FΛForgeAwareness
Locked

API Security Training

Recognize the OWASP API Security Top 10 in a request, a token, and a handler. Explain how each risk is exploited. Apply the fix in code and at design time.

Backend & API developers, AppSec, cloud engineers · ~40 min · 8 modules

This course is part of the paid catalog. Purchase it individually, or unlock it with a membership that includes Tier 1 & 2 content.

What's inside

  1. 01
    Why API security is different
    Why APIs are attacked differently from web pages, and a map of the ten risks you are about to learn.
    ~5 min
  2. 02
    Broken object authorization: BOLA and property-level flaws
    API1 and API3 — returning objects the caller does not own, and exposing or accepting fields they should not touch.
    ~6 min
  3. 03
    Function and business-flow authorization
    API5 and API6 — admin routes a regular user can call, and legitimate flows that become weapons at scale.
    ~5 min
  4. 04
    API authentication and JWT security
    API2 — what makes API auth weak, and why a JWT you do not verify is just attacker-supplied JSON.
    ~6 min
  5. 05
    Rate limiting and resource consumption
    API4 — every endpoint costs something to call. Rate limits keep you online and frustrate brute force.
    ~5 min
  6. 06
    SSRF and security misconfiguration
    API7 and API8 — when your API becomes the attacker's proxy, and the settings that quietly leave the door open.
    ~5 min
  7. 07
    Inventory and safe consumption of APIs
    API9 and API10 — you can't defend what you can't see, and partner APIs are still untrusted input.
    ~4 min
  8. 08
    Logging, secure errors, and the API review checklist
    How to log enough to find a breach without becoming one, and a short checklist for every API review.
    ~4 min