Skip to main content

API Hacking For Testers

180-minute Workshop

Learn how to hack APIs & Exploit them

Timetable

1:30 p.m. – 4:30 p.m. Wednesday 18th

Room

Room E2+E3 - Track 5: Workshops

Security Testing

Audience

Testers, Devs, ...

Required

Laptop with Burpsuite Community Edition Installed + Internet

Key-Learnings

  • You'll learn new Test Techniques
  • You'll learn how to think outside of the box when it comes to APIs
  • You'll learn about new vulnerabilities and how to find them

A lot of courses will teach you how to work with a tool but less on how to actually test an API. In this workshop we'll focus just on that part. While Ethical Hacking is mostly done by security professionals, but why not do it yourself? There are several vulnerabilities that a tester can find and exploit without the help of a Security Expert. And I'm not just talking about the most common vulnerabilities that you'll find in all the blogs and "top 10 lists", there are hundreds of different types of vulnerabilities out there which also need to be found and fixed. 

We'll dive into the basics of Burpsuite (a proxy tool used for penetration testing that lets you examine and change API requests) for offensive security and I'll explain several vulnerabilities and how to exploit them, you'll then have hands-on experiences yourself finding these vulnerabilities. Afterwards I'll share a real world story of how I used these vulnerabilities in the to ethically hack a client's company or application on the job. 

In this workshop you'll learn new test techniques to start hacking APIs, new vulnerabilities that you'll be able to find and exploit. You do not need to have scripting or coding skills, everything will be done manually!

If you want to start assisting your security and/or development team, if you want to detect these vulnerabilities before the pen-test occurs (shift left), or if you just ever wanted to start out in Offensive Cyber Security, then this is a workshop for you!

Related Sessions

Thu, Nov 19 • 1:30 p.m. – 4:30 p.m.
Room D1+D2 - Track 6: Workshops

180-minute Workshop

Collaboration & Communication Other Security Testing

Virtual Pass session
Wed, Nov 18 • 10:45 a.m. – 11:30 a.m.
Room F3 - Track 3: Talks

25-minute Talk

Continuous Integration/Continuous Delivery (CI/CD) Security Testing

Virtual Pass session
Tue, Nov 17 • 1:30 p.m. – 2:15 p.m.
Room F2 - Track 2: Talks

25-minute Talk

Other Security Testing

Virtual Pass session
Thu, Nov 19 • 3:45 p.m. – 4:30 p.m.
Room F1 - Track 1: Talks

25-minute Talk

Security Testing