Kuboid
Open Luck·Kuboid.in
Security BSides2025
Open in YouTube ↗

Anyone Can Hack APIs: A Crash Course For Pentesters And Bug Bounty Hunters

Security BSides London401 views46:31about 1 month ago

This talk demonstrates how to identify and exploit common API vulnerabilities, specifically focusing on Broken Object Level Authorization (BOLA) and Mass Assignment. It highlights the importance of understanding API structure, identifying hidden endpoints, and testing workflows rather than just individual endpoints. The speaker provides a practical methodology for API penetration testing, emphasizing the use of tools like Postman for automated testing and the value of manual reconnaissance.

Talk Type
talk
Difficulty
beginner
Category
web security
Has Demo Has Code Tool Released


BSides London 2025 Track 2

8 talks · 2025
Browse conference →
Premium Security Audit

We break your app before they do.

Professional penetration testing and vulnerability assessments by the Kuboid Secure Layer team. Securing your infrastructure at every layer.

Get in Touch
Official Security Partner
kuboid.in