Locked
API Security Training
Recognize the OWASP API Security Top 10 in a request, a token, and a handler. Explain how each risk is exploited. Apply the fix in code and at design time.
Backend & API developers, AppSec, cloud engineers · ~40 min · 8 modules
This course is part of the paid catalog. Purchase it individually, or unlock it with a membership that includes Tier 1 & 2 content.
What's inside
- 01~5 minWhy API security is differentWhy APIs are attacked differently from web pages, and a map of the ten risks you are about to learn.
- 02~6 minBroken object authorization: BOLA and property-level flawsAPI1 and API3 — returning objects the caller does not own, and exposing or accepting fields they should not touch.
- 03~5 minFunction and business-flow authorizationAPI5 and API6 — admin routes a regular user can call, and legitimate flows that become weapons at scale.
- 04~6 minAPI authentication and JWT securityAPI2 — what makes API auth weak, and why a JWT you do not verify is just attacker-supplied JSON.
- 05~5 minRate limiting and resource consumptionAPI4 — every endpoint costs something to call. Rate limits keep you online and frustrate brute force.
- 06~5 minSSRF and security misconfigurationAPI7 and API8 — when your API becomes the attacker's proxy, and the settings that quietly leave the door open.
- 07~4 minInventory and safe consumption of APIsAPI9 and API10 — you can't defend what you can't see, and partner APIs are still untrusted input.
- 08~4 minLogging, secure errors, and the API review checklistHow to log enough to find a breach without becoming one, and a short checklist for every API review.