Commit Graph

197 Commits

Author SHA1 Message Date
André Rainho
a310ed13c4
new entry on Deliberately vulnerable APIs topic
- new entry Websheep
2021-12-05 00:13:33 +00:00
André Rainho
67f5ac53c1
move entry to tools topic
- move Firecracker entry
2021-12-04 23:51:40 +00:00
André Rainho
645e427858
new entry on Design / Architecture / Development
- entry for The API Specification Toolbox
2021-12-03 11:36:04 +00:00
André Rainho
66479cb957
Merge pull request #3 from yigblst/master
Update README.md
2021-12-03 11:25:19 +00:00
akpsgit
b18738c55b
Add APIClarity tool to the REST API section 2021-12-02 20:25:14 +02:00
yigblst
cb745cd4a0
Update README.md 2021-12-02 12:21:58 +02:00
André Rainho
794db20106
new entry for design / architecture / development
- add entry Understanding gRPC, OpenAPI and REST
2021-11-27 10:49:04 +00:00
André Rainho
97bb4b1455
new topic called specifications 2021-11-27 10:48:05 +00:00
André Rainho
7f5fbfba84
new topic firewalls
new entry for Wallarm Free API Firewall
2021-11-24 00:25:03 +00:00
André Rainho
7f27c659a0
new entry on topic Training / Walkthrough / Labs
- Hacker101 CTFs with GraphQL challenges
2021-11-18 10:01:14 +00:00
André Rainho
997cc1222f
new entry on tools topic
- fuzz-lightyear entry
2021-11-18 06:18:13 +00:00
André Rainho
d2a945d132
new entry for API Keys: Find & validate
- driftwood, a tool for private keys usage verification
2021-11-14 17:10:31 +00:00
André Rainho
69d507b655
new entry for other useful resources
Fixing the 13 most common GraphQL Vulnerabilities entry
2021-11-05 23:53:18 +00:00
André Rainho
db944e4897
new fuzzing/seclist entry
- wordlist api common methods
2021-11-04 22:04:31 +00:00
André Rainho
ab8d22ed8d
other useful resources entry
- new entry for Char49 - API security articles.
2021-10-29 10:02:32 +01:00
André Rainho
d7cbcef6f3
Update README.md 2021-10-26 22:05:04 +01:00
André Rainho
765cede2f8
new subtopics on tools
- graphql, rest, soap and others entries
2021-09-11 10:07:33 +01:00
André Rainho
1123156741
new entries on topic tools
- APIFuzzer, TnT-Fuzzer, GraphQLmap
2021-09-11 09:17:20 +01:00
André Rainho
02dd9ea933
new topic twitter
- adding apisecurity.io entry
2021-09-10 08:28:14 +01:00
André Rainho
a0c8b0172e
new entry or useful resources 2021-09-10 08:22:22 +01:00
André Rainho
2cbb0140ff
new items for fuzzing / seclists
Kiterunner and API routes wordlists from Assetnote
2021-09-10 08:14:14 +01:00
André Rainho
ce87a676a1
new entry for useful resources
- API Pentesting with Swagger Files
2021-08-18 00:22:58 +01:00
André Rainho
064fb2b207
new entry for tools topic
- Swagger-EZ tool
2021-08-18 00:18:41 +01:00
André Rainho
024fb4aa43
fix order 2021-08-04 11:48:36 +01:00
André Rainho
1c6f16e028
new entry for design, arch and dev topic 2021-08-04 10:47:17 +01:00
André Rainho
c595560dca
add author to newsletter entry 2021-08-04 10:44:24 +01:00
André Rainho
89d06e123e
cleanup 2021-08-04 10:42:03 +01:00
André Rainho
818df5e798
new entry for api design, arch and dev
- API Audit method
2021-08-04 10:28:49 +01:00
André Rainho
08424df754
new topic for api design, arch and dev 2021-08-04 10:24:36 +01:00
André Rainho
0b732a12ce
fix checklist entry 2021-08-04 10:09:26 +01:00
André Rainho
979601b9c7
rename topic and refactoring 2021-07-27 10:09:36 +01:00
André Rainho
4329be19d9
fix mindmap entry 2021-07-27 09:54:38 +01:00
André Rainho
98aa7c3abb
Update README.md 2021-07-27 09:53:22 +01:00
André Rainho
ba19b4e1be
new topic - Mind maps 2021-07-27 09:50:46 +01:00
André Rainho
be2c7a45e0
new checklist entry
OAuth2: Security checklist
2021-07-27 09:34:47 +01:00
André Rainho
775eb7e310
new topic API Keys validation 2021-07-27 09:20:58 +01:00
André Rainho
fe5d7dc5ca
new entry for other useful resources
- API Key Leaks: Tools and exploits
2021-07-16 10:25:42 +01:00
André Rainho
67e5131313
change author first letter to caps 2021-07-16 10:15:15 +01:00
André Rainho
1ea8efbeec
add author for checklist 2021-07-16 10:14:32 +01:00
André Rainho
8b360f223e
cleanup and new checklist entry
- refactor and cleanup
- new entry for API Audit checklist
2021-07-16 10:13:49 +01:00
André Rainho
f51798121e
other useful resources entry
- new entry "the fault in our stars"
2021-07-14 09:59:42 +01:00
André Rainho
66cc63af65
fix checklists 2021-07-14 09:55:59 +01:00
André Rainho
9f40e60959
new checklist entry
HolyTips: API security cheklist
2021-07-14 09:53:43 +01:00
André Rainho
0e970770b5
new walkthrough entry
- ShipFast: Practical API security walkthrough series
2021-07-09 00:58:41 +01:00
André Rainho
af75876286
new entry for Cheatsheets
- JSON Web Token Security Cheat Sheet
2021-07-08 20:45:41 +01:00
André Rainho
93eae9919e
new entry for other useful resources
- Strengthening Your API Security Posture – Ford Motor Company
2021-07-07 19:44:20 +01:00
André Rainho
828115de0f
rename entry 2021-07-07 19:12:00 +01:00
André Rainho
f95ae39117
new entry for Fuzzing/SecLists
- Word-list for common API endpoints
2021-07-07 19:11:08 +01:00
André Rainho
4c655b1313
new entry enumeration / scanning
- scan REST APIs with w3af
2021-07-07 19:04:31 +01:00
André Rainho
b0525ab676
new tool entry
- ffuf: a fast web fuzzer written in Go
2021-07-07 19:02:13 +01:00
André Rainho
c0dc89c3a3
new entry for Deliberately vulnerable APIs
- Generic-University Vulnerable API
2021-07-07 19:00:12 +01:00
André Rainho
ec9686433a
a new topic called playlists and minor cleanup
- removing single entry "API hacking for the Actually Pretty Inexperienced hacker."
- adding Katie Paxton-Fear Playlist called "Everything API Hacking."
2021-07-07 10:48:40 +01:00
André Rainho
be9d5523a8
new tool entry
- SoapUI testing solution for APIs and web services
2021-07-07 09:26:58 +01:00
André Rainho
3730883ef6
new tool entry
- REST API fuzzing tool called RESTler
2021-07-07 09:23:16 +01:00
André Rainho
832c73a463
new entries for podcasts
- Hack Your API-Security Testing
- The OWASP API Security Project
- Episode 38 API Security Best Practices
2021-07-07 09:20:41 +01:00
André Rainho
6faca4ba13
new tool entry
APICheck toolset entry
2021-07-07 09:04:17 +01:00
André Rainho
87f6efe83f
new entry for fuzzing/seclists
- list of swagger endpoints
2021-06-30 21:58:09 +01:00
André Rainho
9db1ce3906
fix table 2021-06-30 21:40:06 +01:00
André Rainho
4a3efaedd0
new entry for useful resources
- A guide from PortSwigger: What is API and microservice security?
2021-06-30 21:38:20 +01:00
André Rainho
49fa1945de
two entries for useful resources
- SOAP Security: Top Vulnerabilities and How to Prevent Them
- API Security: The Definitive Guide
2021-06-30 21:29:56 +01:00
André Rainho
c873e74e5d
new entry for cheat sheets
REST assessment cheat sheet entry
2021-06-30 21:13:47 +01:00
André Rainho
d47f1ac61d
new entry for cheatsheets
Microservices security cheatsheet entry
2021-06-30 21:07:09 +01:00
André Rainho
a8489cc387
new entries for enumeration or scanning
- general cleanup on table headers plus scanning/enumeration with zap/burp
2021-06-30 20:55:15 +01:00
André Rainho
b5ebcc4bb7
new podcast entry
Hacker Mind podcast entry called Hacking APIs
2021-06-30 20:44:46 +01:00
André Rainho
931196edeb
new gitbook entry
HackTricks - Web API Pentesting entry
2021-06-28 11:31:34 +01:00
André Rainho
b9bea1e6e0
new tool entry
new entry for Imperva's customizable API attack tool
2021-06-26 18:19:55 +01:00
André Rainho
ff9d4dfb16
rest security and graphql cheat sheets
REST security and GraphQL cheat sheets
2021-06-25 15:34:02 +01:00
André Rainho
30d7bad827
deliberately vulnerable api's and cleanup
- new topic for deliberately vulnerable API's
- rename other topics
2021-06-25 10:47:12 +01:00
André Rainho
465745ffd6
new entry for presentations/videos
API hacking for the Actually Pretty Inexperienced hacker
2021-06-22 11:06:55 +01:00
André Rainho
034f150538
rename item 2021-06-19 13:51:01 +01:00
André Rainho
09f1472310
seclists for api's and graphql
danielmiessler SecLists for web-content discovery of API's and GraphQL
2021-06-19 13:49:42 +01:00
André Rainho
a7944e8a9b
new entry called 'other resources'
including a list of API endpoints & objects at 'other resources'
2021-06-19 07:54:11 +01:00
André Rainho
c85059cd37
adding entry for astra
Automated security testing for REST API's
2021-06-19 07:51:23 +01:00
André Rainho
bca4bf6f74
add missing squares to menus 2021-05-14 09:14:20 +01:00
André Rainho
7100b2e413
fix project and newsletter menus 2021-05-14 09:13:04 +01:00
André Rainho
6463601290
pentesting lab and newsletter entries 2021-05-14 09:11:47 +01:00
André Rainho
b0eca97d1d
add owasp api security project and fix other info 2021-05-09 11:23:01 +01:00
André Rainho
e6215d437f
add GraphQL penetration testing entry 2021-05-04 12:28:07 +01:00
André Rainho
ed755da229
adding new entries kiterunner and MindAPI 2021-05-04 12:27:38 +01:00
André Rainho
112879401e
Update README.md 2021-03-07 00:24:47 +00:00
André Rainho
6c21608a27
Update README.md 2021-03-07 00:24:26 +00:00
André Rainho
e96a98f16d
kontra traning modules
Kontra - OWASP Top 10 for API
2021-03-07 00:23:02 +00:00
André Rainho
9cc8f1493c
31-days-of-API-Security-Tips 2020-09-20 01:20:46 +01:00
André Rainho
2032835eb8
disclosing information via apis 2020-08-19 22:14:21 +01:00
André Rainho
15e3a314b1
rest-in-peace abusing graphql 2020-08-17 15:26:40 +01:00
André Rainho
ccee3e1322
api security videos 2020-08-16 21:59:16 +01:00
André Rainho
f3f8fddbf8
fix link 2020-08-14 18:39:47 +01:00
André Rainho
8325fc63db
api-security-testing-how-to-hack 2020-08-14 18:39:01 +01:00
André Rainho
8e9886c0b0
API Penetration Testing
API Penetration Testing with OWASP 2017 Test Cases
2020-08-14 18:38:01 +01:00
André Rainho
fb74ca5736
fix link 2020-08-14 18:36:22 +01:00
André Rainho
35b7070021
remove comment 2020-08-14 18:35:55 +01:00
André Rainho
adbb3b3a1c
Securing your APIs
presentation
2020-08-14 18:33:51 +01:00
André Rainho
4b10324b74
Arjun 2020-08-14 18:32:38 +01:00
André Rainho
05c950250d
new topic called checklist 2020-08-14 18:28:53 +01:00
André Rainho
da76aba905
How to design a REST API 2020-08-14 18:27:46 +01:00
André Rainho
a9a5d70595
Awesome REST 2020-08-14 18:25:03 +01:00
André Rainho
373a99b514
create readme 2020-08-14 18:18:44 +01:00