DEV Community

API

Application Programming Interface

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

Comments
6 min read
Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Comments
5 min read
NoSQL Injection in APIs: From Auth Bypass to JavaScript Execution via MongoDB Operators

NoSQL Injection in APIs: From Auth Bypass to JavaScript Execution via MongoDB Operators

Comments
5 min read
gRPC Server Reflection: The Unauthenticated API Catalog in Your Production Service

gRPC Server Reflection: The Unauthenticated API Catalog in Your Production Service

Comments
5 min read
API Versioning: When /api/v1/ Survives Without the Authentication Added in /api/v2/

API Versioning: When /api/v1/ Survives Without the Authentication Added in /api/v2/

Comments
5 min read
S3 Pre-Signed URLs Are Bearer Tokens: Five Attack Surfaces API Developers Miss

S3 Pre-Signed URLs Are Bearer Tokens: Five Attack Surfaces API Developers Miss

Comments
5 min read
Mass Assignment in REST APIs: When the Framework Binds More Than It Should

Mass Assignment in REST APIs: When the Framework Binds More Than It Should

Comments
5 min read
CRLF Injection in API Responses: When User Input Reaches HTTP Headers

CRLF Injection in API Responses: When User Input Reaches HTTP Headers

Comments
5 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

Comments
6 min read
gRPC Security: The Authorization Model REST Scanners Cannot See

gRPC Security: The Authorization Model REST Scanners Cannot See

Comments
5 min read
Content-Type Confusion in REST APIs: One Header Switch, Three Attack Surfaces

Content-Type Confusion in REST APIs: One Header Switch, Three Attack Surfaces

Comments
5 min read
API Tokens in CI/CD Pipelines: Five Exposure Surfaces That Rotation Does Not Close

API Tokens in CI/CD Pipelines: Five Exposure Surfaces That Rotation Does Not Close

Comments
5 min read
REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

Comments
6 min read
BFLA Survives Pentests: Why Testers Never Try the Wrong HTTP Method

BFLA Survives Pentests: Why Testers Never Try the Wrong HTTP Method

Comments
5 min read
LDAP Injection in API Login Endpoints: Filter Corruption, CVEs, and the Active Directory Scope

LDAP Injection in API Login Endpoints: Filter Corruption, CVEs, and the Active Directory Scope

Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.