APIs form the backbone of modern web and mobile applications, making them a prime target for attackers. This course deeply explores authentication flaws, broken object-level authorization, and injection paths across both REST and GraphQL endpoints.
You will learn how to intercept, manipulate, and fuzz API traffic using advanced proxy setups. We cover everything from discovering hidden undocumented endpoints to exploiting complex business logic flaws, ensuring you can secure the microservices that power today's digital economy.
Discovering undocumented endpoints, Swagger files, API versions, and mapping the attack surface.
Exploiting BOLA/IDOR, broken authentication, and mass assignment vulnerabilities in REST.
Executing introspection attacks, query batching, and deeply nested query Denial of Service (DoS).
Attacking JWTs, OAuth implementations, and custom token-based authorization mechanisms.
Finding and exploiting SQL, NoSQL, and command injection specifically through API parameters.
Automating the discovery of hidden parameters and edge-case vulnerabilities using advanced fuzzers.
This is a high-level overview of our modules. For a full, detailed syllabus breakdown and enrollment information, please contact us.
Contact on WhatsApp