Web based APIs have grown significantly over the last decade. This is in response to enormous growth of mobile apps and rapidly emerging 'Internet of Things'. In the rush to push products to market, developers often take shortcuts on security, leaving online services vulnerable to attack. The risks are not as obvious as they may be in traditional browser based web apps, yet they are extremely susceptible and attackers know how to identify vulnerabilities. This course teaches you how to go on the offense and hack your own APIs before online attackers do.
Learning Objectives
- Discovering Device Communication With APIs
- Leaky APIs and Hidden APIs
- API Manipulation and Parameter Tampering
- API Authentication and Authorization Vulnerabilities
- Working With SSL Encrypted API Traffic
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Exploitation Analysis
- Software Development
- Vulnerability Assessment and Management
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.