

Buy anything from 5,000+ international stores. One checkout price. No surprise fees. Join 2M+ shoppers on Desertcart.
Desertcart purchases this item on your behalf and handles shipping, customs, and support to Colombia.
Hacking APIs is a crash course in web API security testing that will prepare you to penetration-test APIs, reap high rewards on bug bounty programs, and make your own APIs more secure. Hacking APIs is a crash course on web API security testing that will prepare you to penetration-test APIs, reap high rewards on bug bounty programs, and make your own APIs more secure. Youโll learn how REST and GraphQL APIs work in the wild and set up a streamlined API testing lab with Burp Suite and Postman. Then youโll master tools useful for reconnaissance, endpoint analysis, and fuzzing, such as Kiterunner and OWASP Amass. Next, youโll learn to perform common attacks, like those targeting an APIโs authentication mechanisms and the injection vulnerabilities commonly found in web applications. Youโll also learn techniques for bypassing protections against these attacks. In the bookโs nine guided labs, which target intentionally vulnerable APIs, youโll practice: Enumerating APIs users and endpoints using fuzzing techniques Using Postman to discover an excessive data exposure vulnerability Performing a JSON Web Token attack against an API authentication process Combining multiple API attack techniques to perform a NoSQL injection Attacking a GraphQL API to uncover a broken object level authorization vulnerability By the end of the book, youโll be prepared to uncover those high-payout API bugs other hackers arenโt finding and improve the security of applications on the web. Review: Must read book for bug hunters and api developers - Amazing book by corey....i wish i would have bought this book early Review: Pirated copy - Received a pirated copy with a substandard print quality, images are not in a readable condition.





| Best Sellers Rank | #220,901 in Books ( See Top 100 in Books ) #65 in Web Development & Design #80 in API & Operating Environments #199 in Networking (Books) |
| Customer Reviews | 4.7 out of 5 stars 323 Reviews |
S**.
Must read book for bug hunters and api developers
Amazing book by corey....i wish i would have bought this book early
A**R
Pirated copy
Received a pirated copy with a substandard print quality, images are not in a readable condition.
R**J
Fake print, not the original print of book
Received a cheap print of book, interface screenshots are not even visible. Very small print on paper and that too very light, ink not visible clearly.
J**E
Pirated Copy
The book is pirated copy. with poor quality paper and design.
F**S
Very good
I have read the book on 10 days and i feel i can hack APIs, whereas i had a backgroud about web hacking issues, the book is well organized and the reading was done seamlessly. There is a minor caveat, sometimes there is a lack of screenshot when operations in tools are describted, but It just occurs a couple of times or more.
T**R
A high tech and foundational cyber security book
"Hacking APIs" by Corey Ball, published in 2022 by No Starch Press, is a comprehensive guide to web API security testing. APIs, or Application Programming Interfaces, serve as intermediaries between software programs, enabling seamless communication. This book uniquely delves into API fundamentals and security practices, offering clear explanations and practical examples. It covers enumeration tools, vulnerability discovery, and emphasizes the importance of API security in the context of modern cyber trends like microservices. Despite the negative connotations associated with hacking, the book aims to educate cybersecurity enthusiasts on protecting systems rather than causing harm. For beginners, it provides a solid introduction to APIs and their vulnerabilities, while experienced professionals can benefit from its insights into advanced tools and techniques. In a rapidly evolving tech landscape dominated by mobile apps, understanding API security is paramount. "Hacking APIs" reframes the term "hacker" in its original context of creative problem-solving and system improvement, highlighting the crucial role of API security in safeguarding against cyber threats.
C**Y
Excellent
One of the best books Iโve read in a long time. Corey is an exceptional pen tester and mentor. He simplifies and deliver the content is an easy to digest way. The subject is very interesting. He covered a real need in that book. I practically like all No Starch Press publications. ๐
A**A
Good Paper quality and fast delivery
Paper quality was good and it arrived quickly
A**T
Very useful book
The book is full of valuable information and walks you through deliberately vulnerable API Labs to reinforce what you've learned. Brilliant!
Trustpilot
2 weeks ago
1 day ago