New ArrivalsHoliday Hosting & EntertainingChristmasGift IdeasAI Gift FinderClothing, Shoes & AccessoriesHomeFurnitureToysElectronicsBeautyGift CardsCharacter ShopBabyKitchen & DiningGroceryHousehold EssentialsSchool & Office SuppliesVideo GamesMovies, Music & BooksParty SuppliesBackpacks & LuggageSports & OutdoorsPersonal CareHealthPetsUlta Beauty at TargetTarget OpticalDealsClearanceTarget New Arrivals Target Finds #TargetStyleHanukkahStore EventsAsian-Owned Brands at TargetBlack-Owned or Founded Brands at TargetLatino-Owned Brands at TargetWomen-Owned Brands at TargetLGBTQIA+ ShopTop DealsTarget Circle DealsWeekly AdShop Order PickupShop Same Day DeliveryRegistryRedCardTarget CircleFind Stores
Hacking APIs - by  Corey J Ball (Paperback) - 1 of 1

Hacking APIs - by Corey J Ball (Paperback)

$59.99

In Stock

Eligible for registries and wish lists

Sponsored

About this item

Highlights

  • Hacking APIs is a crash course in web API security testing that will prepare you to penetration-test APIs, reap high rewards on bug bounty programs, and make your own APIs more secure.
  • About the Author: Corey Ball is a cybersecurity consulting manager at Moss Adams, where he leads its penetration testing services.
  • 368 Pages
  • Computers + Internet, Web

Description



About the Book



"Teaches how to penetration-test APIs, make APIs more secure, set up a streamlined API testing lab with Burp Suite and Postman, and master tools for reconnaissance, endpoint analysis, and fuzzing. Topics covered include REST and GraphQL APIs, API authentication mechanisms, vulnerabilities, and techniques for bypassing protections. Includes nine guided labs"--



Book Synopsis



Hacking APIs is a crash course in web API security testing that will prepare you to penetration-test APIs, reap high rewards on bug bounty programs, and make your own APIs more secure.

Hacking APIs is a crash course on web API security testing that will prepare you to penetration-test APIs, reap high rewards on bug bounty programs, and make your own APIs more secure.

You'll learn how REST and GraphQL APIs work in the wild and set up a streamlined API testing lab with Burp Suite and Postman. Then you'll master tools useful for reconnaissance, endpoint analysis, and fuzzing, such as Kiterunner and OWASP Amass. Next, you'll learn to perform common attacks, like those targeting an API's authentication mechanisms and the injection vulnerabilities commonly found in web applications. You'll also learn techniques for bypassing protections against these attacks.

In the book's nine guided labs, which target intentionally vulnerable APIs, you'll practice:

  • Enumerating APIs users and endpoints using fuzzing techniques
  • Using Postman to discover an excessive data exposure vulnerability
  • Performing a JSON Web Token attack against an API authentication process
  • Combining multiple API attack techniques to perform a NoSQL injection
  • Attacking a GraphQL API to uncover a broken object level authorization vulnerability

  • By the end of the book, you'll be prepared to uncover those high-payout API bugs other hackers aren't finding and improve the security of applications on the web.



    Review Quotes




    "Corey Ball takes you on a journey through the lifecycle of APIs in such a manner that you're wanting to not only know more, but also anticipating trying out your newfound knowledge on the next legitimate target. From concepts to examples, through to identifying tools and demonstrating them in fine detail, this book has it all. It IS the motherload for API hacking, and should be found next to the desk, well-read by ANYONE wanting to take this level of adversarial research, assessment, or DevSecOps seriously."
    --Chris Roberts, @Sidragon1, vCISO/Researcher/Hacker

    "This book opens the doors to the field of API Hacking, a subject not very well understood. Using real-world examples that emphasize Access Control issues, this book will help you understand the ins and outs of securing APIs, hunt great bounties, and help organizations improve their API Security!"
    --Inon Shkedy, @InonShkedy, Security Researcher

    "Even though the internet is filled with information on any topic possible in cybersecurity, it is still hard to find solid insight on performing penetration tests on APIs. Corey's book satisfies this demand--not only for the beginner cybersecurity practitioner, but also for the seasoned expert."
    --Cristi Vlad, @CristiVlad25, Cybersecurity Researcher

    "Hacking APIs is extremely helpful for anyone who wants to get into penetration testing. In particular, this book gives you the tools to start testing the security of APIs, which are becoming a weak point for many modern web applications. Experienced security folks can get something out of the book too, as it features automation tips and protection bypass techniques that will up any pentesters' game."
    --Vickie Li, @vickieli7, Developer Evangelist, Author of Bug Bounty Bootcamp

    "[Hacking APIs is] the best source of API info I've seen. If you're curious about what APIs are and how they work, read it once. If you work with or create APIs, read it twice. If you break APIs, read it three times."
    --Graham Helton, @GrahamHelton3

    "One of the few books that is actually dedicated to API hacking. . . . a great resource for anyone who wants to learn more about API security and how to hack into web applications. It provides in-depth information on how to break through various types of APIs, as well as tips on how to stay ahead of the curve in this rapidly changing field."
    --Dana Epp, Security Boulevard

    "This book has more to offer than hacking APIs but sets down a solid foundation of tools and techniques that would benefit any developer or QA Engineer that has to develop, test, or otherwise work with APIs."
    --John Wenning, Cybersecurity Researcher, Fortra

    "A thorough guide to what APIs are, how they work, what technologies they use, the various common insecurities that APIs have, and, most importantly, how to exploit them. . . . I would recommend Hacking APIs as a great read for anyone interested in learning more about the vulnerable side of APIs."
    --Darlene Hibbs, Senior Cybersecurity Researcher, Fortra



    About the Author



    Corey Ball is a cybersecurity consulting manager at Moss Adams, where he leads its penetration testing services. He has over ten years of experience working in IT and cybersecurity across several industries, including aerospace, agribusiness, energy, financial tech, government services, and healthcare. In addition to a bachelor's degree in English and philosophy from Sacramento State University, Corey holds the OSCP, CCISO, CEH, CISA, CISM, CRISC, and CGEIT industry certifications.
    Dimensions (Overall): 9.1 Inches (H) x 6.9 Inches (W) x .8 Inches (D)
    Weight: 1.5 Pounds
    Suggested Age: 22 Years and Up
    Number of Pages: 368
    Genre: Computers + Internet
    Sub-Genre: Web
    Publisher: No Starch Press
    Theme: Web Services & APIs
    Format: Paperback
    Author: Corey J Ball
    Language: English
    Street Date: July 12, 2022
    TCIN: 1007429729
    UPC: 9781718502444
    Item Number (DPCI): 247-52-3987
    Origin: Made in the USA or Imported
    If the item details aren’t accurate or complete, we want to know about it.

    Shipping details

    Estimated ship dimensions: 0.8 inches length x 6.9 inches width x 9.1 inches height
    Estimated ship weight: 1.5 pounds
    We regret that this item cannot be shipped to PO Boxes.
    This item cannot be shipped to the following locations: American Samoa (see also separate entry under AS), Guam (see also separate entry under GU), Northern Mariana Islands, Puerto Rico (see also separate entry under PR), United States Minor Outlying Islands, Virgin Islands, U.S., APO/FPO

    Return details

    This item can be returned to any Target store or Target.com.
    This item must be returned within 90 days of the date it was purchased in store, shipped, delivered by a Shipt shopper, or made ready for pickup.
    See the return policy for complete information.

    Trending Computers & Technology Books

    Discover more options

    Empire of AI - by  Karen Hao (Hardcover)

    $18.81
    was $21.71 New lower price
    Buy 1, get 1 50% off select books & accessories

    Microsoft 365 Excel for Dummies - by  David H Ringstrom (Paperback)

    $16.99
    was $17.99 New lower price
    Buy 1, get 1 50% off select books & accessories

    Related Categories

    Get top deals, latest trends, and more.

    Privacy policy

    Footer

    About Us

    About TargetCareersNews & BlogTarget BrandsBullseye ShopSustainability & GovernancePress CenterAdvertise with UsInvestorsAffiliates & PartnersSuppliersTargetPlus

    Help

    Target HelpReturnsTrack OrdersRecallsContact UsFeedbackAccessibilitySecurity & FraudTeam Member ServicesLegal & Privacy

    Stores

    Find a StoreClinicPharmacyTarget OpticalMore In-Store Services

    Services

    Target Circle™Target Circle™ CardTarget Circle 360™Target AppRegistrySame Day DeliveryOrder PickupDrive UpFree 2-Day ShippingShipping & DeliveryMore Services
    PinterestFacebookInstagramXYoutubeTiktokTermsCA Supply ChainPrivacy PolicyCA Privacy RightsYour Privacy ChoicesInterest Based AdsHealth Privacy Policy