Commit Graph

175 Commits

Author SHA1 Message Date
André Rainho
14ea4ed11e
fix menu 2022-02-25 16:30:45 +00:00
André Rainho
37aff9b5e4
update menu 2022-02-25 16:26:59 +00:00
André Rainho
3e1751ed93
rename topic name 2022-02-25 16:25:09 +00:00
André Rainho
32e9b0bbf7
new entry for fuzzing, seclists
- Hacking-APIs by @hapi_hacker
2022-02-13 21:42:14 +00:00
André Rainho
dfbf56b385
new entry on deliberately vulnerable api's
- new entry pixi
2022-02-13 20:09:58 +00:00
André Rainho
ea97ddbece
Update README.md 2022-02-09 21:10:50 +00:00
André Rainho
41227e1716
update discarded entries details 2022-02-09 21:04:37 +00:00
André Rainho
5cda6193f4
Update README.md 2022-02-09 21:02:39 +00:00
André Rainho
d244aa8a0a
updating contributions specifics 2022-02-09 20:47:55 +00:00
André Rainho
3d62b368de
new topic contributions 2022-02-02 21:23:03 +00:00
yigblst
1ce7612364
Update README.md
Rename of the project name from Firecracker to Cherrybomb + URL change + updated description.
2022-02-02 08:18:12 +02:00
André Rainho
80866187a2
new entry on Design, Architecture, Development
- new entry called "API security design best practices"
2022-01-07 21:22:17 +00:00
André Rainho
ba85b15d01
refactor menu 2021-12-31 00:41:57 +00:00
André Rainho
8cc162f950
alphabetical order for menu topics 2021-12-21 23:09:30 +00:00
André Rainho
8c0e6e0a30
menu refactor 2021-12-21 23:04:12 +00:00
André Rainho
6b6e53b814
add a menu in readme 2021-12-21 09:58:23 +00:00
André Rainho
46cf3ec19c
new entry on tools
- new graphql entry called clairvoyance
2021-12-16 22:13:04 +00:00
André Rainho
5f8345a034
new entry on tools
- new entry called graphql-playground
2021-12-16 22:09:27 +00:00
André Rainho
749a07f9e9
new entry on Other useful resources
- entry called Hacking APIs - Notes from Bug Bounty Bootcamp
2021-12-12 19:10:02 +00:00
André Rainho
ac66d78217
new entry on topic 'Deliberately vulnerable APIs'
- new entry called APISandbox
2021-12-12 01:33:45 +00:00
André Rainho
d7bee51fdf
new entry on tools
- new entry called APIKit
2021-12-12 01:32:46 +00:00
André Rainho
806cd16903
new entry on tools topic
- new entry with gotestwaf
2021-12-09 17:40:15 +00:00
André Rainho
36a9d02124
new topic called books
- adding book entries 'API Security in Action' and 'Hacking APIs'
2021-12-09 16:24:17 +00:00
André Rainho
25aca76f4d
new entry on topic 'Other useful resources'
- new entry How to Hack API in 60 minutes with Open Source Tools
2021-12-09 16:10:55 +00:00
André Rainho
c0be9b77b1
new gitbook entry
- new entry from six2dez about APIs Pentest Book
2021-12-09 16:07:25 +00:00
André Rainho
da6f85e898
new entry for other useful resources
- new entry for API Security Testing
2021-12-06 00:09:19 +00:00
André Rainho
c39626dedb
new entry on HTTP 101 topic
- new entry httpstatuses.com
2021-12-05 01:02:55 +00:00
André Rainho
cd45844ab3
new topic HTTP 101 2021-12-05 00:54:08 +00:00
André Rainho
a310ed13c4
new entry on Deliberately vulnerable APIs topic
- new entry Websheep
2021-12-05 00:13:33 +00:00
André Rainho
67f5ac53c1
move entry to tools topic
- move Firecracker entry
2021-12-04 23:51:40 +00:00
André Rainho
645e427858
new entry on Design / Architecture / Development
- entry for The API Specification Toolbox
2021-12-03 11:36:04 +00:00
André Rainho
66479cb957
Merge pull request #3 from yigblst/master
Update README.md
2021-12-03 11:25:19 +00:00
akpsgit
b18738c55b
Add APIClarity tool to the REST API section 2021-12-02 20:25:14 +02:00
yigblst
cb745cd4a0
Update README.md 2021-12-02 12:21:58 +02:00
André Rainho
794db20106
new entry for design / architecture / development
- add entry Understanding gRPC, OpenAPI and REST
2021-11-27 10:49:04 +00:00
André Rainho
97bb4b1455
new topic called specifications 2021-11-27 10:48:05 +00:00
André Rainho
7f5fbfba84
new topic firewalls
new entry for Wallarm Free API Firewall
2021-11-24 00:25:03 +00:00
André Rainho
7f27c659a0
new entry on topic Training / Walkthrough / Labs
- Hacker101 CTFs with GraphQL challenges
2021-11-18 10:01:14 +00:00
André Rainho
997cc1222f
new entry on tools topic
- fuzz-lightyear entry
2021-11-18 06:18:13 +00:00
André Rainho
d2a945d132
new entry for API Keys: Find & validate
- driftwood, a tool for private keys usage verification
2021-11-14 17:10:31 +00:00
André Rainho
69d507b655
new entry for other useful resources
Fixing the 13 most common GraphQL Vulnerabilities entry
2021-11-05 23:53:18 +00:00
André Rainho
db944e4897
new fuzzing/seclist entry
- wordlist api common methods
2021-11-04 22:04:31 +00:00
André Rainho
ab8d22ed8d
other useful resources entry
- new entry for Char49 - API security articles.
2021-10-29 10:02:32 +01:00
André Rainho
d7cbcef6f3
Update README.md 2021-10-26 22:05:04 +01:00
André Rainho
765cede2f8
new subtopics on tools
- graphql, rest, soap and others entries
2021-09-11 10:07:33 +01:00
André Rainho
1123156741
new entries on topic tools
- APIFuzzer, TnT-Fuzzer, GraphQLmap
2021-09-11 09:17:20 +01:00
André Rainho
02dd9ea933
new topic twitter
- adding apisecurity.io entry
2021-09-10 08:28:14 +01:00
André Rainho
a0c8b0172e
new entry or useful resources 2021-09-10 08:22:22 +01:00
André Rainho
2cbb0140ff
new items for fuzzing / seclists
Kiterunner and API routes wordlists from Assetnote
2021-09-10 08:14:14 +01:00
André Rainho
ce87a676a1
new entry for useful resources
- API Pentesting with Swagger Files
2021-08-18 00:22:58 +01:00
André Rainho
064fb2b207
new entry for tools topic
- Swagger-EZ tool
2021-08-18 00:18:41 +01:00
André Rainho
024fb4aa43
fix order 2021-08-04 11:48:36 +01:00
André Rainho
1c6f16e028
new entry for design, arch and dev topic 2021-08-04 10:47:17 +01:00
André Rainho
c595560dca
add author to newsletter entry 2021-08-04 10:44:24 +01:00
André Rainho
89d06e123e
cleanup 2021-08-04 10:42:03 +01:00
André Rainho
818df5e798
new entry for api design, arch and dev
- API Audit method
2021-08-04 10:28:49 +01:00
André Rainho
08424df754
new topic for api design, arch and dev 2021-08-04 10:24:36 +01:00
André Rainho
0b732a12ce
fix checklist entry 2021-08-04 10:09:26 +01:00
André Rainho
979601b9c7
rename topic and refactoring 2021-07-27 10:09:36 +01:00
André Rainho
4329be19d9
fix mindmap entry 2021-07-27 09:54:38 +01:00
André Rainho
98aa7c3abb
Update README.md 2021-07-27 09:53:22 +01:00
André Rainho
ba19b4e1be
new topic - Mind maps 2021-07-27 09:50:46 +01:00
André Rainho
be2c7a45e0
new checklist entry
OAuth2: Security checklist
2021-07-27 09:34:47 +01:00
André Rainho
775eb7e310
new topic API Keys validation 2021-07-27 09:20:58 +01:00
André Rainho
fe5d7dc5ca
new entry for other useful resources
- API Key Leaks: Tools and exploits
2021-07-16 10:25:42 +01:00
André Rainho
67e5131313
change author first letter to caps 2021-07-16 10:15:15 +01:00
André Rainho
1ea8efbeec
add author for checklist 2021-07-16 10:14:32 +01:00
André Rainho
8b360f223e
cleanup and new checklist entry
- refactor and cleanup
- new entry for API Audit checklist
2021-07-16 10:13:49 +01:00
André Rainho
f51798121e
other useful resources entry
- new entry "the fault in our stars"
2021-07-14 09:59:42 +01:00
André Rainho
66cc63af65
fix checklists 2021-07-14 09:55:59 +01:00
André Rainho
9f40e60959
new checklist entry
HolyTips: API security cheklist
2021-07-14 09:53:43 +01:00
André Rainho
0e970770b5
new walkthrough entry
- ShipFast: Practical API security walkthrough series
2021-07-09 00:58:41 +01:00
André Rainho
af75876286
new entry for Cheatsheets
- JSON Web Token Security Cheat Sheet
2021-07-08 20:45:41 +01:00
André Rainho
93eae9919e
new entry for other useful resources
- Strengthening Your API Security Posture – Ford Motor Company
2021-07-07 19:44:20 +01:00
André Rainho
828115de0f
rename entry 2021-07-07 19:12:00 +01:00
André Rainho
f95ae39117
new entry for Fuzzing/SecLists
- Word-list for common API endpoints
2021-07-07 19:11:08 +01:00
André Rainho
4c655b1313
new entry enumeration / scanning
- scan REST APIs with w3af
2021-07-07 19:04:31 +01:00
André Rainho
b0525ab676
new tool entry
- ffuf: a fast web fuzzer written in Go
2021-07-07 19:02:13 +01:00
André Rainho
c0dc89c3a3
new entry for Deliberately vulnerable APIs
- Generic-University Vulnerable API
2021-07-07 19:00:12 +01:00
André Rainho
ec9686433a
a new topic called playlists and minor cleanup
- removing single entry "API hacking for the Actually Pretty Inexperienced hacker."
- adding Katie Paxton-Fear Playlist called "Everything API Hacking."
2021-07-07 10:48:40 +01:00
André Rainho
be9d5523a8
new tool entry
- SoapUI testing solution for APIs and web services
2021-07-07 09:26:58 +01:00
André Rainho
3730883ef6
new tool entry
- REST API fuzzing tool called RESTler
2021-07-07 09:23:16 +01:00
André Rainho
832c73a463
new entries for podcasts
- Hack Your API-Security Testing
- The OWASP API Security Project
- Episode 38 API Security Best Practices
2021-07-07 09:20:41 +01:00
André Rainho
6faca4ba13
new tool entry
APICheck toolset entry
2021-07-07 09:04:17 +01:00
André Rainho
87f6efe83f
new entry for fuzzing/seclists
- list of swagger endpoints
2021-06-30 21:58:09 +01:00
André Rainho
9db1ce3906
fix table 2021-06-30 21:40:06 +01:00
André Rainho
4a3efaedd0
new entry for useful resources
- A guide from PortSwigger: What is API and microservice security?
2021-06-30 21:38:20 +01:00
André Rainho
49fa1945de
two entries for useful resources
- SOAP Security: Top Vulnerabilities and How to Prevent Them
- API Security: The Definitive Guide
2021-06-30 21:29:56 +01:00
André Rainho
c873e74e5d
new entry for cheat sheets
REST assessment cheat sheet entry
2021-06-30 21:13:47 +01:00
André Rainho
d47f1ac61d
new entry for cheatsheets
Microservices security cheatsheet entry
2021-06-30 21:07:09 +01:00
André Rainho
a8489cc387
new entries for enumeration or scanning
- general cleanup on table headers plus scanning/enumeration with zap/burp
2021-06-30 20:55:15 +01:00
André Rainho
b5ebcc4bb7
new podcast entry
Hacker Mind podcast entry called Hacking APIs
2021-06-30 20:44:46 +01:00
André Rainho
931196edeb
new gitbook entry
HackTricks - Web API Pentesting entry
2021-06-28 11:31:34 +01:00
André Rainho
b9bea1e6e0
new tool entry
new entry for Imperva's customizable API attack tool
2021-06-26 18:19:55 +01:00
André Rainho
ff9d4dfb16
rest security and graphql cheat sheets
REST security and GraphQL cheat sheets
2021-06-25 15:34:02 +01:00
André Rainho
30d7bad827
deliberately vulnerable api's and cleanup
- new topic for deliberately vulnerable API's
- rename other topics
2021-06-25 10:47:12 +01:00
André Rainho
465745ffd6
new entry for presentations/videos
API hacking for the Actually Pretty Inexperienced hacker
2021-06-22 11:06:55 +01:00
André Rainho
034f150538
rename item 2021-06-19 13:51:01 +01:00
André Rainho
09f1472310
seclists for api's and graphql
danielmiessler SecLists for web-content discovery of API's and GraphQL
2021-06-19 13:49:42 +01:00
André Rainho
a7944e8a9b
new entry called 'other resources'
including a list of API endpoints & objects at 'other resources'
2021-06-19 07:54:11 +01:00