Hacking APIs: Fuzzing 101

Поделиться
HTML-код
  • Опубликовано: 16 янв 2025

Комментарии • 31

  • @chipko
    @chipko Год назад +5

    Oh wow! This is amazing and so quick. Thank you Alex, Heath and TCM!

  • @Tekionemission
    @Tekionemission Год назад +3

    (2:02, 5:21) Lab and Fuzz Parameter
    (7:40) Wfuzz filter out 404
    (11:33, 11:51) Wfuzz

  • @faadi4536
    @faadi4536 Год назад +3

    Never knew about this up until now. Good job bro.

  • @m1ni_m4l
    @m1ni_m4l Год назад +5

    Thanks for the content, really important and precise. TCM courses helped me a lot in my cybersec journey!

  • @mridulkumartiwari607
    @mridulkumartiwari607 Год назад +3

    Much needed video 🤠📸

  • @Mrg-kj5ml
    @Mrg-kj5ml Год назад

    That was super informative. Thanks for thorough explanation.

  • @worm_403
    @worm_403 2 месяца назад

    Interesting video man thanks for your contribution

  • @Z0nd4
    @Z0nd4 Год назад

    Thanks for this videos, I just begin in the API pentest wave, and Its very interesting.

  • @skysunset877
    @skysunset877 10 месяцев назад

    Super good! Thank you!

  • @renatojlopes
    @renatojlopes Год назад +1

    Thanks for sharing this.

  • @janekmachnicki2593
    @janekmachnicki2593 Год назад

    Great tutorial mate .Thanks

  • @nonlinearsound-001
    @nonlinearsound-001 Год назад +15

    Been in the coding game for the past 20 years and made a lot of mistakes and had my successes. But, what I don’t understand at all, is, who on Earth would code a Web-API and include direct file access like this, basically creating a reverse shell? (more or less). Do we really have such a significant amount of software out there, featuring this kind of flaw?

    • @offsecprep
      @offsecprep Год назад +6

      Yes, the main point is the methodology rather than the vulnerability. But, you'd be surprised, I've seen quite a few simple vulns like this in the past when carrying out pentests (granted, usually before the application is released - it's less likely you'll find this in the wild or during BB)

    • @SmedleyButler1
      @SmedleyButler1 Год назад

      ​@@offsecprep a channel showing packet and pentesting of libre apps would be great and you sound like you could do it! To get started a unique and hugely popular video idea would be on hash /checksum app verification ON Android, FOR Android? Hash Droid is the only way I know of and I'm still not sure how to use it often (auto runs, zipped files, playstore vs Foxydroid or neostore) NOBODY has done this and it seems like THE most important thing to do!?...lots of.powershell vids on it but not everyone uses windows....also, is a chromebook really more secure than Linux as one tech (not cyber security) guy claims? He said cyber pros told him to use it or Linux in a virtual machine in windows

  • @BerniesBastelBude
    @BerniesBastelBude Год назад

    useful explanation - thank you!

  • @harrylumsdon6773
    @harrylumsdon6773 Год назад +1

    Great stuff

  • @Alaa-kc4rx
    @Alaa-kc4rx Год назад

    Nice video, sir, and thanks for sharing this valuable content with us.
    please share moore videos about api enemuration and pentetst, with just basics

  • @leghdaf
    @leghdaf 9 месяцев назад

    Great Content ...

  • @doshamitv5020
    @doshamitv5020 7 месяцев назад

    IF THE LFI DIDNT WORK ON "ID param" could work on "author param" ? ( like the vulnb could work depend on the param right? ) or it also works on the other params?

  • @张佳新-j7u
    @张佳新-j7u Год назад +1

    how can i get api dictionary

  • @maryjanechukwuma9707
    @maryjanechukwuma9707 3 месяца назад

    how can i get the World list you used in this video

  • @bitminersouth8845
    @bitminersouth8845 Год назад

    I have the same chair, I was expecting more confort.

  • @varunfoodvlog9215
    @varunfoodvlog9215 Год назад

    api endpoint give 404 error then what i do,
    can anyone give me same tips?

  • @TradeFXCode
    @TradeFXCode Год назад

    I need wordlist txt

  • @sotecluxan4221
    @sotecluxan4221 Год назад

    !!

  • @_sownther_268
    @_sownther_268 Год назад +2

    1st comment 😁

  • @TheCyberWarriorGuy
    @TheCyberWarriorGuy Год назад

    :)

  • @kunwaradarshsingh6436
    @kunwaradarshsingh6436 Год назад +1

    4th comment 😀

  • @variXD
    @variXD Год назад +1

    your volume is too low

  • @austynstephens9263
    @austynstephens9263 Год назад

    🫡