw away email account within a Ubuntu VM download and run OSINT on the file. Anything I am missing? Thanks in advance!

submitted by /u/Irhsjakdjj
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
hacking printers

So, I am interested in hacking embedded systems, and especially printers rn, I searched on the sub and on Google there isn't really that much about it, like where do you start and what should you know to be able to hack printers?

( currently learning to use Linux and networking then will hopefully study for a CEH and do some capture the flags and stuff idk will think about it when I get to this point )

So, where can I learn about this topic?

submitted by /u/Fuck_Life_421
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video