Free Hacking APIs Course (APISEC University!)
Key Takeaways
APISEC University offers a free 12-hour course on API pen testing and security, covering API security basics, web app security, and API testing, with tools such as Mr. Express and APISEC University.
Full Transcript
already well hey thanks so much everyone tuning in I am super excited to chat with some of these fun folks hey I've got Corey ball over here uh author of hacking apis putting out by no starch press I believe uh and hey I'm totally gonna ask you to fill in the gaps here because I can send your Praises just as well but I know you can do uh the right Justice here and Dan Dan I think hey helping out the crew building out the team for all the incredible stuff that's moving and shaking at API SEC University uh but please gentlemen introduce yourself uh and hey give me a little bit of context just as well what are you up to these days and what's awesome in your world sure so a quick intro of myself uh Corey ball I am Senior manager over penetration testing at Moss Adams there I'm a pen test consultant so day job is helping our clients through pen testing their Network and web apps and apis and when I'm not doing that I'm doing cool things like working with Dan over at happy SEC University to help create our courses and get more information know and writing books like hacking apis with uh Mr Express yeah yeah hey John and I'm Dan verahona my day job uh used to be with appisec uh which is a company that does automated API security testing still my day job um but last year uh kind of collaborated with Corey and came up with this idea of building a course to complement the hacking api's book and that was sort of the the Genesis of appisec University and what started out as you know kind of an interesting thing to to you know contribute and build for the community has now really become my full-time day job um whatever you want to call it Dino happy SEC University or Provost I don't even know what that means but happy St university has become really um just a tremendous uh destination and a site for for educational content around apis and how to secure them with our Flagship course from Corey but lots of grand plans to grow and expand that and add a lot more good stuff going forward it's incredible and kudos to you both uh for all that fantastic work and the fact that you're keeping with it it's still moving uh moving and shaking and I want to get it hey right out in the open right away because I think some folks are going to be jumping at the bit correct me if I'm wrong here but the course is free is that right yeah that's right so the first course we put out is the API pen test course and it's completely free uh all the tools and everything involved are are free as well and then you can go through the course and complete all the exercises and exams and walk away with a certificate of completion yeah and I'd just add on to that um yeah totally free um you can sign up it's happysecuniversity.com or appisecu.com whatever you like um sign up take the course there's about I don't know Corey 12 hours worth of video content in there with with all the text details so you can see the screen grabs you can see if Corey actually using the tools and hacking apis live uh in the course um they're quizzes and assessments throughout and um if you get through all of that you get your own badge and certificate and we see them by the hundreds getting posted onto LinkedIn it's uh it's a really gratifying thing and I'll just say you know we launched this thing back in August and we just crossed 30 000 students uh in the in the course so really excited about that and it's definitely got us thinking about where we can go uh where we can take this forward man that is that is so awesome because I I've seen them hey uh shouting and celebrating over on LinkedIn just as well and I think and again another incredible Kudos and Applause for for you both hats off for making this thing free and accessible uh and spreading education and spreading knowledge uh and just getting the info out there for everyone because I'm a huge proponent I I try to be as much as an advocate for that as I can uh and I think look that's the way that we can really move the needle that's how we can bring value to the whole industry the whole community and oh man you guys are doing it right so if I may I know hey we've been slinging around this whole acronym uh just to kind of add a little bit more color if folks don't happen to know could I catch your definition and how you kind of at least explain or raffle what what is an API yeah which I I do I get that question quite a bit especially from non-technical friends and such and the definition application programming interface you know just saying that really doesn't help anyone and so apis are a common interface for web applications to work together so I specifically hacking apis is all about rest apis there's some uh in there about graphql hacking as well uh but yeah the book is all about hacking web apis and same with the course so I like to bring up Uber as a great example so about 15 plus years ago when developers were creating a new uh application they would have to specialize or have developers specialize in all the different aspects of development and so you'd have to have part of the team that could develop maps and work with GPS and process payments and all these other things web apis came along and helped developers use the specialization of other organizations and the API allows them to pull the data and functionality out of these other groups and so now you have a company like uber that can pull the API from Google Maps and they can pull Payment Processing from another group and put it all together to create this new application that didn't exist before new business new organization so apis really help the data flow and shared functionality between organizations and different applications and if data is one of the world's most desired resources most valuable resources apis are what allow that to flow that was gonna be our next question and I think hey you were leading into it really well is like why is testing the API and why is it checking and validating and assessing API security why is that so important why is that so vital why is it just really a necessity here yeah so my background I I started out in penetration testing specifically Network pen testing and then moved into web app uh pen testing and from that perspective of an adversary you're trying to break into an organization through the uh external attack surface uh get past the firewall get into the network land on a machine pivot to the right machine find the data and then exfiltrate now you can really bypass all of that with a vulnerable API so a public vulnerable API is going to have a direct link to the most valuable resources that a company is trying to protect their data and if that's vulnerable then I can simply use the API request those resources and steal it without having to go through all the trouble of everything involved in a good Network pen test no I was just thinking because when I try to capture it I always think like man that is just the whole brains of the operation it's the like the central core the nucleus of a software like of an application uh hey if you can get right to the core of it more power to you yeah and the there's really a few parts to it like they are often vulnerable and unprotected and I think part of that is there there is such a business driver behind them that Security's still trying to catch up as usual and uh with those left vulnerable and overlooked uh it leaves a lot of deal-breaking vulnerabilities in place yeah I would I would just jump in and add you know like these apis are exposing like valuable useful functionality like being able to process a credit card or look up a map or you know book an Uber um but those apis expose any flaws in vulnerabilities and you know logic issues that might exist on the back end too and and we see this I mean every week almost daily examples of apis getting breached um where you know someone has discovered you know the interesting about an API is you can craft any request that you want right and just put it into the request then either the the back end is smart enough to reject it and detect that it's malicious or it's not but you can't do the equivalent in say a web application right like if you take what happened to coinbase right somebody basically used the API they reverse engineered it and was able to change the source account the source of funds from me from my account to your account right but then deposit the proceeds back into my account impossible to achieve that through the web app there's no button to adjust the source account right to somebody else but this person discovered that you know you could literally add a a variable to the API request that says Source account equals John right destination account equals Dan and process and in that case it actually worked right and so these apis don't just expose the the legitimate functionality but there can be those those logic gaps and flaws that also get exposed it's so crazy it's so wild again I think just man the mothership of the inherent functionality of an application uh and that's sitting right there and knowing how to speak that language just hey as you mentioned whether it's graphql whether it's whatever that's a lot of power so very very cool may I ask hey what kind of spurred the inspiration and creativity like let's write the book on this I feel like I talked to a lot of folks now that I'm like I genuinely get to say oh yeah he wrote the book on that they're like oh this is this is the expert that literally wrote the book uh that's very wild to be able to have that experience more and more but Corey I gotta ask you my friend where'd this idea and how did you put pen to paper here yeah so back in 2019 uh near the end of 2019 I started as a pen test consultant at Moss Adams and I was helping lead Network and web app pen testing one of the partners there said you know we have this growing demand for API pen tests and we want you to be the you know uh subject matter expert on on that topic and so I was more or less volatile to uh lead that area of testing from there I really dove into it and I I started my search on Amazon I just went and tried to gather all the books on the topic I typed in hacking apis and nothing came up for the first time in my career and so uh no stock overflow answer for this one yeah yeah exactly so I started to do a bunch of research I took a bunch of notes over the next few months I had 150 pages of notes put together I'd gone to a few conferences at that time and I would seek out you know whichever Elite hacker was giving the best talk and talk to them afterwards like what are you doing for a web API testing and they either didn't have an answer themselves or they just had that one person that specialized on team yeah and I'm like if the leading hackers that are giving these talks don't know about it there aren't any books on the topic it's not put together then you know maybe I'm on to something that uh I could share with the community uh through a book and I approached no starch press and they questioned me I think there was like three weeks of back and forth questions uh about the book and then uh signed on and continued writing and it took about two years from there for it to be over on my shelf wow okay I think you still are if I may uh first to Market though just as you mentioned like man that just there wasn't there wasn't an answer uh so we just made it so we built it okay so we'll put it together uh and again hats off kudos to you all uh I've I thank you you sent me a book by the way and I'm super grateful for that I've been flipping through it and it's just great great work yeah it's uh it's highly recommended reading I'm I'm not super technical the first three chapters um are really for anyone right if you want to understand what's an API what are rest calls you know all of the sort of Basics um that's great reading right and the rest of the book gets into I mean maybe Corey you can share some of the topic areas and this Maps very very well over to the course as well that was going to be my next question I don't know if you had anything to to bring in there uh Corey but I'd love to mention hey this is the companion to happy SEC University uh is there more love is there more we can chat about for what the university and courses bring into life yeah sure I'll touch on both of those so the uh book first three chapters goes over to the basics of apis and web apps and really gets anyone up to speed anyone with like a basic I.T experience can get into this and I'm I'm really convinced that apis can be the first person the first person first thing that a new hacker hacks and so it's a it's a huge gap in testing right now the classic tools that we use for web application testing often provide false negatives for API testing so if you generically test it especially without a token you give back results that look like nothing is wrong with the API so no budget is appropriated and the testers don't see anything interesting so they move on to the next thing and so I think you know the the book and getting new testers focused on apis especially through the the course is a great way to help start closing that Gap globally and preventing uh future API related breaches gotta be done yeah definitely as far as the course goes right now we have uh the full course is released you can get the certificate of completion next steps for that is I want to introduce like a real challenge to prove that you've developed your skills and you can apply them within a time frame I I have my oscp I know you have the trio on your end which is awesome um I'm heavily inspired by the quality of tests that offensive security puts out so I want to have something at that level and so right now are going through and finding um developers that are going to help us develop those custom vulnerable API driven apps for the course that's very cool that was one thing that I I did want to ask is like and if I may maybe jump the gun but like hey what what's next uh what's on the horizon what's on the roadmap are there are there more but hey let's get the Hands-On practical application kind of Capstone exam to it uh are there more things going to be sprinkled in slowly but surely definitely yeah this has really turned into a platform for API security related information and courses and so I think next step is really getting that exam out there and available and then we're going to start introducing micro courses so much smaller more digestible in a small time frame uh courses where you can learn things like the oasp API security top 10. and other fast items maybe compliance driven just really the whole variety of API security topics into there for me within the next year looking to hopefully develop and release a more beginners course so this one is the API pen test course but if someone really doesn't know about web apps and HTTP response codes and apis then this next course really help and match up closer to like the beginning of my book to help guide them into the topic better cool oh I'm stoked I'm super excited to see what you guys are gonna be cooking up next yeah hey hey John one one example there we we got contacted by probably one of the 10 largest banks I'd say uh in the U.S um their learning Department right and and to Corey's point about kind of a lack of of you know content books courses out there um you know they actually mandate that all their developers have to take an owasp you know web app um course um but they couldn't find an equivalent for for oauth API top 10 uh type of things right so they reached out and asked if we would deliver a course to them sort of uh personally and and it just sort of pointed out like you know there's this huge gap they're actually mandating all their developers take Corey's uh API pen testing course right and they can't get their hands on on um into GitHub for example until they've passed the course like these are sort of mandatory must know type of things so um that was I think a bit of an inspiration too you know we need some you know smaller more digestible intro level courses um so I if if we sort of started with the 301 if you will um with the API Panda that's sort of an advanced course um so now we're going to come out with the 101 and the 201s um but definitely look for quite a lot more material a lot more content and always we want to keep this as as free and accessible as possible I love it and hey congrats uh getting it like integrated into the pipeline is a really really cool thing and I think that that absolutely Fosters growth some of my last questions for you if it's all right I know hey Corey you're in the Weeds on this thing hey you're doing some of that pen testing for for day job cruising on an API second et cetera for for well you can but are there any and I love to ask are there any stories that you might be able to share because hey can we find any of those real case studies or any of those narratives and anecdotes that just absolutely prove the value and are just kind of wild and fun to tell along the campfire uh any sweet stuff that sticks out in your mind sure yeah I can speak generically to that not politically correct yeah safe as we can yeah so uh I've definitely had my hands on some fintech apis where you can really drive home the difference between some of the OSP API security top 10 uh differences so up top at the list you have Bola which is broken object level authorization and that's really the ability of user a to access user B's resources so I could look in with a fintech API uh I can look into what's in Dan's bank account right uh so that there's another one further down the list called broken function level authorization and that one is really about being able to access access functionality uh and interact with the resources of another user uh from an unauthorized testing standpoint so again with my account and a fintech API it's not just the ability to look into Dan's account but to begin transferring funds from his account back to my account and uh definitely seen those out in the wild in production and uh helped close those gaps during testing that's cool that's super cool well I think it goes back to like um I think one of Corey's big sort of messages um in sort of mantras is this whole concept of API first uh testing right and and you know you're talking about some of these regulations you know there are plenty of examples out there of you know organizations you know getting audited getting tested getting certified and using the sort of traditional web app scanners and things like that and getting a clean bill of help right right um and then there's one sort of very famous example at the Postal Service where this is a number of years ago they had a clean bill of health from the office of the Inspector General they had used all of these well-known web scanning tools nothing found and then a few months later you know was it 60 million user accounts accessed through a leaky API I don't know Corey do you have any sort of more color to add yeah I mean that uh that instance is really interesting all around uh that was in 2018 and the office of the Inspector General had done a review a web app pen test web app vulnerability assessment of uh the improved visibility program which part of the leading uh features of that program was the new API that was being released and the uh the report for that program is public you can still access it and read it through and see what's in there um one of the most notable things that's not in there if you do quick search through it is any mention of an API the tools that were used in it are included in the appendix so you can use those same tools on a CTF environment or deliberately vulnerable API driven apps and they come up uh with little to no results meanwhile a month after it got this clean bill of health and it was released they ended up on Krebs and so that's where uh the news was released that yeah 60 million uh instances of pii were leaked over this API and I think it actually took like another year for them to close the gap on that vulnerability um yeah if a tester had used the API as it was designed not even you know putting on the black hat or anything just really using it and you had done a search with the API for an address that was an apartment complex you'd see excessive data exposure so you would see the data of everyone else that lived in that apartment complex their information would also be leaked there were also authorization uh vulnerabilities in there too man I see a whole lot of like even different perspectives because absolutely a thousand percent from the testers and validators and assessing side start with that API because man that's where you're going to get the most bang for your buck and there's just so much that could come from it a lot of stuff might fall out uh but I also am thinking about like the developer side when you're writing applications when you're building software and code I always feel like they should start with the API and bake in and build in some of that security first so that those things don't happen I might go out on a limb here maybe touch a hot stove and I'll get flame for it but I think if software was written without a central API tends to be crap software when it's tacked on sort of halfway along or maybe at the end of development cycle then that's when even immediately opens up all those bugs and leaks and vulnerabilities and flaws uh so man getting this thing in the Forefront of everyone's mind is is I think a super important thing and I'm going to be right there beside you also touting like hey bring the API first make that the first priority yeah so I might say like apis have sort of been this elephant in the room of of API security right and I'll give you an example um you might have heard of fedramp it's you know the regulation for anyone that does cloud services to the government you have to certify for fedramp and in there under our A5 is a monthly vulnerability scan requirement right and it says all web interfaces this is the exact web interfaces must be scanned monthly and you deliver your reports back to the to um to your government agency right um so I asked the the pmo the program management offices does that concept web interface does that include apis and unequivocally the answer was yes it does okay and then when I talked to dozens of fedramp certified organizations and every last one was like that's not a requirement right it just like flat like every last one right to laugh at that so I think there's a new version of fedramp coming out and I think it will in fact say you know including apis just to make it you know very very clear for sure but but you know like probably for various reasons and one of them lack of talent lack of tools um how would you go about you know sort of scalably you know continuously effectively testing your apis right and and frankly it's why you know Corey didn't find a book and there wasn't a course and and why we have 30 000 folks signed up into Happy Sac U right this is this you know elephant in the room and when you read about breaches you know it's rarely a SQL injection attack that's that's succeeding right it's some sort of Bola you know logic flaw example that you know Leverage The a gap in the API that's that's where the breaches are happening well thank you for really leading the charge here I think it is it is a real necessity and uh I don't know I'm glad we we lit the match and hey that's that's all from you so hey as we're winding down in the last couple of moments here how can folks get started how can folks jump in how can to get a hold of you if that's appropriate how could they stay with this thing sure yeah definitely connect with me on LinkedIn follow me on Twitter I'm putting out you know any uh API security related information that's out there I'm pushing that out and having great conversations with people uh that's yeah way number one number two uh definitely join the course we have a Discord community of people there that great great to chat with and help you through any questions about the course or additional study material yeah definitely and and Corey is is uh at happy underscore hacker hapi um on Twitter um great guy to follow on LinkedIn um highly recommend folks uh sign up for happy SEC University just at appisecu.com free to sign up we have monthly newsletter we like to feature great people to follow on LinkedIn and other great resources um and yeah that Discord Community is phenomenal it's north of 3 000 folks in there and some really smart folks really vibrant a lot of a lot of good conversation going on there so lots of good ways to get involved fantastic I'm super happy to hear it and uh Hey for folks that don't know maybe just a little funny Easter egg I got to meet Corey just some time ago uh for the Sans Difference Maker award ceremony cheesy thing uh and poor Corey was the was the victim that had to sit in our required designated seating uh with me for dinner the entire evening so hey we got to have a whole lot of fun Banton and chatting uh and I I gotta say truth be told uh just loving all the sweet stuff that you all are up to uh great to meet you both in person when we had and uh I think it's really often that we say in our industry in our in our whole community that like look all the folks bringing out free education and free knowledge that's what's carrying this forward and that is how we stand on the shoulders of giants not not to be cliche not to be trite in any of that but it's one thing to say that and then it's another thing to be the Giants uh so hey Kudos and credit to again you all and uh I hope folks will dive in I hope we can get some folks interested in all this API SEC University the book and API security testing but thank you thank you thank you both and this has been a great shot thank you thanks so much thanks a lot for having us on cool thanks all
Original Description
Jump into APISEC university for free! https://jh.live/apisec
Also, the APISEC crew is doing a webinar on API Security in the Healthcare Industry if you are interested: https://jh.live/api-webinar
00:00 - Hacking APIs and APISEC University
00:06 - Introductions
04:13 - What is an API
06:22 - Why is testing the API so important?
10:13 - What inspired writing the book?
13:08 - Relationship between University and Book
15:06 - What's next?
18:06 - Story Time!
19:57 - Why it's important to test your API!
25:47 - How to get started
27:05 - Final thoughts
🔥 YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
🙏 SUPPORT THE CHANNEL ➡ https://jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ https://jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ https://jh.live/discord ↔ https://jh.live/twitter ↔ https://jh.live/linkedin ↔ https://jh.live/instagram ↔ https://jh.live/tiktok
💥 SEND ME MALWARE ➡ https://jh.live/malware
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: LLM Foundations
View skill →Related Reads
📰
📰
📰
📰
I Built a Free Privacy-First Developer Toolkit - No Data Leaves Your Browser
Dev.to · RavikiranReddy Balemla
A Non-Technical Way to Look at SSH
Dev.to · AbdulRasheed Agunbiade
CCIP Has Three Ways to Move Tokens Cross-Chain. Choosing the Wrong One Is an Audit Finding.
Dev.to · Ramprasad Edigi
Electron's docs quietly dropped their recommended security tool. What now?
Dev.to · Gyu
Chapters (11)
Hacking APIs and APISEC University
0:06
Introductions
4:13
What is an API
6:22
Why is testing the API so important?
10:13
What inspired writing the book?
13:08
Relationship between University and Book
15:06
What's next?
18:06
Story Time!
19:57
Why it's important to test your API!
25:47
How to get started
27:05
Final thoughts
🎓
Tutor Explanation
DeepCamp AI