• Regeln für den Video-Bereich:

    In den Börsenbereich gehören nur Angebote die bereits den Allgemeinen Regeln entsprechen.

    Einteilung

    - Folgende Formate gehören in die angegeben Bereiche:
    - Filme: Encodierte Filme von BluRay, DVD, R5, TV, Screener sowie Telesyncs im Format DivX, XviD und x264.
    - DVD: Filme im Format DVD5, DVD9 und HD2DVD.
    - HD: Encodierte Filme mit der Auflösung 720p oder darüber von BluRay, DVD, R5, TV, Screener sowie Telesyncs im Format x264.
    - 3D: Encodierte Filme von BluRay, die in einem 3D Format vorliegen. Dies gilt auch für Dokus, Animation usw.
    - Serien: Cartoon/Zeichentrick, Anime, Tutorials, Dokumentationen, Konzerte/Musik, Sonstiges sind demnach in die entsprechenden Bereiche einzuordnen, auch wenn sie beispielsweise im High Definition-Format oder als DVD5/DVD9/HD2DVD vorliegen. Ausnahme 3D.
    - Bereich Englisch: Englische Releases gehören immer in diesen Bereich.
    - Bereich Talk: Der Bereich, in dem über die Releases diskutiert werden kann, darf, soll und erwünscht ist.


    Angebot/Beitrag erstellen

    - Ein Beitrag darf erst dann erstellt werden, wenn der Upload bei mindestens einem OCH komplett ist. Platzhalter sind untersagt.
    - Bei einem Scenerelease hat der Threadtitel ausschließlich aus dem originalen, unveränderten Releasenamen zu bestehen. Es dürfen keine Veränderungen wie z.B. Sterne, kleine Buchstaben o.ä. vorgenommen werden. Ausnahme Serienbörse:
    - Bei einem Sammelthread für eine Staffel entfällt aus dem Releasename natürlich der Name der Folge. Beispiel: Die Simpsons S21 German DVDRip XviD - ITG
    - Dementsprechend sind also u.a. verboten: Erweiterungen wie "Tipp", "empfehlenswert", "only", "reup", usw. / jegliche andere Zusatzinformation oder Ergänzung, welche nicht in obiger Beschreibung zu finden ist.

    Aufbau des Angebots und Threadtitel

    Der Titel nach folgendem Muster erstellt zu werden. <Name> [3D] [Staffel] [German] <Jahr> <Tonspur> [DL] [Auflösung] <Quelle> <Codec> - <Group>
    Beispiel: The Dark Knight German 2008 AC3 DVDRip XviD - iND
    Beispiel: The Dark Knight 2008 DTS DL BDRip x264 - iND
    Beispiel: The Dark Knight 2008 AC3 DL BDRip XviD - iND
    Beispiel: The Dark Knight German 2008 AC3 720p BluRay x264 iND
    Beispiel: The Dark Knight 2008 DTS DL 1080p BluRay x264 iND
    Beispiel: Die Simpsons S01 German AC3 DVDRip XviD iND
    Beispiel: Die Simpsons S20 German AC3 720p BluRay x264 iND
    Beispiel: Sword Art Online II Ger Sub 2014 AAC 1080p WEBRip x264 - peppermint
    Entsprechend sind also u.a. verboten: Sonderzeichen wie Klammern, Sterne, Ausrufezeichen, Unterstriche, Anführungszeichen / Erweiterungen wie "Tipp", "empfehlenswert", "only", "reup", usw. / jegliche andere Zusatzinformation oder Ergänzung, welche nicht in obiger Beschreibung zu finden ist
    Ausnahmen hiervon können in den Bereichen geregelt sein.

    Die Beiträge sollen wie folgt aufgebaut werden:
    Überschrift entspricht dem Threadtitel
    Cover
    kurze Inhaltsbeschreibung
    Format, Größe, Dauer sind gut lesbar für Downloader außerhalb des Spoilers zu vermerken
    Nfo sind immer Anzugeben und selbige immer im Spoiler in Textform.
    Sind keine Nfo vorhanden z.B. Eigenpublikationen, sind im Spoiler folgende Dateiinformationen zusätzlich anzugeben :
    Quelle
    Video (Auflösung und Bitrate)
    Ton (Sprache, Format und Bitrate der einzelnen Spuren)
    Untertitel (sofern vorhanden)
    Hosterangabe in Textform außerhalb eines Spoiler mit allen enthaltenen Hostern.
    Bei SD kann auf diese zusätzlichen Dateiinformationen verzichtet werden.

    Alle benötigten Passwörter sind, sofern vorhanden, in Textform im Angebot anzugeben.
    Spoiler im Spoiler mit Kommentaren :"Schon Bedankt?" sind unerwünscht.


    Releases

    - Sind Retail-Release verfügbar, sind alle anderen Variationen untersagt. Ausnahmen: Alle deutschen Retail-Release sind CUT, in diesem Fall sind dubbed UNCUT-Release zulässig.
    - Im Serien-Bereich gilt speziell: Wenn ein Retail vor Abschluss einer laufenden Staffel erscheint, darf diese Staffel noch zu Ende gebracht werden.62
    - Gleiche Releases sind unbedingt zusammenzufassen. Das bedeutet, es ist zwingend erforderlich, vor dem Erstellen eines Themas per Suchfunktion zu überprüfen, ob bereits ein Beitrag mit demselben Release besteht. Ist dies der Fall, ist der bereits vorhandene Beitrag zu verwenden.
    - P2P und Scene Releases dürfen nicht verändert oder gar unter einem iND Tag eingestellt werden.


    Support, Diskussionen und Suche

    - Supportanfragen sind entweder per PN oder im Bereich Talk zu stellen.
    - Diskussionen und Bewertungen sind im Talk Bereich zu führen. Fragen an die Uploader haben ausschließlich via PN zu erfolgen, und sind in den Angeboten untersagt.
    - Anfragen zu Upload-Wünschen sind nur im Bereich Suche Video erlaubt. Antworten dürfen nur auf Angebote von MyBoerse.bz verlinkt werden.


    Verbote

    - Untersagt sind mehrere Formate in einem einzigen Angebotsthread, wie beispielsweise das gleichzeitige Anbieten von DivX/XviD, 720p und 1080p in einem Thread. Pro Format, Release und Auflösung ist ein eigener Thread zu eröffnen.
    - Grundsätzlich ebenso verboten sind Dupes. Uploader haben sich an geeigneter Stelle darüber zu informieren, ob es sich bei einem Release um ein Dupe handelt.
    - Gefakte, nur teilweise lauffähige oder unvollständige Angebote sind untersagt. Dies gilt auch für eigene Publikationen, die augenscheinlich nicht selbst von z.B. einer DVD gerippt wurden. Laufende Serien, bei denen noch nicht alle Folgen verfügbar sind, dürfen erstellt und regelmäßig geupdatet werden.
    - Untersagt sind Angebote, welche nur und ausschließlich in einer anderen Sprache als deutsch oder englisch vorliegen. Ausnahmen sind VORHER mit den Moderatoren zu klären.


    Verstoß gegen die Regeln

    - Angebote oder Beiträge, die gegen die Forenregeln verstoßen, sind über den "Melden"-Button im Beitrag zu melden.
  • Bitte registriere dich zunächst um Beiträge zu verfassen und externe Links aufzurufen.

*** Bestes IPTV *** bester Preis *** gratis Test ***



Ethical Hacking of RESTful and GraphQL APIs Training Course

Tutorials

MyBoerse.bz Pro Member
80fab4178f409fba5d4f20b1a107698e.jpeg

Free Download Ethical Hacking of RESTful and GraphQL APIs Training Course
Published 3/2024
Created by Martin Voelk
MP4 | Video: h264, 1280x720 | Audio: AAC, 44.1 KHz, 2 Ch
Genre: eLearning | Language: English | Duration: 58 Lectures ( 5h 34m ) | Size: 2.93 GB

Become a Successful REST API and GraphQL API Penetration Tester and Bug Bounty Hunter!
What you'll learn:
RESTful API vulnerabilities
GraphQL API vulnerabilities
Basic web application vulnerabilities
Basic mobile application vulnerabilities
Getting started in web application bug bounty
Getting started in mobile application bug bounty
REST API Introduction
REST API Discovery and Recon
REST API Enumeration
REST API Broken Object Level Authorization (BOLA)
REST API Broken Authentication
REST API Broken Object Property Level Authorization
REST API Excessive Data Exposure
REST API Mass Assignment
REST API Unrestricted Resource Consumption
REST API Broken Function Level Authorization (BLFA)
REST API Unrestricted Access to Sensitive Business Flows
REST API Server Side Request Forgery (SSRF)
REST API Security Misconfiguration
REST API Improper Inventory Management
REST API Unsafe Consumption of APIs
REST API Server-side parameter pollution
GraphQL Introduction
What is GraphQL
GraphQL Key terminologies
GraphQL Burp extensions
GraphQL Wordlists
GraphQL Payloads
GraphQL Tools
GraphQL API Attack Surface, Recon, Enumeration
GraphQL Attack Surface Analysis
GraphQL GET requests and the issues
GraphQL POST requests
GraphQL Information Disclosure
GraphQL Introspection
GraphQL GET vs. POST Introspection
GraphQL Introspection filter bypass example
GraphQL Non-prod GraphQL endpoints
GraphQL Field Suggestion
GraphQL Automating Field Suggestion
GraphQL Field Stuffing
GraphQL Abusing Error Messages
GraphQL IDE
GraphQL DoS
GraphQL Deep Recursion Query Attack
GraphQL Circular Fragment Vulnerabilities
GraphQL Batch Query Attacks / Resource Intensive Query Attacks
GraphQL Field Duplication Attacks
GraphQL Alias based attacks (DoS scenario)
GraphQL Directive Overloading
GraphQL Object Limit Overriding
GraphQL Array-Based Query Batching
GraphQL Authentication and Authorization attacks
GraphQL Login functions
GraphQL Bypassing protections
GraphQL Alias based attacks / query batching
GraphQL JWT token forgery
GraphQL Cookie forgery
GraphQL Access control issues and IDORs
GraphQL Injection attacks
GraphQL OS Command Injection
GraphQL SQL Injection
GraphQL HTML Injection
GraphQL XSS (Cross-site scripting)
GraphQL Request Forgery and Hijacking
GraphQL Server-side request forgery (SSRF)
GraphQL Cross-site request forgery (CSRF)
GraphQL GET based CSRF
GraphQL POST based CSRF
GraphQL Cross-Site WebSocket Hijacking (CSWH)
Requirements:
Basic IT Skills
Basic understanding of web or mobile app technology
No Linux, programming or hacking knowledge required
Computer with a minimum of 4GB ram/memory
Operating System: Windows / Apple Mac OS / Linux
Reliable internet connection
Burp Suite Community (Pro optional)
Firefox Web Browser
Either VMware, Virtual Box, Raspberry PI or similar to run virtual servers
Description:
Welcome to the Ethical Hacking of RESTful and GraphQL APIs Training CourseImportant note: This course is NOT teaching the actual usage of Burp Suite and its features. This course is a heavily hands-on introduction to both RESTful as well as GraphQL API vulnerabilities. These APIs are very common in modern web and mobile applications. Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.This course features theoretical introductions into API vulnerabilities followed by practical exploitations of common RESTful API and GraphQL API vulnerabilities. Some labs are being performed utilizing the Portswigger Web Academy Labs. Other labs are performed on standalone VMs such as crAPI and DVGA. As people use different platforms, The training will not show the set up of crAPI or DVGA. But you can install these easily on a free virtualization software like virtual box on Windows or MacOSX. Martin will be solving a lot of labs and explains each step on finding the vulnerability and why it can be exploited in a certain way. The videos are easy to follow along and replicate. This training is highly recommended for anyone who wants to start out in API Penetration Testing or API Bug Bounty Hunting.The course features the following topics.REST API IntroductionREST API Discovery and Recon REST API Enumeration REST API Broken Object Level Authorization (BOLA)REST API Broken AuthenticationREST API Broken Object Property Level AuthorizationREST API Excessive Data Exposure REST API Mass AssignmentREST API Unrestricted Resource ConsumptionREST API Broken Function Level Authorization (BLFA)REST API Unrestricted Access to Sensitive Business FlowsREST API Server Side Request Forgery (SSRF)REST API Security Misconfiguration REST API Improper Inventory Management REST API Unsafe Consumption of APIsREST API Server-side parameter pollutionGraphQL IntroductionGraphQL What is it?GraphQL Key terminologiesGraphQL Burp extensionsGraphQL WordlistsGraphQL PayloadsGraphQL ToolsGraphQL API Attack Surface, Recon, EnumerationGraphQL Attack Surface AnalysisGraphQL GET requests and the issuesGraphQL POST requestsGraphQL Information DisclosureGraphQL Introspection GraphQL GET vs. POST Introspection GraphQL Introspection filter bypass exampleGraphQL Non-prod GraphQL endpointsGraphQL Field SuggestionGraphQL Automating Field SuggestionGraphQL Field StuffingGraphQL Abusing Error MessagesGraphQL IDEGraphQL DoSGraphQL Deep Recursion Query AttackGraphQL Circular Fragment VulnerabilitiesGraphQL Batch Query Attacks / Resource Intensive Query AttacksGraphQL Field Duplication AttacksGraphQL Alias based attacks (DoS scenario)GraphQL Directive OverloadingGraphQL Object Limit OverridingGraphQL Array-Based Query BatchingGraphQL Authentication and Authorization attacksGraphQL Login functionsGraphQL Bypassing protections GraphQL Alias based attacks / query batching GraphQL JWT token forgery GraphQL Cookie forgery GraphQL Access control issues and IDORs GraphQL Injection attacksGraphQL OS Command InjectionGraphQL SQL Injection GraphQL HTML Injection GraphQL XSS (Cross-site scripting)GraphQL Request Forgery and HijackingGraphQL Server-side request forgery (SSRF)GraphQL Cross-site request forgery (CSRF)GraphQL GET based CSRFGraphQL POST based CSRFGraphQL Cross-Site WebSocket Hijacking (CSWH)Notes & DisclaimerPortswigger labs are a public and a free service from Portswigger for anyone to use to sharpen their skills. All you need is to sign up for a free account. crAPI and DVGA are free as well and can be cloned from GitHub. I will to respond to questions in a reasonable time frame. Learning Web / Mobile Application Pen Testing / Bug Bounty Hunting is a lengthy process, so please don't feel frustrated if you don't find a bug right away. Try to use Google, read Hacker One reports and research each feature in-depth. This course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.
Who this course is for:
Anybody interested in learning basic ethical web application hacking / penetration testing
Anybody interested in learning basic API hacking / penetration testing
Anybody interested in learning basic ethical web application bug bounty hunting
Anybody interested in learning basic ethical API bug bounty hunting
Anybody interested in learning how hackers hack web applications
Anybody interested in learning how hackers hack mobile applications
Anybody interested in learning how hackers hack APIs
Developers looking to expand on their knowledge of vulnerabilities that may impact them
Anyone interested in application security
Anyone interested in Red teaming
Anyone interested in offensive security
Homepage











Recommend Download Link Hight Speed | Please Say Thanks Keep Topic Live
No Password - Links are Interchangeable
 

dc504048de5d3bc21188330e293a20d1.jpg

Ethical Hacking Of Restful And Graphql Apis Training Course
Published 3/2024
MP4 | Video: h264, 1920x1080 | Audio: AAC, 44.1 KHz
Language: English | Size: 3.49 GB | Duration: 5h 33m​

Become a Successful REST API and GraphQL API Penetration Tester and Bug Bounty Hunter!

What you'll learn

RESTful API vulnerabilities

GraphQL API vulnerabilities

Basic web application vulnerabilities

Basic mobile application vulnerabilities

Getting started in web application bug bounty

Getting started in mobile application bug bounty

REST API Introduction

REST API Discovery and Recon

REST API Enumeration

REST API Broken Object Level Authorization (BOLA)

REST API Broken Authentication

REST API Broken Object Property Level Authorization

REST API Excessive Data Exposure

REST API Mass Assignment

REST API Unrestricted Resource Consumption

REST API Broken Function Level Authorization (BLFA)

REST API Unrestricted Access to Sensitive Business Flows

REST API Server Side Request Forgery (SSRF)

REST API Security Misconfiguration

REST API Improper Inventory Management

REST API Unsafe Consumption of APIs

REST API Server-side parameter pollution

GraphQL Introduction

What is GraphQL

GraphQL Key terminologies

GraphQL Burp extensions

GraphQL Wordlists

GraphQL Payloads

GraphQL Tools

GraphQL API Attack Surface, Recon, Enumeration

GraphQL Attack Surface Analysis

GraphQL GET requests and the issues

GraphQL POST requests

GraphQL Information Disclosure

GraphQL Introspection

GraphQL GET vs. POST Introspection

GraphQL Introspection filter bypass example

GraphQL Non-prod GraphQL endpoints

GraphQL Field Suggestion

GraphQL Automating Field Suggestion

GraphQL Field Stuffing

GraphQL Abusing Error Messages

GraphQL IDE

GraphQL DoS

GraphQL Deep Recursion Query Attack

GraphQL Circular Fragment Vulnerabilities

GraphQL Batch Query Attacks / Resource Intensive Query Attacks

GraphQL Field Duplication Attacks

GraphQL Alias based attacks (DoS scenario)

GraphQL Directive Overloading

GraphQL Object Limit Overriding

GraphQL Array-Based Query Batching

GraphQL Authentication and Authorization attacks

GraphQL Login functions

GraphQL Bypassing protections

GraphQL Alias based attacks / query batching

GraphQL JWT token forgery

GraphQL Cookie forgery

GraphQL Access control issues and IDORs

GraphQL Injection attacks

GraphQL OS Command Injection

GraphQL SQL Injection

GraphQL HTML Injection

GraphQL XSS (Cross-site scripting)

GraphQL Request Forgery and Hijacking

GraphQL Server-side request forgery (SSRF)

GraphQL Cross-site request forgery (CSRF)

GraphQL GET based CSRF

GraphQL POST based CSRF

GraphQL Cross-Site WebSocket Hijacking (CSWH)

Requirements

Basic IT Skills

Basic understanding of web or mobile app technology

No Linux, programming or hacking knowledge required

Computer with a minimum of 4GB ram/memory

Operating System: Windows / Apple Mac OS / Linux

Reliable internet connection

Burp Suite Community (Pro optional)

Firefox Web Browser

Either VMware, Virtual Box, Raspberry PI or similar to run virtual servers

Description

Welcome to the Ethical Hacking of RESTful and GraphQL APIs Training CourseImportant note: This course is NOT teaching the actual usage of Burp Suite and its features. This course is a heavily hands-on introduction to both RESTful as well as GraphQL API vulnerabilities. These APIs are very common in modern web and mobile applications. Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.This course features theoretical introductions into API vulnerabilities followed by practical exploitations of common RESTful API and GraphQL API vulnerabilities. Some labs are being performed utilizing the Portswigger Web Academy Labs. Other labs are performed on standalone VMs such as crAPI and DVGA. As people use different platforms, The training will not show the set up of crAPI or DVGA. But you can install these easily on a free virtualization software like virtual box on Windows or MacOSX. Martin will be solving a lot of labs and explains each step on finding the vulnerability and why it can be exploited in a certain way. The videos are easy to follow along and replicate. This training is highly recommended for anyone who wants to start out in API Penetration Testing or API Bug Bounty Hunting.The course features the following topics.REST API IntroductionREST API Discovery and Recon REST API Enumeration REST API Broken Object Level Authorization (BOLA)REST API Broken AuthenticationREST API Broken Object Property Level AuthorizationREST API Excessive Data Exposure REST API Mass AssignmentREST API Unrestricted Resource ConsumptionREST API Broken Function Level Authorization (BLFA)REST API Unrestricted Access to Sensitive Business FlowsREST API Server Side Request Forgery (SSRF)REST API Security Misconfiguration REST API Improper Inventory Management REST API Unsafe Consumption of APIsREST API Server-side parameter pollutionGraphQL IntroductionGraphQL What is it?GraphQL Key terminologiesGraphQL Burp extensionsGraphQL WordlistsGraphQL PayloadsGraphQL ToolsGraphQL API Attack Surface, Recon, EnumerationGraphQL Attack Surface AnalysisGraphQL GET requests and the issuesGraphQL POST requestsGraphQL Information DisclosureGraphQL Introspection GraphQL GET vs. POST Introspection GraphQL Introspection filter bypass exampleGraphQL Non-prod GraphQL endpointsGraphQL Field SuggestionGraphQL Automating Field SuggestionGraphQL Field StuffingGraphQL Abusing Error MessagesGraphQL IDEGraphQL DoSGraphQL Deep Recursion Query AttackGraphQL Circular Fragment VulnerabilitiesGraphQL Batch Query Attacks / Resource Intensive Query AttacksGraphQL Field Duplication AttacksGraphQL Alias based attacks (DoS scenario)GraphQL Directive OverloadingGraphQL Object Limit OverridingGraphQL Array-Based Query BatchingGraphQL Authentication and Authorization attacksGraphQL Login functionsGraphQL Bypassing protections GraphQL Alias based attacks / query batching GraphQL JWT token forgery GraphQL Cookie forgery GraphQL Access control issues and IDORs GraphQL Injection attacksGraphQL OS Command InjectionGraphQL SQL Injection GraphQL HTML Injection GraphQL XSS (Cross-site scripting)GraphQL Request Forgery and HijackingGraphQL Server-side request forgery (SSRF)GraphQL Cross-site request forgery (CSRF)GraphQL GET based CSRFGraphQL POST based CSRFGraphQL Cross-Site WebSocket Hijacking (CSWH)Notes & DisclaimerPortswigger labs are a public and a free service from Portswigger for anyone to use to sharpen their skills. All you need is to sign up for a free account. crAPI and DVGA are free as well and can be cloned from GitHub. I will to respond to questions in a reasonable time frame. Learning Web / Mobile Application Pen Testing / Bug Bounty Hunting is a lengthy process, so please don't feel frustrated if you don't find a bug right away. Try to use Google, read Hacker One reports and research each feature in-depth. This course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.

Overview

Section 1: ETHICAL HACKING OF REST & GRAPHQL APIs

Lecture 1 REST & GRAPHQL API AGENDA

Lecture 2 Setting up Burp

Section 2: RESTful API Introduction

Lecture 3 RESTful API Introduction

Section 3: RESTful API Discovery and Recon

Lecture 4 RESTful API Discovery and Recon

Lecture 5 Enumeration Lab

Section 4: RESTful API Broken Object Level Authorization (BOLA)

Lecture 6 RESTful API Broken Object Level Authorization (BOLA)

Lecture 7 RESTful API Broken Object Level Authorization (BOLA) - lab 1

Lecture 8 RESTful API Broken Object Level Authorization (BOLA) - lab 2

Section 5: RESTful API Broken Authentication

Lecture 9 RESTful API Broken Authentication

Lecture 10 RESTful API Broken Authentication - lab 1

Section 6: RESTful API Broken Object Property Level Authorization (Excessive Data Exposure)

Lecture 11 RESTful API Broken Object Property Level Authorization (Excessive Data Exposure)

Lecture 12 RESTful API Broken Object Property Level Authorization (Excessive Data Exposure)

Lecture 13 RESTful API Broken Object Property Level Authorization (Excessive Data Exposure)

Section 7: RESTful API Unrestricted Resource Consumption

Lecture 14 RESTful API Unrestricted Resource Consumption

Lecture 15 RESTful API Unrestricted Resource Consumption - lab 1

Section 8: RESTful API Broken Function Level Authorization (BFLA)

Lecture 16 RESTful API Broken Function Level Authorization (BFLA)

Lecture 17 RESTful API Broken Function Level Authorization (BFLA) - lab 1

Lecture 18 RESTful API Broken Function Level Authorization (BFLA) - lab 2

Lecture 19 RESTful API Broken Function Level Authorization (BFLA) - lab 3

Section 9: RESTful API Unrestricted Access to Sensitive Business Flows

Lecture 20 RESTful API Unrestricted Access to Sensitive Business Flows

Lecture 21 RESTful API Unrestricted Access to Sensitive Business Flows - labs 1 and 2

Lecture 22 RESTful API Unrestricted Access to Sensitive Business Flows - labs 3

Section 10: RESTful API Server Side Request Forgery

Lecture 23 RESTful API Server Side Request Forgery

Lecture 24 RESTful API Server Side Request Forgery - lab 1

Section 11: RESTful API Security Misconfiguration

Lecture 25 RESTful API Security Misconfiguration

Section 12: RESTful API Improper Inventory Management

Lecture 26 RESTful API Improper Inventory Management

Section 13: RESTful API Unsafe Consumption of APIs

Lecture 27 RESTful API Unsafe Consumption of APIs

Lecture 28 RESTful API Unsafe Consumption of APIs - lab 1

Section 14: RESTful API server-side parameter pollution

Lecture 29 RESTful API server-side parameter pollution

Lecture 30 Server-side parameter pollution - lab 1

Section 15: GraphQL API Introduction

Lecture 31 GraphQL API Introduction

Section 16: GraphQL API Attack Surface Analysis, Recon, Enumeration

Lecture 32 GraphQL API Attack Surface Analysis, Recon, Enumeration

Lecture 33 GraphQL API Attack Surface Analysis, Recon, Enumeration - lab 1

Section 17: GraphQL API Information Disclosure

Lecture 34 GraphQL API Information Disclosure

Lecture 35 GraphQL API Information Disclosure - lab 1 introspection

Lecture 36 GraphQL API Information Disclosure - lab 2 graphql ide

Lecture 37 GraphQL API Information Disclosure - lab 3 field suggestion

Lecture 38 GraphQL API Information Disclosure - lab 4 stack traces

Lecture 39 GraphQL API Information Disclosure - lab 5 - Accessing private GraphQL posts

Lecture 40 GraphQL API Information Disclosure - lab 6 - Burp Accidental exposure of private

Lecture 41 GraphQL API Information Disclosure - lab 7 - Finding a hidden GraphQL endpoint

Section 18: GraphQL API Denial of Service (DoS)

Lecture 42 GraphQL API Denial of Service (DoS)

Lecture 43 GraphQL API Denial of Service (DoS) - lab 1 and 2 resource intensive batch query

Lecture 44 GraphQL API Denial of Service (DoS) - lab 3 deep recursion query

Lecture 45 GraphQL API Denial of Service (DoS) - lab 4 field duplication

Lecture 46 GraphQL API Denial of Service (DoS) - lab 5 alias based DoS

Lecture 47 GraphQL API Denial of Service (DoS) - lab 6 circular fragment attack

Section 19: GraphQL API Authentication and Authorization bypasses

Lecture 48 GraphQL API Authentication and Authorization bypasses

Lecture 49 GraphQL API Authentication and Authorization bypasses - lab 1 cookie forge

Lecture 50 GraphQL API Authentication and Authorization bypasses - lab2 header bypass

Lecture 51 GraphQL API Authentication and Authorization bypasses - lab 3 Bypassing GraphQL

Section 20: GraphQL API Injection attacks

Lecture 52 GraphQL API Injection attacks

Lecture 53 GraphQL API Injection attacks - lab 1 os command injection

Lecture 54 GraphQL API Injection attacks - lab 2 sql injection

Lecture 55 GraphQL API Injection attacks - lab 3 and 4 XSS and HTML injection

Section 21: GraphQL API Request Forgery and Hijacking

Lecture 56 GraphQL API Request Forgery and Hijacking

Lecture 57 GraphQL API Request Forgery and Hijacking - lab 1 SSRF

Lecture 58 GraphQL API Request Forgery and Hijacking - lab 2 Performing CSRF exploits over

Anybody interested in learning basic ethical web application hacking / penetration testing,Anybody interested in learning basic API hacking / penetration testing,Anybody interested in learning basic ethical web application bug bounty hunting,Anybody interested in learning basic ethical API bug bounty hunting,Anybody interested in learning how hackers hack web applications,Anybody interested in learning how hackers hack mobile applications,Anybody interested in learning how hackers hack APIs,Developers looking to expand on their knowledge of vulnerabilities that may impact them,Anyone interested in application security,Anyone interested in Red teaming,Anyone interested in offensive security

oBRNByXL_o.jpg

 
Zurück
Oben Unten