41554 blogs · [ { "id": "01a08766-9f99-70b5-83d1-a4a6c22a5044", "title": "Why you should stay “professionally detached” from the vulns you find", "url": "https://danaepp.com/staying-professionally-detached-from-your-security-research", "published_at": "2024-11-26T17:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c327d598", "title": "Why Shadow APIs provide a defenseless path for threat actors", "url": "https://danaepp.com/why-shadow-apis-provide-a-defenseless-path-for-threat-actors", "published_at": "2024-11-19T17:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c3cee1c5", "title": "Is the latest book on “Pentesting APIs” any good?", "url": "https://danaepp.com/is-the-latest-book-on-pentesting-apis-any-good", "published_at": "2024-11-12T17:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c3f7a02b", "title": "Evade IP blocking by using residential proxies", "url": "https://danaepp.com/evade-ip-blocking-by-using-residential-proxies", "published_at": "2024-11-05T17:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c47b3197", "title": "KEV + CWE = Attack Vector ❤️‍🔥", "url": "https://danaepp.com/kev-cwe-attack-vector", "published_at": "2024-10-29T16:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c56fd1da", "title": "From Exploit to Extraction: Data Exfil in Blind RCE Attacks", "url": "https://danaepp.com/from-exploit-to-extraction-data-exfil-in-blind-rce-attacks", "published_at": "2024-10-22T16:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c57688b2", "title": "Attacking APIs using JSON Injection", "url": "https://danaepp.com/attacking-apis-using-json-injection", "published_at": "2024-10-15T16:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c5c36403", "title": "5 tips to improve your API exploits", "url": "https://danaepp.com/5-tips-to-improve-your-api-exploits", "published_at": "2024-10-08T16:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c6ab6517", "title": "Hacking API discovery with a custom Burp extension", "url": "https://danaepp.com/hacking-api-discovery-with-a-custom-burp-extension", "published_at": "2024-10-01T16:00:00+00:00" }, { "id": "01a08766-9f99-70b5-83d1-a4a6c7064508", "title": "Level Up Your Vulnerability Reports With CWEs", "url": "https://danaepp.com/level-up-your-vulnerability-reports-with-cwe", "published_at": "2024-09-24T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982995afb8", "title": "Hacking Modern Android Mobile Apps & APIs with Burp Suite", "url": "https://danaepp.com/hacking-modern-android-apps-with-burpsuite", "published_at": "2024-09-17T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a9829b7d6b1", "title": "Why the X-Bug-Bounty Header Matters for Hackers", "url": "https://danaepp.com/why-the-x-bug-bounty-header-matters-for-hackers", "published_at": "2024-09-10T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982a767cad", "title": "Detecting new API endpoints with oasdiff", "url": "https://danaepp.com/detecting-new-api-endpoints-with-oasdiff", "published_at": "2024-09-03T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982adec673", "title": "Why API Security Testing Matters – Learning from Tracfone", "url": "https://danaepp.com/why-api-security-testing-matters-learning-from-tracfone", "published_at": "2024-08-06T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982b6085da", "title": "Mapping Attack Patterns to your Threat Model", "url": "https://danaepp.com/mapping-attack-patterns-to-your-threat-model", "published_at": "2024-07-30T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982c118645", "title": "Covert Data Exfiltration via JSON in an API", "url": "https://danaepp.com/covert-data-exfiltration-via-json-in-an-api", "published_at": "2024-07-23T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982ca37cb0", "title": "Fuzzing JSON to find API security flaws", "url": "https://danaepp.com/fuzzing-json-to-find-api-security-flaws", "published_at": "2024-07-16T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982cc3ef94", "title": "Finding hidden API parameters", "url": "https://danaepp.com/finding-hidden-api-parameters", "published_at": "2024-07-09T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982d650366", "title": "Weaponizing API discovery metadata", "url": "https://danaepp.com/weaponizing-api-discovery-metadata", "published_at": "2024-07-02T16:00:00+00:00" }, { "id": "01a0c505-7128-71a7-be72-6a982d7d70f5", "title": "Hacking APIs with HTTPie", "url": "https://danaepp.com/hacking-apis-with-httpie", "published_at": "2024-06-25T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd648e49c5c", "title": "3 ways to improve appsec code auditing with graudit", "url": "https://danaepp.com/3-ways-to-improve-appsec-code-auditing-with-graudit", "published_at": "2024-06-18T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd64902be97", "title": "7 Deadly Sins of API Security Testing", "url": "https://danaepp.com/7-deadly-sins-of-api-security-testing", "published_at": "2024-06-11T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd649d5ecd0", "title": "Why HAST is important to API hackers", "url": "https://danaepp.com/why-hast-is-important-to-api-hackers", "published_at": "2024-06-04T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd64a287c3d", "title": "Writing Burp extensions in Kotlin", "url": "https://danaepp.com/writing-burp-extensions-in-kotlin", "published_at": "2024-05-28T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd64a29c571", "title": "Sensitive Data Detection using AI for API Hackers", "url": "https://danaepp.com/sensitive-data-detection-using-ai-for-api-hackers", "published_at": "2024-05-21T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd64a5a0193", "title": "Reverse Engineering Electron Apps to Discover APIs", "url": "https://danaepp.com/reverse-engineering-electron-apps-to-discover-apis", "published_at": "2024-05-14T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd64af07c3c", "title": "Guts & Greed: How Bug Hunter Arrogance and Apathy Hurts Us All", "url": "https://danaepp.com/guts-and-greed-vdp", "published_at": "2024-05-07T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd64b0fc07e", "title": "Finding Attack Vectors using API Linting", "url": "https://danaepp.com/finding-attack-vectors-using-api-linting", "published_at": "2024-04-30T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd64b1c2d02", "title": "5 Tips for API Hackers on Picking Your First Target", "url": "https://danaepp.com/5-tips-for-api-hackers-on-picking-your-first-target", "published_at": "2024-04-23T16:00:00+00:00" }, { "id": "01a0c517-33ba-7352-b823-1bd64b734c07", "title": "Is Bruno a good Postman alternative for API hacking?", "url": "https://danaepp.com/is-bruno-good-for-api-hacking", "published_at": "2024-04-16T16:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f8329b839", "title": "Breaking APIs with Naughty Strings", "url": "https://danaepp.com/breaking-apis-with-naughty-strings", "published_at": "2024-04-09T16:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f8406037b", "title": "The Beginners Guide to Writing API Security Tests in Postman", "url": "https://danaepp.com/the-beginners-guide-to-writing-api-security-tests-in-postman", "published_at": "2024-04-02T16:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f846160e6", "title": "Improving port scans against API servers", "url": "https://danaepp.com/improving-port-scans-against-api-servers", "published_at": "2024-03-26T16:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f84b33044", "title": "Discovering API secrets & endpoints using APKLeaks", "url": "https://danaepp.com/discovering-api-secrets-endpoints-using-apkleaks", "published_at": "2024-03-19T16:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f85187d94", "title": "5 more Burp extensions for API hacking", "url": "https://danaepp.com/5-more-burp-extensions-for-api-hacking", "published_at": "2024-03-12T16:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f85e69798", "title": "Is Nuclei any good for API hacking?", "url": "https://danaepp.com/is-nuclei-any-good-for-api-hacking", "published_at": "2024-03-05T17:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f8654f5c3", "title": "5 mistakes beginners make during app recon", "url": "https://danaepp.com/5-mistakes-beginners-make-during-app-recon", "published_at": "2024-02-27T17:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f865a9892", "title": "Writing API exploits in Python", "url": "https://danaepp.com/writing-api-exploits-in-python", "published_at": "2024-02-20T17:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f86b56439", "title": "Endpoints vs Routes: What every API hacker needs to know", "url": "https://danaepp.com/endpoints-vs-routes", "published_at": "2024-02-13T17:00:00+00:00" }, { "id": "01a0c522-2da8-736e-856b-543f87a406bb", "title": "Detecting API endpoints and source code with JS Miner", "url": "https://danaepp.com/detecting-api-endpoints-and-source-code-with-js-miner", "published_at": "2024-02-06T17:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc12a61fd", "title": "Detecting Uncommon Headers in an API using Burp Bambda Filters", "url": "https://danaepp.com/detecting-uncommon-headers", "published_at": "2024-01-30T17:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc1eca485", "title": "From Tsunami to Twitter: How Rigorous API Testing Can Prevent Critical System Outages During Disasters", "url": "https://danaepp.com/rigorous-api-rate-limiting-testing", "published_at": "2024-01-23T17:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc2664719", "title": "The No-Nonsense Guide to Bypassing API Auth Using NoSQL Injection", "url": "https://danaepp.com/bypassing-api-auth-using-nosql-injection", "published_at": "2024-01-16T17:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc2a00912", "title": "Beyond the Crystal Ball: What API security may look like in 2024", "url": "https://danaepp.com/api-security-in-2024", "published_at": "2024-01-11T00:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc2c87f33", "title": "Exploiting an API with Structured Format Injection", "url": "https://danaepp.com/structured-format-injection", "published_at": "2024-01-02T17:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc2f385b4", "title": "That time I broke into an API and became a billionaire", "url": "https://danaepp.com/that-time-i-broke-into-an-api-and-became-a-billionaire", "published_at": "2023-12-19T17:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc303e7a4", "title": "Finding “dark data” in an API", "url": "https://danaepp.com/finding-dark-data", "published_at": "2023-12-12T17:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc37f9175", "title": "Writing Burp Bambda Filters Like a Boss", "url": "https://danaepp.com/writing-burp-bambda-filters", "published_at": "2023-12-05T17:00:00+00:00" }, { "id": "01a0c52d-b31b-70c5-98ae-77cbc3d60fd6", "title": "Using Chaos Engineering To Hack An API", "url": "https://danaepp.com/using-chaos-engineering-to-hack-an-api", "published_at": "2023-11-28T17:00:00+00:00" }, { "id": "01a0c52d-b31c-7214-9293-37a4d62eb462", "title": "Uncovering Elusive API Targets via VHOST Discovery", "url": "https://danaepp.com/uncovering-elusive-api-targets-via-vhost-discovery", "published_at": "2023-11-21T17:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786f8a8d6db", "title": "Bypassing API rate limiting using IP rotation in Burp Suite", "url": "https://danaepp.com/bypassing-api-rate-limiting-using-ip-rotation-in-burp-suite", "published_at": "2023-11-14T17:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786f983a6e9", "title": "5 ways to improve your GraphQL hacking skills", "url": "https://danaepp.com/5-ways-to-improve-your-graphql-hacking-skills", "published_at": "2023-11-07T17:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786f9b416b5", "title": "API Recon Tip: Using AI to “Eyeball” your targets", "url": "https://danaepp.com/api-recon-tip-using-ai-to-eyeball-your-targets", "published_at": "2023-10-31T16:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786fa5ca18e", "title": "Adversarial Thinking for Bug Hunters", "url": "https://danaepp.com/adversarial-thinking-for-bug-hunters", "published_at": "2023-10-24T16:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786fa80e4fc", "title": "Proving API exploitability with Burp Collaborator", "url": "https://danaepp.com/proving-api-exploitability-with-burp-collaborator", "published_at": "2023-10-17T16:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786fb532350", "title": "What API hackers need to know about the Exploit Prediction Scoring System", "url": "https://danaepp.com/exploit-prediction-scoring-system", "published_at": "2023-10-10T16:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786fc45f8ae", "title": "The Art of Using Mind Maps to Improve Your API Hacking", "url": "https://danaepp.com/the-art-of-using-mind-maps-to-improve-your-api-hacking", "published_at": "2023-10-03T16:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786fc531511", "title": "Finding Hidden API Endpoints Using Path Prediction", "url": "https://danaepp.com/finding-hidden-api-endpoints-using-path-prediction", "published_at": "2023-09-26T16:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786fc7d3e8f", "title": "Writing API exploits using Postman Flows", "url": "https://danaepp.com/writing-api-exploits-using-postman-flows", "published_at": "2023-09-19T16:00:00+00:00" }, { "id": "01a0c538-5d99-72c0-8132-d786fd7094db", "title": "Why API Hacking is Critical to Web App Security Testing", "url": "https://danaepp.com/why-api-hacking-is-critical-to-web-app-security-testing", "published_at": "2023-09-12T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75af64b72", "title": "API Security Testing using AI in Postman", "url": "https://danaepp.com/api-security-testing-using-ai-in-postman", "published_at": "2023-09-05T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75be33d61", "title": "API Attack Surface Detection using Noir", "url": "https://danaepp.com/api-attack-surface-detection-using-noir", "published_at": "2023-08-29T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75c53e872", "title": "Mastering API Exploitation: Crafting Reverse Shells via cURL", "url": "https://danaepp.com/mastering-api-exploitation-crafting-reverse-shells-via-curl", "published_at": "2023-08-22T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75d233506", "title": "Why API hackers should embrace failure", "url": "https://danaepp.com/why-api-hackers-should-embrace-failure", "published_at": "2023-08-15T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75d6b50df", "title": "My secret to API privesc: Tapping compromised web servers", "url": "https://danaepp.com/my-secret-to-api-privesc-tapping-compromised-web-servers", "published_at": "2023-08-08T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75dd09745", "title": "Why Your Vulnerability Report Titles Suck, and What to Do About It", "url": "https://danaepp.com/why-your-vulnerability-report-titles-suck-and-what-to-do-about-it", "published_at": "2023-08-01T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75e20570f", "title": "Here’s how I get the most out of Burp Suite reporting", "url": "https://danaepp.com/heres-how-i-get-the-most-out-of-burp-suite-reporting", "published_at": "2023-07-25T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75eba5f46", "title": "The Ultimate Guide to Learning Burp Suite for FREE", "url": "https://danaepp.com/the-ultimate-guide-to-learning-burp-suite-for-free", "published_at": "2023-07-18T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75eba734b", "title": "Improve your API Security Testing with Burp BCheck Scripts", "url": "https://danaepp.com/improve-your-api-security-testing-with-burp-bcheck-scripts", "published_at": "2023-07-11T16:00:00+00:00" }, { "id": "01a0c541-e17b-7294-bc5f-37b75f1a1f68", "title": "How to exploit an API using prototype pollution", "url": "https://danaepp.com/how-to-exploit-an-api-using-prototype-pollution", "published_at": "2023-07-04T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c5606c758aa", "title": "3 ways to use Common Attack Patterns to abuse an API", "url": "https://danaepp.com/3-ways-to-use-common-attack-patterns-to-abuse-an-api", "published_at": "2023-06-27T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c5606c78ebf", "title": "A “cewl” way for API discovery", "url": "https://danaepp.com/a-cewl-way-for-api-discovery", "published_at": "2023-06-20T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c56077b0aca", "title": "Grepping through API payloads with Gron", "url": "https://danaepp.com/grepping-through-api-payloads-with-gron", "published_at": "2023-06-13T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c5607f578bc", "title": "Avoiding the Apocalypse: A Guide to Finding Zombie APIs", "url": "https://danaepp.com/guide-to-finding-zombie-apis", "published_at": "2023-06-06T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c5608b46c7c", "title": "The Lucrative Economics of API Hacking", "url": "https://danaepp.com/the-lucrative-economics-of-api-hacking", "published_at": "2023-05-30T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c56097316f4", "title": "Cross-Tenant Data Leaks (CTDL): Why API Hackers Should Be On The LookOut", "url": "https://danaepp.com/cross-tenant-data-leaks-ctdl-why-api-hackers-should-be-on-the-lookout", "published_at": "2023-05-23T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c560999bd42", "title": "How to get started as an API hacker", "url": "https://danaepp.com/how-to-get-started-as-an-api-hacker", "published_at": "2023-05-16T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c560a01bfff", "title": "Attacking APIs by tainting data in weird places", "url": "https://danaepp.com/attacking-apis-by-tainting-data-in-weird-places", "published_at": "2023-05-09T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c560a194e48", "title": "The Security Researcher’s Guide to Reporting Vulnerabilities to Vendors", "url": "https://danaepp.com/the-security-researchers-guide-to-reporting-vulnerabilities-to-vendors", "published_at": "2023-05-02T16:00:00+00:00" }, { "id": "01a0c54a-ccd1-70c7-857d-8c560a7da375", "title": "Finding API secrets in hidden layers within Docker containers", "url": "https://danaepp.com/finding-api-secrets-in-hidden-layers-within-docker-containers", "published_at": "2023-04-25T16:00:00+00:00" }, { "id": "01a0c553-14f1-727b-93b3-9065b87659a3", "title": "How to use GPG as a security researcher", "url": "https://danaepp.com/how-to-use-gpg-as-a-security-researcher", "published_at": "2023-04-18T16:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e3a50279", "title": "Exploiting Server Side Request Forgery (SSRF) in an API", "url": "https://danaepp.com/exploiting-ssrf-in-an-api", "published_at": "2023-04-11T16:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e3cab310", "title": "“Pay peanuts, Get monkeys”: The API Penetration Testing Pricing Dilemma", "url": "https://danaepp.com/pay-peanuts-get-monkeys-the-api-penetration-testing-pricing-dilemma", "published_at": "2023-04-04T16:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e3eee7f8", "title": "How Adversaries Attack APIs Through Dependencies", "url": "https://danaepp.com/how-adversaries-attack-apis-through-dependencies", "published_at": "2023-03-28T16:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e4a47b78", "title": "Why writing API exploits is important when reporting vulnerabilities", "url": "https://danaepp.com/why-writing-api-exploits-is-important-when-reporting-vulnerabilities", "published_at": "2023-03-21T16:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e4f040b9", "title": "Is Offensive AI Going to be a Problem for API Hackers?", "url": "https://danaepp.com/is-offensive-ai-going-to-be-a-problem-for-api-hackers", "published_at": "2023-03-14T16:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e59028a6", "title": "OWASP API Security Top 10: Upcoming Changes You Need To Know About", "url": "https://danaepp.com/owasp-api-security-top-10-upcoming-changes-you-need-to-know-about", "published_at": "2023-03-07T17:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e64fe227", "title": "An API Security Testing Checklist… with a twist", "url": "https://danaepp.com/an-api-security-testing-checklist-with-a-twist", "published_at": "2023-02-28T17:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e6f3a1cc", "title": "Analyzing Your Existing API Testing Through a Security Lens", "url": "https://danaepp.com/analyzing-your-existing-api-testing-through-a-security-lens", "published_at": "2023-02-21T17:00:00+00:00" }, { "id": "01a0c553-14f2-7035-9b4b-c145e71646cd", "title": "Exploiting embedded APIs by dumping firmware", "url": "https://danaepp.com/exploiting-embedded-apis-by-dumping-firmware", "published_at": "2023-02-14T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998ac1ec51", "title": "Beating the Demon of Self-doubt: Embracing Imposter Syndrome as a Hacker", "url": "https://danaepp.com/beating-the-demon-of-self-doubt-embracing-imposter-syndrome-as-a-hacker", "published_at": "2023-02-07T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998af98759", "title": "Using a Flipper Zero to access API source code on IoT devices", "url": "https://danaepp.com/using-a-flipper-zero-to-access-api-source-code-on-iot-devices", "published_at": "2023-01-31T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998b83fd40", "title": "Why you should never trust PoC exploits on GitHub", "url": "https://danaepp.com/why-you-should-never-trust-poc-exploits-on-github", "published_at": "2023-01-24T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998c3ab845", "title": "A Step-by-Step Guide to Writing Extensions for API Pentesting in BurpSuite", "url": "https://danaepp.com/a-step-by-step-guide-to-writing-extensions-for-api-pentesting-in-burpsuite", "published_at": "2023-01-17T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998cab5c19", "title": "5 simple questions to make your API pentest more successful", "url": "https://danaepp.com/5-simple-questions-to-make-your-api-pentest-more-successful", "published_at": "2023-01-10T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998cdbb918", "title": "3 training resources to improve your API hacking tradecraft", "url": "https://danaepp.com/3-training-resources-to-improve-your-api-hacking-tradecraft", "published_at": "2023-01-03T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998d2b2865", "title": "Hacking a .NET API in the real world", "url": "https://danaepp.com/hacking-a-net-api-in-the-real-world", "published_at": "2022-12-27T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998e28631f", "title": "How to use OAST to detect vulnerabilities in an API", "url": "https://danaepp.com/how-to-use-oast-to-detect-vulnerabilities-in-an-api", "published_at": "2022-12-20T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998ed3f262", "title": "Defeating a dockerized API to get access to source code", "url": "https://danaepp.com/defeating-a-dockerized-api-to-get-access-to-source-code", "published_at": "2022-12-13T17:00:00+00:00" }, { "id": "01a0c55b-85c4-72c0-838b-75998f27f531", "title": "How to extract artifacts from OpenAPI docs to help attack APIs", "url": "https://danaepp.com/how-to-extract-artifacts-from-openapi-docs-to-help-attack-apis", "published_at": "2022-12-06T17:00:00+00:00" } ] posts Claim your blog
Back to danaepp.com
Blog · corpus.blog/blogs/danaepp.com/posts

danaepp.com

danaepp.com

2024

2023

2022