Hidden in Plain Site: Disclosing Information via Your APIs - Peter Yaworski, Bugcrowd's LevelUp 2017

  Рет қаралды 13,853

Bugcrowd

Bugcrowd

Күн бұрын

Пікірлер: 6
@oai9106
@oai9106 5 жыл бұрын
Thanks to Bugcrowd as well as Mr. Peter Yaworski .
@sowhatsupeirik
@sowhatsupeirik 5 жыл бұрын
Great talk Peter! Your a treat in webhacking and security in general.
@eliasibrahim1055
@eliasibrahim1055 6 жыл бұрын
Thank you Peter, this lesson really expanded my way of hunting.
@decalresponds3066
@decalresponds3066 7 жыл бұрын
This issue of failing to remove the proper column extracts from data returned by API operations created via code reuse requires really detailed table security to even begin to prevent. Aside from GRANT and REVOKE, I'm not sure ANSI SQL offers any other access control statements. Various technology-specific extensions to the DAL, DDL and DML (Data Access, Data Definition and Data Modification Languages) may exist depending on the RDBMS and DBA. However, even the most comprehensive security policies/constraints aren't going to stop application business logic errors--no excuses can be made for the developers there.
@watchlistsclips3196
@watchlistsclips3196 3 жыл бұрын
You are so sweet like the hacker who saved the internet marcus hutchins.
@huzifaahmed1426
@huzifaahmed1426 2 жыл бұрын
your ideas stil dangourase ✌ still high
How to have fun with a child 🤣 Food wrap frame! #shorts
0:21
BadaBOOM!
Рет қаралды 17 МЛН
Sigma girl VS Sigma Error girl 2  #shorts #sigma
0:27
Jin and Hattie
Рет қаралды 124 МЛН
БАБУШКА ШАРИТ #shorts
0:16
Паша Осадчий
Рет қаралды 4,1 МЛН
Do you like fuzzing? - Abhijeth, Bugcrowd's LevelUp 2017
25:40
Real Bugs - API Information Disclosure
17:32
The Cyber Mentor
Рет қаралды 33 М.
Bad API, hAPI Hackers! by jr0ch17
23:57
Bugcrowd
Рет қаралды 27 М.
Bugcrowd University - Cross Site Scripting (XSS)
24:50
Bugcrowd
Рет қаралды 106 М.
Clean Code - Uncle Bob / Lesson 2
1:06:01
UnityCoin
Рет қаралды 515 М.
Beginner's Guide to the Bash Terminal
1:14:37
Joe Collins (EzeeLinux)
Рет қаралды 2,3 МЛН
Node.js: The Documentary | An origin story
1:02:49
Honeypot
Рет қаралды 682 М.
DHH discusses SQLite (and Stoicism)
54:00
Aaron Francis
Рет қаралды 103 М.
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 147 М.
How to have fun with a child 🤣 Food wrap frame! #shorts
0:21
BadaBOOM!
Рет қаралды 17 МЛН