Elektrine lite

← Feed

Dana Epp :donor: :verified:

danaepp@infosec.exchange

<p>Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.</p>

Posts

  • Post #1656429

    Let me show you how to weaponize API discovery metadata to improve your recon of the APIs you are hacking or conducting security testing on. #apihacking #apisecurity https://danaepp.com/weaponizing-api-discovery-metadata

  • Post #1656428

    Let me show you how to use Param Miner to find hidden parameters that may help manipulate an API in unintended ways, revealing potential security flaws. #apihacking #apisecurity https://danaepp.com/finding-hidden-api-parameters

  • Post #1656427

    Let me show you how to fuzz JSON to find security vulnerabilities in the APIs you are hacking with the help of a custom wordlist and Param Miner. #apihacking #apisecurity https://danaepp.com/fuzzing-json-to-find-api-security-flaws

  • Post #1656426

    Let me show you how to conduct covert data exfiltration within JSON payloads of an API response. #apihacking #apisecurity https://danaepp.com/covert-data-exfiltration-via-json-in-an-api

  • Post #1656425

    Let me show you how to map MITRE CAPEC attack patterns to STRIDE threat model categories and improve your approach to security testing. https://danaepp.com/mapping-attack-patterns-to-your-threat-model

  • Post #1656424

    Let&amp;#39;s look at Tracfone&amp;#39;s $16 million settlement with the FCC to understand why API security testing matters. #apisecurity #apihacking https://danaepp.com/why-api-security-testing-matters-learning-from-tracfone

  • Post #1656423

    Let me show you how to gain a competitive edge over other security researchers by detecting changes to APIs before others even know about them by using oasdiff. #apihacking #apisecurity https://danaepp.com/detecting-new-api-endpoints-with-oasdiff

  • Post #1656422

    Let me show you why the X-Bug-Bounty custom HTTP header can be helpful during your bug bounty engagements with a target. https://danaepp.com/why-the-x-bug-bounty-header-matters-for-hackers

  • Post #1656421

    Let me show you how to set up your hacking environment to attack mobile apps &amp;amp; APIs running on modern versions of Android with Burp Suite. https://danaepp.com/hacking-modern-android-apps-with-burpsuite

  • Post #1656420

    Let me show you how to use MITRE&amp;#39;s Common Weakness Enumerations (CWE) entries to level up your vulnerability reports. https://danaepp.com/level-up-your-vulnerability-reports-with-cwe

  • Post #1656419

    Learn how to improve your API discovery with a custom Burp Suite extension dedicated to automatically finding API document artifacts for you. https://danaepp.com/hacking-api-discovery-with-a-custom-burp-extension

  • Post #1656418

    Check out these five tips to help improve the API exploits you submit into security triage as part of your vulnerability research. https://danaepp.com/5-tips-to-improve-your-api-exploits

  • Post #1656417

    Let me show you how to use JSON injection to manipulate API payloads to control the flow of data and business logic within an API. #apihacking #apisecurity https://danaepp.com/attacking-apis-using-json-injection

  • Post #1656416

    Learn how to write exploits that take advantage of blind command injection vulnerabilities using a time-delayed boolean oracle attack. https://danaepp.com/from-exploit-to-extraction-data-exfil-in-blind-rce-attacks

  • Post #1656415

    Let me show you how to cross-reference Known Exploit Vulnerabilities (KEV) against CWE to find the best attack vectors to use during security testing. https://danaepp.com/kev-cwe-attack-vector

  • Post #1656414

    Check out how to use upstream residential and mobile proxies in Burp Suite to evade IP blocking during your API security testing. #apihacking #apisecurity https://danaepp.com/evade-ip-blocking-by-using-residential-proxies

  • Post #1656413

    Let&amp;#39;s explore the latest book by Packt Publishing on &amp;quot;Pentesting APIs&amp;quot; and see if it&amp;#39;s worth putting on an API hacker&amp;#39;s bookshelf. #apihacking #apisecurity https://danaepp.com/is-the-latest-book-on-pentesting-apis-any-good

  • Post #1656412

    Learn why shadow APIs sometimes provide a defenseless path for threat actors, and learn what YOU can do about it. https://danaepp.com/why-shadow-apis-provide-a-defenseless-path-for-threat-actors

  • Post #1656411

    Let me show you how to stay professionally detached from the vulnerabilities you discover and disclose as part of your security research. https://danaepp.com/staying-professionally-detached-from-your-security-research

  • Post #1656410

    Looks like I’m a finalist for “API Security Person of the Year”. Like my articles and research? I’d appreciate your vote. https://www.linkedin.com/posts/coreyjball_the-api-security-person-of-the-year-finalists-activity-7276021618643030016-5sqI?utm_source=share&amp;amp;utm_medium=member_ios