top of page
apis and business logic abuse

APIs and Business Logic Abuse

  • 39 Steps
  • 4 Participants

About

Prerequisite: Complete [Advanced Web Vulnerabilities](https://www.darkrelay.com/challenge-page/advanced-web-vulnerabilities) before this module. That unit covers SSRF, XXE, insecure deserialization, and SSTI on NeonVault. You will reuse Burp and HTTP request skills here when you move into API attack-surface modeling, authentication oracles, token verification, and concurrent money flows. In this module of the Web Application Pentester learning path, you study APIs and business logic abuse by learning how clients use web APIs, comparing REST with SOAP, GraphQL, RPC, and webhooks, and modeling a REST attack surface from requests and OpenAPI. You will connect CRUD operations, authentication models, authorization boundaries, and the OWASP API Security Top 10 to practical test decisions. You will audit the NeonVault Node.js REST API. After a practice-only foundation, inventory OpenAPI and live behavior, enumerate usernames, then abuse missing rate limits, reflective CORS with credentials, and an open redirect. You will elevate privileges through Mass Assignment, forge a JSON Web Token (JWT) by bypassing signature verification, and exploit a Time-of-Check to Time-of-Use race in the treasury withdrawal system. Upon completion of the module, students will be able to: • Explain API styles, REST constraints, CRUD semantics, request anatomy, and common authentication models. • Build an API testing worksheet from OpenAPI, live requests, and observed authorization boundaries. • Relate the OWASP API Security Top 10 2023 to relevant testing topics without treating it as a one-to-one checklist. • Enumerate usernames and test OTP limits, CORS, redirects, Mass Assignment, JWT verification, and concurrent withdrawals. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry

Overview

Price

2 Plans Available, From ₹2,399.00

Share

bottom of page