Index
As this ebook edition doesn't have fixed pagination, the page numbers below are hyperlinked for reference only, based on the printed edition of this book.
A
access controls
Broken Function Level Authorization (BFLA) 108-110
Broken Object Level Authorization (BOLA) 106-108
bypassing 104-106
active enumeration 53
Amazon Web Services (AWS) 4, 102
American Fuzzy Lop (AFL) 148
Anaconda 41, 44
Apache Bench (ab) 42, 163
API abuse scenarios 212
credential stuffing 213
data scraping 227
parameter tampering 231
API keys 77-79
API reconnaissance 51
API security
need for 15, 16
APIs Guru
reference link 63
API vulnerabilities 17
Application Programming Interfaces (APIs) 3, 4, 5, 75
data and schema structures, identifying 70-72
documentation and endpoints, analyzing 62-66
enumerating 52-54
Google Remote Procedure Call (gRPC) 12
Graph Query Language (GraphQL) 7, 14, 15
history 5-7
...