Penetration Testing
search
⌘Ctrlk
Penetration Testing
  • Web
    • Reconnaissance
    • Open Source Intelligence
    • Misconfiguration
    • Identity Management
    • Broken Authentication
    • Broken Authorization
    • Session Management
    • Input Validation
    • Error Handling
    • Weak Cryptography
    • Business Logic
    • Client Side
    • API Attacks
      • Broken Object Level Authorization
      • Broken Authentication
      • Excessive Data Exposure
      • Lack of Resources and Rate Limiting
      • Broken Function Level Authorization
      • Mass Assignment
      • Security Misconfiguration
      • Injection Attack
      • Improper Assets Management
      • Insufficient Logging and Monitoring
  • Mobile
    • Mobile App Taxonomy
    • Mobile App Security Testing
    • General
    • Android
    • iOS
  • Cloud
    • Reconnaissance
    • SaaS
    • IaaS
    • Azure
    • AWS
    • GCP
    • IBM
    • Digital Ocean
    • Kubernetes
    • CI/CD
    • Active Directory
  • Network
    • Introduction
    • Intelligence Gathering
    • Vulnerability Analysis
    • Logical Vulnerabilities
    • Exploitation of Remote Services (User-Mode)
    • Exploitation of Remote Services (Kernel-Mode)
  • Wireless
    • Page 4
  • iot
    • Page 5
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Web

API Attacks

Broken Object Level Authorizationchevron-rightBroken Authenticationchevron-rightExcessive Data Exposurechevron-rightLack of Resources and Rate Limitingchevron-rightBroken Function Level Authorizationchevron-rightMass Assignmentchevron-rightSecurity Misconfigurationchevron-rightInjection Attackchevron-rightImproper Assets Managementchevron-rightInsufficient Logging and Monitoringchevron-right
PreviousReverse Tabnabbingchevron-leftNextBroken Object Level Authorizationchevron-right

Last updated 2 years ago