HakByte: How to use Postman to Reverse Engineer Private APIs

  Рет қаралды 77,264

Hak5

Hak5

Күн бұрын

Пікірлер: 71
@danielm1359
@danielm1359 3 жыл бұрын
Amazing, reverse engineered a wireless controller the same way. It was a great way to start network automation.
@c0ri
@c0ri 2 жыл бұрын
Postman is awesome, been using it for a long time. It is extremely helpful writting code to interface APIs.. even if they are undocumented.
@lazerusmfh
@lazerusmfh 3 жыл бұрын
Good timing. I need a simple integration to a device with an api without documentation, and this will definitely help!
@Belioyt
@Belioyt 3 жыл бұрын
Really enjoyed this, eyes are wide open for possibilities
@finbom
@finbom Жыл бұрын
Thanks!!!! Amazing! Well worth spent 10 minutes to give me a MUCH better understanding. No fuzz, straight on with good examples and a working result.
@davidabba7663
@davidabba7663 2 ай бұрын
This was so understandable I think that’s what I was waiting for I feel much more confident on the vectors now or what to ask Bless you!
@John_Smith__
@John_Smith__ 3 жыл бұрын
The entire header section is going to be used by ebay in this case to fingerprint the browsers. Should be anonymized. But I've noticed servers on ebay sometimes do not have all the required fields populated, that is a search like that will miss a Lot of servers simply because the seller does not fill in all data on the required description of the item.
@cristianbam
@cristianbam 3 жыл бұрын
Why not just filter by XHR requests?
@janpost8598
@janpost8598 Жыл бұрын
Sometimes they put the data (like json) in the html code.
@oglothenerd
@oglothenerd 3 ай бұрын
I am trying to learn this stuff so I can archive Netflix original series as local video files! I hate the fact that if Netflix decides to remove these series, they will no longer exist.
@georgesmith9178
@georgesmith9178 2 жыл бұрын
Really nice vid. Thumbs-up of course. Just a quick suggestion - bump up your font size a bit (on some screens it is hard to see) and use some sort of pointer tracking tool, so that people can see where you click. I had to go back a couple of times in several sections of the video to see where you were clicking.
@coder159
@coder159 2 жыл бұрын
Please not the pointer tracking tool dear god
@robertfacella846
@robertfacella846 3 жыл бұрын
Using Runescape as the ideal case example, I see you
@drygordspellweaver8761
@drygordspellweaver8761 2 жыл бұрын
Do RuneScape API bots even work? Most I know use Ahk
@drygordspellweaver8761
@drygordspellweaver8761 2 жыл бұрын
Nice video- any resources on reversing a mobil app API?
@uboxtech
@uboxtech 2 жыл бұрын
what to do about cors error? i tried this multiple times, checked all headers but still giving me cors error
@BusinessIdeasHub
@BusinessIdeasHub 7 ай бұрын
Can you decompile an app and search api and can you use in postman? If yes then I'll send apk
@bukalter
@bukalter Жыл бұрын
I would like to use your method but I get error 401 meassage "Access denied due to missing subscription key. Make sure to include subscription key when making requests to an API." Is there some method to find it or use other way?
@notamindninja2003
@notamindninja2003 5 ай бұрын
Exactly like when a ho up in this house is taking too much of the pie and you need to take more from their available code so you can reverse engineer to thief back and take a higher position and more of your commission back- gig workers- get on that. They love to give opaque information but no helpful data. - Thanks for this-
@mmaranta785
@mmaranta785 3 жыл бұрын
Good info. Can I do that with C#?
@kizhissery
@kizhissery 2 жыл бұрын
to be frank the website you want most likely have cookies which changes in 12_24 hr , hence they will send 404
@ignaciokairuz
@ignaciokairuz Жыл бұрын
Great information!!
@Benedikt.05
@Benedikt.05 7 ай бұрын
want to create a zalando invoive scraper but I am completely new in that theme. Already checked that there is a specific link which triggers the download of the invoive. But I need an efficient way to scrape the ordernumbers and orderdates. Can I use the technique shown in the video to scrape those informations?
@bigbooduh
@bigbooduh 2 жыл бұрын
Enjoyed this, does Michael Raymond have any courses on api Hacking?
@mamupelu565
@mamupelu565 3 жыл бұрын
What if there's a really shitty website and I want to make another one on top of it, just to use it as a database basically?
@SamoCoder
@SamoCoder 2 жыл бұрын
Great video. Liked and subscribed. Thanks.
@zuberkariye2299
@zuberkariye2299 3 жыл бұрын
Hey Micheal from the Security FWD
@sihmy9870
@sihmy9870 3 жыл бұрын
What is he wearing? Is that a mic?
@firesnake6311
@firesnake6311 3 жыл бұрын
Oh yeah wait a minute Mr.postman hey ey ey ye Mr.postman
@ryanrozario1195
@ryanrozario1195 2 жыл бұрын
Can we do the same thing for air tickets??
@Rheaded
@Rheaded 7 ай бұрын
can i do this with safari and brave
@LeanneGrhymes
@LeanneGrhymes Жыл бұрын
does this work on websites that requires user log ins
@dr.groove7957
@dr.groove7957 3 жыл бұрын
Brah, you need to hit up a boot camp.
@gasparem16
@gasparem16 3 жыл бұрын
thanks! great video!!!
@statesponsored9435
@statesponsored9435 3 жыл бұрын
Wow great michael.
@shemmo
@shemmo 3 жыл бұрын
i like scraping sites but many times it can be illegal when you tap on the source with PII in it.. just saying, btw, nice tutorial
@zapbeeblebrox1053
@zapbeeblebrox1053 3 жыл бұрын
Maybe against terms of service but illegal? Not sure about that. The data is being delivered publicly. You can do what you want.
@kingsleyben297
@kingsleyben297 3 жыл бұрын
For this, You can search for *Hacklord Tom* a business page on fäcebóok.. he offers a wide range of hacking and spy services
@randyallen8610
@randyallen8610 Жыл бұрын
I need help scraping data from a website that has a firewall. Will pay
@evancunningham9872
@evancunningham9872 3 жыл бұрын
Very cool indeed.
@TabletMini
@TabletMini 3 ай бұрын
Just be careful to use the online version, as you might disclose sensitive information public.
@Pervy
@Pervy 3 жыл бұрын
Jason.
@river1711
@river1711 3 жыл бұрын
Very cool!
@denissetiawan3645
@denissetiawan3645 3 жыл бұрын
Yummy yummy, time to scrape.
@RohanVetale
@RohanVetale 8 ай бұрын
thankyouu
@midimusicforever
@midimusicforever 3 жыл бұрын
Cool. :)
@ismailachabi8627
@ismailachabi8627 Жыл бұрын
💚
@mindyabiznarc
@mindyabiznarc 3 жыл бұрын
💯
@ca7986
@ca7986 3 жыл бұрын
👌
@ianp6742
@ianp6742 3 жыл бұрын
First
@xseflx
@xseflx 3 жыл бұрын
5
@saberint
@saberint 3 жыл бұрын
omfg you are claiming you are 'reverse engineering' lmfao, this is pathetic...
@Christian-mn8dh
@Christian-mn8dh 2 жыл бұрын
what is this then?
@saberint
@saberint 2 жыл бұрын
@@Christian-mn8dh it’s simply monitoring the results. It’s not giving you the code behind or data access layers. Sure it shows a how to *sniff* an api, but that’s it.
@Christian-mn8dh
@Christian-mn8dh 2 жыл бұрын
@@saberint interesting. im trynna learn reverse engineering, have any advice on how I should start? it's kinda hard to find a good structured education for this
@edoch3700
@edoch3700 3 жыл бұрын
Fourth
@DD_MN
@DD_MN 3 жыл бұрын
Second
@harshdesai7957
@harshdesai7957 3 жыл бұрын
third
@mandc20022
@mandc20022 3 жыл бұрын
This guy has very feminine qualities
@retiallc
@retiallc 3 жыл бұрын
He is wearing a pride shirt.
@CelesteOnYoutube
@CelesteOnYoutube 3 жыл бұрын
WTF is wrong with you people
Hacking APIs: Fuzzing 101
13:29
The Cyber Mentor
Рет қаралды 53 М.
这是自救的好办法 #路飞#海贼王
00:43
路飞与唐舞桐
Рет қаралды 131 МЛН
Motorbike Smashes Into Porsche! 😱
00:15
Caters Clips
Рет қаралды 23 МЛН
МЕНЯ УКУСИЛ ПАУК #shorts
00:23
Паша Осадчий
Рет қаралды 3,3 МЛН
How To Do Recon: API Enumeration
56:12
InsiderPhD
Рет қаралды 60 М.
How To Hack APIs with Python
22:55
John Hammond
Рет қаралды 88 М.
Always Check for the Hidden API when Web Scraping
11:50
John Watson Rooney
Рет қаралды 644 М.
API Hacking 101, w/ Dr. Katie Paxton-Fear | by Traceable AI
54:34
Traceable AI
Рет қаралды 48 М.
Hacking/Reverse Engineering a PRIVATE api
6:35
chriscodes
Рет қаралды 110 М.
Tor Under Attack - ThreatWire
7:54
Hak5
Рет қаралды 13 М.
Web Scraping + Reverse Engineering APIs
52:33
Syntax
Рет қаралды 7 М.
Free Hacking API courses (And how to use AI to help you hack)
53:46
David Bombal
Рет қаралды 116 М.