Speaker
✓ Workshop day for free
✓ Save up to 622€
✓ Amazon Echo Dot or Arduino for free
Register now
✓ Workshop-Tag gratis
✓ Bis zu 622 € sparen
✓ Amazon Echo Dot oder Arduino gratis
Jetzt anmelden
✓ 2-in-1 conference package
✓ Team discount
✓ Extra specials for freelancers
Register now
✓ Bis zum nächsten mal!
Infos
Description
Application security threats are evolving.Fortune 100 companies with large budgets and talented security engineers get breached through their APIs on a weekly basis. Uber full account takeover, the famous Facebook breach, & the Verizon customer bills leakage are just a few recent examples of API based breaches. Traditional vulnerabilities such as SQL injection, CSRF & XSS are less prevalent thanks to modern technologies and security education.
Attackers leverage the predictable and oversharing nature of REST APIs to exploit new types of vulnerabilities that are focused on business logic abuse and authorization.
OWASP (the gold standard in AppSec) has acknowledged this shift in threats and has announced the OWASP API Security Project. The project addresses modern API threats and provides mitigation techniques.
Come learn from the leader of the project about:
– OWASP Top 10 For APIs and how they are different from traditional top 10 lists.
– Examples for complex API exploits, which involve many steps
– How to exploit an API as a pentester, and how to protect it as a developer.
This Session originates from the archive of Diese Session stammt aus dem Archiv von The HagueDen Haag . Take me to the program of . Hier geht es zum aktuellen Programm von Berlin Berlin .