Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Dana Epp :donor: :verified:

@danaepp@infosec.exchange
  • Open on infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

0 Followers
0 Following
21 Posts
Joined November 06, 2022
Website:
https://danaepp.com
Twitter:
https://twitter.com/danaepp
LinkedIn:
https://www.linkedin.com/in/danaepp/

Posts

Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Dec 21, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Looks like I’m a finalist for “API Security Person of the Year”. Like my articles and research? I’d appreciate your vote.

https://www.linkedin.com/posts/coreyjball_the-api-security-person-of-the-year-finalists-activity-7276021618643030016-5sqI?utm_source=share&utm_medium=member_ios

2
0
1
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Nov 26, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to stay professionally detached from the vulnerabilities you discover and disclose as part of your security research.

https://danaepp.com/staying-professionally-detached-from-your-security-research

0
0
0
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Nov 19, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Learn why shadow APIs sometimes provide a defenseless path for threat actors, and learn what YOU can do about it.

https://danaepp.com/why-shadow-apis-provide-a-defenseless-path-for-threat-actors

3
0
3
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Nov 12, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let's explore the latest book by Packt Publishing on "Pentesting APIs" and see if it's worth putting on an API hacker's bookshelf.

#apihacking #apisecurity

https://danaepp.com/is-the-latest-book-on-pentesting-apis-any-good

0
0
0
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Nov 05, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Check out how to use upstream residential and mobile proxies in Burp Suite to evade IP blocking during your API security testing.

#apihacking #apisecurity

https://danaepp.com/evade-ip-blocking-by-using-residential-proxies

1
0
1
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Oct 29, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to cross-reference Known Exploit Vulnerabilities (KEV) against CWE to find the best attack vectors to use during security testing.

https://danaepp.com/kev-cwe-attack-vector

1
0
0
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Oct 22, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Learn how to write exploits that take advantage of blind command injection vulnerabilities using a time-delayed boolean oracle attack.

https://danaepp.com/from-exploit-to-extraction-data-exfil-in-blind-rce-attacks

1
0
2
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Oct 15, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to use JSON injection to manipulate API payloads to control the flow of data and business logic within an API.

#apihacking #apisecurity

https://danaepp.com/attacking-apis-using-json-injection

2
0
2
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Oct 08, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Check out these five tips to help improve the API exploits you submit into security triage as part of your vulnerability research.

https://danaepp.com/5-tips-to-improve-your-api-exploits

1
0
0
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Oct 01, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Learn how to improve your API discovery with a custom Burp Suite extension dedicated to automatically finding API document artifacts for you.

https://danaepp.com/hacking-api-discovery-with-a-custom-burp-extension

2
0
1
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Sep 24, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to use MITRE's Common Weakness Enumerations (CWE) entries to level up your vulnerability reports.

https://danaepp.com/level-up-your-vulnerability-reports-with-cwe

0
0
0
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Sep 17, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to set up your hacking environment to attack mobile apps & APIs running on modern versions of Android with Burp Suite.

https://danaepp.com/hacking-modern-android-apps-with-burpsuite

1
0
1
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Sep 10, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you why the X-Bug-Bounty custom HTTP header can be helpful during your bug bounty engagements with a target.

https://danaepp.com/why-the-x-bug-bounty-header-matters-for-hackers

2
0
1
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Sep 03, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to gain a competitive edge over other security researchers by detecting changes to APIs before others even know about them by using oasdiff.

#apihacking #apisecurity

https://danaepp.com/detecting-new-api-endpoints-with-oasdiff

0
0
0
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Aug 06, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let's look at Tracfone's $16 million settlement with the FCC to understand why API security testing matters.

#apisecurity #apihacking

https://danaepp.com/why-api-security-testing-matters-learning-from-tracfone

0
0
0
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Jul 30, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to map MITRE CAPEC attack patterns to STRIDE threat model categories and improve your approach to security testing.

https://danaepp.com/mapping-attack-patterns-to-your-threat-model

0
0
0
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Jul 23, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to conduct covert data exfiltration within JSON payloads of an API response.

#apihacking #apisecurity

https://danaepp.com/covert-data-exfiltration-via-json-in-an-api

0
0
1
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Jul 16, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to fuzz JSON to find security vulnerabilities in the APIs you are hacking with the help of a custom wordlist and Param Miner.

#apihacking #apisecurity

https://danaepp.com/fuzzing-json-to-find-api-security-flaws

1
0
2
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Jul 09, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to use Param Miner to find hidden parameters that may help manipulate an API in unintended ways, revealing potential security flaws.

#apihacking #apisecurity

https://danaepp.com/finding-hidden-api-parameters

1
0
1
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Jul 02, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange

Let me show you how to weaponize API discovery metadata to improve your recon of the APIs you are hacking or conducting security testing on.

#apihacking #apisecurity

https://danaepp.com/weaponizing-api-discovery-metadata

3
0
1
0
Open post
danaepp
Dana Epp :donor: :verified: @danaepp@infosec.exchange · Mar 21, 2024
Dana Epp :donor: :verified:
@danaepp@infosec.exchange

Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.

infosec.exchange
Replying to @shellsharks@infosec.exchange
@shellsharks @selenalarson @JohnsNotHere @4Dgifts @tweedge @wdormann @reverseics @LukaszOlejnik @raesene @cryptax @catc0n @acrypthash @0ddj0bb @timb_machine @mayahustle @tiraniddo @hdm @obivan @hackNpatch @thc @malmoeb @danaepp @vinoth @verovaleros @alexandreborges @lukasberancz @albinowax @nhamiel @alex @taylorparizo @sanjaymenon @teriradichel @shortridge @yossarian @livinginsyn @EricHogue @neurovagrant @LeeArchinal @harrysintonen @0xor0ne @r1cksec @cyb_detective @abrignoni @Cyberkid1987 @buherator @mttaggart @bruienne @florenciocano @karmaz @ahoog42 Thanks for including me in such a great list. I’m grateful and honored to be mentioned along side some of these great security researchers. Hack hard! 🎉
8
0
0
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:11:37 UTC