Filter
Exclude
Time range
-
Near
Day 30/#30daysofApisecU Covered OWASP API Top 10, API pentesting, and security fundamentals hands on. Worked through crAPI, DVAPI, and realworld API finding flaws, breaking auth, and understanding what defenders miss. Will continue my journey with GraphQL. @ce3nerd @hAPI_hacker
Day 28&29/#30DaysofApisecU I tested my brother's RestAPI and reported to him what I found. I practiced all I learnt from @hAPI_hacker course on APIsecU and book. looking forward to testing more real life API @akintunero @commando_skiipz @ce3nerd @KoredeSec
3
5
36
1,408
Day 28&29/#30DaysofApisecU I tested my brother's RestAPI and reported to him what I found. I practiced all I learnt from @hAPI_hacker course on APIsecU and book. looking forward to testing more real life API @akintunero @commando_skiipz @ce3nerd @KoredeSec
Day 27/#30DaysofAPIsecU Chapter 2 reading "Black Hat GraphQL " installation of tools that will be needed throughout the course. @akintunero @commando_skiipz @ce3nerd @KoredeSec @hAPI_hacker
1
2
26
2,455
Day 27/#30DaysofAPIsecU Chapter 2 reading "Black Hat GraphQL " installation of tools that will be needed throughout the course. @akintunero @commando_skiipz @ce3nerd @KoredeSec @hAPI_hacker
Day26/#30DaysofApisecU I started reading "BLACK HAT GRAPHQL" as recommended to me by @hAPI_hacker . chapter 1 done learnt basics and also write my first GraphQL query @commando_skiipz @ce3nerd @akintunero @KoredeSec
2
17
1,346
Day26/#30DaysofApisecU I started reading "BLACK HAT GRAPHQL" as recommended to me by @hAPI_hacker . chapter 1 done learnt basics and also write my first GraphQL query @commando_skiipz @ce3nerd @akintunero @KoredeSec
Day 26/#30DaysofAPIsecU Continue learning GraphQL by reading this book by @hAPI_hacker building my skills around API hacking @akintunero @commando_skiipz @ce3nerd @KoredeSec
1
2
14
591
Day 26/#30DaysofAPIsecU Continue learning GraphQL by reading this book by @hAPI_hacker building my skills around API hacking @akintunero @commando_skiipz @ce3nerd @KoredeSec
DAY 24 I started learning GraphQL and how to test it @commando_skiipz @ce3nerd @akintunero @KoredeSec
2
3
21
1,572
Day 23/#30daysofApisecU I completed DVAPI 9/10 OWASP API , 9 flags captured 🔥 JWT attack NoSQL injection login bypass BOLA via username parameter HTTP method tampering for privilege Below 👇🏻 is my medium link medium.com/@abdulmalikadebay… @akintunero @commando_skiipz @ce3nerd
Day 22/#30DaysofAPIsecU I got 9/10 flag remain the SSRF , this really sharpen my brain about API testing and how to solve thing On to the next lab @commando_skiipz @KoredeSec @ce3nerd @akintunero @nacss_uniosun
1
3
25
1,038
Day 22/#30DaysofAPIsecU I got 9/10 flag remain the SSRF , this really sharpen my brain about API testing and how to solve thing On to the next lab @commando_skiipz @KoredeSec @ce3nerd @akintunero @nacss_uniosun
Day21/#30Days I set up DVAPI today and started the CTF got 5/10 flags looking forward to remaining @commando_skiipz @ce3nerd @KoredeSec @nacss_uniosun @akintunero
2
16
1,380
Day 20/#30DaysofAPIsecU I tested the login page for user enumeration and reset password page for excessive data exposure check below👇for step by step @commando_skiipz @ce3nerd @KoredeSec
Day 19/#30DaysofAPIsecU I tested for Mass Assignment and was able to increase my account value , freeze it and also privileged escalation from customer to admin privileged check below👇 @commando_skiipz @ce3nerd @akintunero @KoredeSec @ireteeh
2
1
20
863
Day 19/#30DaysofAPIsecU I tested for Mass Assignment and was able to increase my account value , freeze it and also privileged escalation from customer to admin privileged check below👇 @commando_skiipz @ce3nerd @akintunero @KoredeSec @ireteeh
Day 18 /#30DaysofAPIsecU while testing today a particular endpoint grab my attention "GET/api/v1/accounts" ,I decided to add "admin" into the path which return other user acc . I will use them tomorrow and see what I can do with it @commando_skiipz @akintunero @ce3nerd @KoredeSec
3
8
42
2,816
Day 18 /#30DaysofAPIsecU while testing today a particular endpoint grab my attention "GET/api/v1/accounts" ,I decided to add "admin" into the path which return other user acc . I will use them tomorrow and see what I can do with it @commando_skiipz @akintunero @ce3nerd @KoredeSec
Day 17/#30DaysofAPIsecU I take a break yesterday , now I'm back practicing with what I have learnt last few days. I find 3 BOLA in OpenValut Bank . Below is how I find them 👇 @commando_skiipz @KoredeSec @nacss_uniosun @ce3nerd @ireteeh @elormkdaniel
2
3
49
5,328
Day 17/#30DaysofAPIsecU I take a break yesterday , now I'm back practicing with what I have learnt last few days. I find 3 BOLA in OpenValut Bank . Below is how I find them 👇 @commando_skiipz @KoredeSec @nacss_uniosun @ce3nerd @ireteeh @elormkdaniel
Day 15/#30DaysofAPIsecU congratulation to me and my self I Just wrapped up my API pentesting on APIsecU Learned a lot about finding vulnerabilities, tightening security, and thinking like an attacker. On to the next challenge @commando_skiipz @KoredeSec @ce3nerd @akintunero
2
2
26
3,493
Day 15/#30DaysofAPIsecU congratulation to me and my self I Just wrapped up my API pentesting on APIsecU Learned a lot about finding vulnerabilities, tightening security, and thinking like an attacker. On to the next challenge @commando_skiipz @KoredeSec @ce3nerd @akintunero
Day 14/#30daysofAPIsecU Tested for injection attack and crAPI is vulnerable ,, was able to inject the coupon code endpoint and got free coupon @commando_skiipz @KoredeSec @hAPI_hacker @ce3nerd @akintunero @nacss_uniosun
8
5
37
1,570
Day 14/#30daysofAPIsecU Tested for injection attack and crAPI is vulnerable ,, was able to inject the coupon code endpoint and got free coupon @commando_skiipz @KoredeSec @hAPI_hacker @ce3nerd @akintunero @nacss_uniosun
Day 13/#30DaysofAPIsecU Tested for SSRF on crAPI came out good , it was quite interesting . 2 more module and that is all @commando_skiipz @KoredeSec @akintunero @nacss_uniosun @hAPI_hacker @ce3nerd
1
2
20
1,377
Day 13/#30DaysofAPIsecU Tested for SSRF on crAPI came out good , it was quite interesting . 2 more module and that is all @commando_skiipz @KoredeSec @akintunero @nacss_uniosun @hAPI_hacker @ce3nerd
Day12/#30DaysofAPIsecU while testing for Mass assignment today on crAPI,I discovered the endpoint has business logic vuln , which allows me to increase my account balance @commando_skiipz @nacss_uniosun @KoredeSec @akintunero @hAPI_hacker
4
34
897
Day12/#30DaysofAPIsecU while testing for Mass assignment today on crAPI,I discovered the endpoint has business logic vuln , which allows me to increase my account balance @commando_skiipz @nacss_uniosun @KoredeSec @akintunero @hAPI_hacker
Day 11/#30DaysofApisecU Light out , decided to watch some part of my YouTube video " Red team recon" by hackersploit hoping for a better tomorrow @commando_skiipz @KoredeSec @nacss_uniosun
2
3
20
987
Day 11/#30DaysofApisecU Light out , decided to watch some part of my YouTube video " Red team recon" by hackersploit hoping for a better tomorrow @commando_skiipz @KoredeSec @nacss_uniosun
Day10/#30DaysofAPIsecU Tested for BFLA(Broken Function Level Authorization ) Mr Test was able to delete Mrs Test's private video by changing the video ID b4 that admin endpoint was found and it's vulunrable @commando_skiipz @KoredeSec @nacss_uniosun @elormkdaniel
1
3
22
676
Day10/#30DaysofAPIsecU Tested for BFLA(Broken Function Level Authorization ) Mr Test was able to delete Mrs Test's private video by changing the video ID b4 that admin endpoint was found and it's vulunrable @commando_skiipz @KoredeSec @nacss_uniosun @elormkdaniel
Day 9/#30daysofAPIsecU Tested and confirmed BOLA on the vehicle endpoint by using another vehicle UUID. Did not bother to change the token since it wan confirmed yesterday that it dosen't check for anything @commando_skiipz @KoredeSec @akintunero
2
4
27
607
Day 9/#30daysofAPIsecU Tested and confirmed BOLA on the vehicle endpoint by using another vehicle UUID. Did not bother to change the token since it wan confirmed yesterday that it dosen't check for anything @commando_skiipz @KoredeSec @akintunero
Day8/#30daysofAPIsec I ran jwt_tool against crAPI's dashboard endpoint and discovered the JWT implementation is critically broken itaccepts invalid signatures, unsigned tokens (alg:none),forged JWKS, and SQL injection in the kid claim. Almost every major JWT attack returned 200
3
3
20
798