API pentest requirements?
https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/
I found an interesting article here and have a few questions. https://www.getsecureworld.com/blog/what-are-the-api-pentest-requirements/ I understand that user credentials are required per profile to test vulnerabilities related to broken access controls. But what about an API dataset? Here is the info taken from that site. An API dataset Now, what if the documentation does not exist and you need to perform an API pentest. In this situation, you will need to give as much dataset about the API communication as possible. A dataset is simply a history group of requests and responses between the developers and your API. This could be retrieved from the test phase of your API. The request should include all the needed parameters with their values, and all the required authentication cookies and tokens. In addition, you should include at least one valid response for each request. The more API dataset you give to your service provider, the more tests he would perform, and of course, the more likely to find vulnerabilities. However, offering the API documentation stay the best solution for better results. Here is an example of such dataset: Message type Example Request GET http://example.com:8090/tpmRest/v1/participants/participant?isHost=false&name=partner1&isActive=true Response Successful operation response:{“result”:”Operate successfully”}Failed operation response:{“errorMessage”:”XXXXXX”} What is the common practice when do you perform API pentest? Do you get an API dataset during initial meeting with your client? The reason I'm asking this is I found a bunch of articles and tutorials about API enumeration. e.g. API recon tutorials https://portswigger.net/support/using-burp-to-enumerate-a-rest-api https://www.redteamsecure.com/research/api-enumeration-with-redteam-securitys-tool-purl https://www.youtube.com/watch?v=fvcKwUS4PTE So, if we already have this API dataset, API enumeration is no longer required right? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/) [comments] (https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/
I found an interesting article here and have a few questions. https://www.getsecureworld.com/blog/what-are-the-api-pentest-requirements/ I understand that user credentials are required per profile to test vulnerabilities related to broken access controls. But what about an API dataset? Here is the info taken from that site. An API dataset Now, what if the documentation does not exist and you need to perform an API pentest. In this situation, you will need to give as much dataset about the API communication as possible. A dataset is simply a history group of requests and responses between the developers and your API. This could be retrieved from the test phase of your API. The request should include all the needed parameters with their values, and all the required authentication cookies and tokens. In addition, you should include at least one valid response for each request. The more API dataset you give to your service provider, the more tests he would perform, and of course, the more likely to find vulnerabilities. However, offering the API documentation stay the best solution for better results. Here is an example of such dataset: Message type Example Request GET http://example.com:8090/tpmRest/v1/participants/participant?isHost=false&name=partner1&isActive=true Response Successful operation response:{“result”:”Operate successfully”}Failed operation response:{“errorMessage”:”XXXXXX”} What is the common practice when do you perform API pentest? Do you get an API dataset during initial meeting with your client? The reason I'm asking this is I found a bunch of articles and tutorials about API enumeration. e.g. API recon tutorials https://portswigger.net/support/using-burp-to-enumerate-a-rest-api https://www.redteamsecure.com/research/api-enumeration-with-redteam-securitys-tool-purl https://www.youtube.com/watch?v=fvcKwUS4PTE So, if we already have this API dataset, API enumeration is no longer required right? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/) [comments] (https://www.reddit.com/r/redteamsec/comments/wv7tji/api_pentest_requirements/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
API pentest requirements?
I found an interesting article here and have a few...
API pentest requirements?
https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/
I found an interesting article here and have a few questions. https://www.getsecureworld.com/blog/what-are-the-api-pentest-requirements/ I understand that user credentials are required per profile to test vulnerabilities related to broken access controls. But what about an API dataset? Here is the info taken from that site. An API dataset Now, what if the documentation does not exist and you need to perform an API pentest. In this situation, you will need to give as much dataset about the API communication as possible. A dataset is simply a history group of requests and responses between the developers and your API. This could be retrieved from the test phase of your API. The request should include all the needed parameters with their values, and all the required authentication cookies and tokens. In addition, you should include at least one valid response for each request. The more API dataset you give to your service provider, the more tests he would perform, and of course, the more likely to find vulnerabilities. However, offering the API documentation stay the best solution for better results. Here is an example of such dataset: Message type Example Request GET http://example.com:8090/tpmRest/v1/participants/participant?isHost=false&name=partner1&isActive=true Response Successful operation response:{“result”:”Operate successfully”}Failed operation response:{“errorMessage”:”XXXXXX”} What is the common practice when do you perform API pentest? Do you get an API dataset during initial meeting with your client? The reason I'm asking this is I found a bunch of articles and tutorials about API enumeration. e.g. API recon tutorials https://portswigger.net/support/using-burp-to-enumerate-a-rest-api https://www.redteamsecure.com/research/api-enumeration-with-redteam-securitys-tool-purl https://www.youtube.com/watch?v=fvcKwUS4PTE So, if we already have this API dataset, API enumeration is no longer required right? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/) [comments] (https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/
I found an interesting article here and have a few questions. https://www.getsecureworld.com/blog/what-are-the-api-pentest-requirements/ I understand that user credentials are required per profile to test vulnerabilities related to broken access controls. But what about an API dataset? Here is the info taken from that site. An API dataset Now, what if the documentation does not exist and you need to perform an API pentest. In this situation, you will need to give as much dataset about the API communication as possible. A dataset is simply a history group of requests and responses between the developers and your API. This could be retrieved from the test phase of your API. The request should include all the needed parameters with their values, and all the required authentication cookies and tokens. In addition, you should include at least one valid response for each request. The more API dataset you give to your service provider, the more tests he would perform, and of course, the more likely to find vulnerabilities. However, offering the API documentation stay the best solution for better results. Here is an example of such dataset: Message type Example Request GET http://example.com:8090/tpmRest/v1/participants/participant?isHost=false&name=partner1&isActive=true Response Successful operation response:{“result”:”Operate successfully”}Failed operation response:{“errorMessage”:”XXXXXX”} What is the common practice when do you perform API pentest? Do you get an API dataset during initial meeting with your client? The reason I'm asking this is I found a bunch of articles and tutorials about API enumeration. e.g. API recon tutorials https://portswigger.net/support/using-burp-to-enumerate-a-rest-api https://www.redteamsecure.com/research/api-enumeration-with-redteam-securitys-tool-purl https://www.youtube.com/watch?v=fvcKwUS4PTE So, if we already have this API dataset, API enumeration is no longer required right? submitted by /u/w0lfcat (https://www.reddit.com/user/w0lfcat)
[link] (https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/) [comments] (https://www.reddit.com/r/Pentesting/comments/wv7t74/api_pentest_requirements/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
API pentest requirements?
I found an interesting article here and have a few...
hacking: security in practice
Preferred VM for opening malware?
Hey all you hacking people, just wanted to know what your favorite sandbox for opening Malware is?
I got sent spam and would like to do OSINT on the attachments.
I am going to forward the email to a throw away email account within a Ubuntu VM download and run OSINT on the file. Anything I am missing? Thanks in advance!
submitted by /u/Irhsjakdjj
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Preferred VM for opening malware?
Hey all you hacking people, just wanted to know what your favorite sandbox for opening Malware is?
I got sent spam and would like to do OSINT on the attachments.
I am going to forward the email to a throw away email account within a Ubuntu VM download and run OSINT on the file. Anything I am missing? Thanks in advance!
submitted by /u/Irhsjakdjj
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Preferred VM for opening malware?
Hey all you hacking people, just wanted to know what your favorite sandbox for opening Malware is? I got sent spam and would like to do OSINT on...
hacking: security in practice
hacking printers
So, I am interested in hacking embedded systems, and especially printers rn, I searched on the sub and on Google there isn't really that much about it, like where do you start and what should you know to be able to hack printers?
( currently learning to use Linux and networking then will hopefully study for a CEH and do some capture the flags and stuff idk will think about it when I get to this point )
So, where can I learn about this topic?
submitted by /u/Fuck_Life_421
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
hacking printers
So, I am interested in hacking embedded systems, and especially printers rn, I searched on the sub and on Google there isn't really that much about it, like where do you start and what should you know to be able to hack printers?
( currently learning to use Linux and networking then will hopefully study for a CEH and do some capture the flags and stuff idk will think about it when I get to this point )
So, where can I learn about this topic?
submitted by /u/Fuck_Life_421
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
hacking printers
So, I am interested in hacking embedded systems, and especially printers rn, I searched on the sub and on Google there isn't really that much...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Staying Safe Online in a Digital Age
https://cdn-images-1.medium.com/max/2600/0*S9qHwIHv33e7Q3EJ
Staying safe today is far different than staying safe a decade or two ago. With data like emails and passwords, bank accounts, and social…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Staying Safe Online in a Digital Age
https://cdn-images-1.medium.com/max/2600/0*S9qHwIHv33e7Q3EJ
Staying safe today is far different than staying safe a decade or two ago. With data like emails and passwords, bank accounts, and social…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Staying Safe Online in a Digital Age
Staying safe today is far different than staying safe a decade or two ago. With data like emails and passwords, bank accounts, and social…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Conozca Borat RAT, una nueva triple amenaza única
https://cdn-images-1.medium.com/max/1707/0*C4JSmTfqV0B5YXCe
La compañía de inteligencia de riesgos cibernéticos con sede en Atlanta, Cyble, descubrió un nuevo malware troyano de acceso remoto (RAT)…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Conozca Borat RAT, una nueva triple amenaza única
https://cdn-images-1.medium.com/max/1707/0*C4JSmTfqV0B5YXCe
La compañía de inteligencia de riesgos cibernéticos con sede en Atlanta, Cyble, descubrió un nuevo malware troyano de acceso remoto (RAT)…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Conozca Borat RAT, una nueva triple amenaza única
La compañía de inteligencia de riesgos cibernéticos con sede en Atlanta, Cyble, descubrió un nuevo malware troyano de acceso remoto (RAT)…
Hacking on Medium
Hack The Box Walkthrough: Jeeves
https://cdn-images-1.medium.com/max/1400/1*ujkfxvwPikKoh5XVMZt78A.png
I enjoy doing CTFs and I think everyone should try them, they allow us to hone our skills while having a little fun at the same time. This…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack The Box Walkthrough: Jeeves
https://cdn-images-1.medium.com/max/1400/1*ujkfxvwPikKoh5XVMZt78A.png
I enjoy doing CTFs and I think everyone should try them, they allow us to hone our skills while having a little fun at the same time. This…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack The Box Walkthrough: Jeeves
I enjoy doing CTFs and I think everyone should try them, they allow us to hone our skills while having a little fun at the same time. This…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Over 80,000 exploitable Hikvision cameras exposed online
https://external-preview.redd.it/oNzEOhUkl2OUY2RC0sd2GuNblPx7-D0D5_uDnkxGEw0.jpg?width=640&crop=smart&auto=webp&s=297156fff941ba452cffd6d8199b0191e3fd25b6 submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Over 80,000 exploitable Hikvision cameras exposed online
https://external-preview.redd.it/oNzEOhUkl2OUY2RC0sd2GuNblPx7-D0D5_uDnkxGEw0.jpg?width=640&crop=smart&auto=webp&s=297156fff941ba452cffd6d8199b0191e3fd25b6 submitted by /u/Glad_Living3908
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Over 80,000 exploitable Hikvision cameras exposed online
Posted in r/hacking by u/Glad_Living3908 • 1 point and 0 comments
hacking: security in practice
Hacking Documentaries?
Would love some suggestions to good hacking documentaries.
submitted by /u/djcrank4life
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Documentaries?
Would love some suggestions to good hacking documentaries.
submitted by /u/djcrank4life
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Game hacking and cheat development
https://cdn-images-1.medium.com/max/631/1*udivd4CnmdRO0xcq0ovffA.png
A simple overview of how game cheats work and how hard it can be to actually make game cheats.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Game hacking and cheat development
https://cdn-images-1.medium.com/max/631/1*udivd4CnmdRO0xcq0ovffA.png
A simple overview of how game cheats work and how hard it can be to actually make game cheats.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
gGame hacking and cheat development
A simple overview of how game cheats work and how hard it can be to actually make game cheats.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Lloyd’s New Cyber Insurance Exclusions Aim to Avoid Payouts from Nation State Hacks
https://cdn-images-1.medium.com/max/1280/1*TJ2Se3uHJiBW3-Fxk9JZ0A.png
The recent announcement by the insurance giant Lloyds of London, may be the biggest cybersecurity news of the year. It might not seem all…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Lloyd’s New Cyber Insurance Exclusions Aim to Avoid Payouts from Nation State Hacks
https://cdn-images-1.medium.com/max/1280/1*TJ2Se3uHJiBW3-Fxk9JZ0A.png
The recent announcement by the insurance giant Lloyds of London, may be the biggest cybersecurity news of the year. It might not seem all…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Lloyd’s New Cyber Insurance Exclusions Aim to Avoid Payouts from Nation State Hacks
The recent announcement by the insurance giant Lloyds of London, may be the biggest cybersecurity news of the year. It might not seem all…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
You should learn THIS before HACKING
https://cdn-images-1.medium.com/max/2600/1*yZhz2Ik_q62TzZXwpiIYZQ.jpeg
Hacking, Penetration Testing and Red Teaming is a broad field and requires huge amounts of skills in order to succeed.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
You should learn THIS before HACKING
https://cdn-images-1.medium.com/max/2600/1*yZhz2Ik_q62TzZXwpiIYZQ.jpeg
Hacking, Penetration Testing and Red Teaming is a broad field and requires huge amounts of skills in order to succeed.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
You should learn THIS before HACKING
Hacking, Penetration Testing and Red Teaming is a broad field and requires huge amounts of skills in order to succeed. If you want to learn…
Cool Recon techniques every hacker misses!
https://medium.com/@lakhaniv28/cool-recon-techniques-every-hacker-misses-1c5e0e294e89?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@lakhaniv28/cool-recon-techniques-every-hacker-misses-1c5e0e294e89?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cool Recon techniques every hacker misses! 🔥🔥
Welcome to this article! This article is about some cool recon techniques every hacker misses! Tighten your belts as we walk you through…
Welcome to this article! This article is about some cool recon techniques every hacker misses! Tighten your belts as we walk you through…Continue reading on Medium » (https://medium.com/@lakhaniv28/cool-recon-techniques-every-hacker-misses-1c5e0e294e89?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cool Recon techniques every hacker misses! 🔥🔥
Welcome to this article! This article is about some cool recon techniques every hacker misses! Tighten your belts as we walk you through…