⤷ Title: API Pen Testing : Zero to Hero Hands on Labs
════════════════════════
𐀪 Author: Vaibhav
════════════════════════
ⴵ Time: Wed, 06 May 2026 20:01:01 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #owasp_api_security_top_10 #web_security #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Vaibhav
════════════════════════
ⴵ Time: Wed, 06 May 2026 20:01:01 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #owasp_api_security_top_10 #web_security #penetration_testing #cybersecurity
Medium
API Pen Testing : Zero to Hero Hands on Labs
1. Introduction
⤷ Title: OWASP API Security Top 10–1 | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:47:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #owasp_api_security_top_10 #vulnerability #tryhackme
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:47:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #owasp_api_security_top_10 #vulnerability #tryhackme
Medium
OWASP API Security Top 10–1 | TryHackMe
Learn the basic concepts for secure API development (Part 1).
⤷ Title: API 2 : Broken Authentication
════════════════════════
𐀪 Author: Vaibhav
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:58:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #api_security #cybersecurity #web_security #owasp_api_security_top_10
════════════════════════
𐀪 Author: Vaibhav
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:58:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #api_security #cybersecurity #web_security #owasp_api_security_top_10
Medium
API 2 : Broken Authentication
Theory
⤷ Title: Beyond XSS and SQLi: Why Business Logic Is the Real Frontier of Web Security Testing
════════════════════════
𐀪 Author: Shubhomrawat
════════════════════════
ⴵ Time: Fri, 15 May 2026 17:48:35 GMT
════════════════════════
⌗ Tags: #business_logic #owasp_api_security_top_10 #cybersecurity #penetration_testing #web_application_security
════════════════════════
𐀪 Author: Shubhomrawat
════════════════════════
ⴵ Time: Fri, 15 May 2026 17:48:35 GMT
════════════════════════
⌗ Tags: #business_logic #owasp_api_security_top_10 #cybersecurity #penetration_testing #web_application_security
Medium
Beyond XSS and SQLi: Why Business Logic Is the Real Frontier of Web Security Testing
What a week of hands-on API testing taught me about thinking like an attacker, not just scanning like a tool
⤷ Title: Broken Authentication: How Attackers Gain Unauthorized Access to Your Application.
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Sat, 16 May 2026 16:54:23 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #api_penetration_testing #broken_authentication #owasp_api_security_top_10 #bug_bounty
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Sat, 16 May 2026 16:54:23 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #api_penetration_testing #broken_authentication #owasp_api_security_top_10 #bug_bounty
Medium
Broken Authentication: How Attackers Gain Unauthorized Access to Your Application.
Introduction: Why Broken Authentication Still Wins
⤷ Title: Broken Authentication: How Attackers Gain Unauthorized Access to Your Application.
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Mon, 18 May 2026 10:22:57 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #api_penetration_testing #broken_authentication #owasp_api_security_top_10 #bug_bounty
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Mon, 18 May 2026 10:22:57 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #api_penetration_testing #broken_authentication #owasp_api_security_top_10 #bug_bounty
Medium
Broken Authentication: How Attackers Gain Unauthorized Access to Your Application.
Introduction: Why Broken Authentication Still Wins
⤷ Title: OWASP crAPI Walkthrough Series
════════════════════════
𐀪 Author: Boluwatife Dada
════════════════════════
ⴵ Time: Tue, 19 May 2026 22:22:40 GMT
════════════════════════
⌗ Tags: #api_security #crapi #owasp_api_security_top_10 #crapi_walkthrough
════════════════════════
𐀪 Author: Boluwatife Dada
════════════════════════
ⴵ Time: Tue, 19 May 2026 22:22:40 GMT
════════════════════════
⌗ Tags: #api_security #crapi #owasp_api_security_top_10 #crapi_walkthrough
Medium
OWASP crAPI Walkthrough Series
Broken Object Level Authorization (BOLA) — API 1:2023
⤷ Title: I Found a Way to Access Company Data Without Logging In
════════════════════════
𐀪 Author: Abdullahbinzarshaid
════════════════════════
ⴵ Time: Wed, 20 May 2026 22:09:59 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #ethical_hacking #cybersecurity #web_security #owasp_api_security_top_10
════════════════════════
𐀪 Author: Abdullahbinzarshaid
════════════════════════
ⴵ Time: Wed, 20 May 2026 22:09:59 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #ethical_hacking #cybersecurity #web_security #owasp_api_security_top_10
Medium
I Found a Way to Access Company Data Without Logging In
By Abdullah Bin Zarshaid
⤷ Title: Bypassing the Vault: How SQLi, BOLA, BOPLA and PCI DSS Failures Broke a Vuln-bank API
════════════════════════
𐀪 Author: Divine
════════════════════════
ⴵ Time: Wed, 27 May 2026 05:38:04 GMT
════════════════════════
⌗ Tags: #api #api_security #owasp_api_security_top_10
════════════════════════
𐀪 Author: Divine
════════════════════════
ⴵ Time: Wed, 27 May 2026 05:38:04 GMT
════════════════════════
⌗ Tags: #api #api_security #owasp_api_security_top_10
Medium
Bypassing the Vault: How SQLi, BOLA, BOPLA and PCI DSS Failures Broke a Vuln-bank API
This is the final post in my vuln-bank series. Over the past four weeks I have worked through recon, JWT attacks, rate limiting, and PIN…
⤷ Title: GraphQL Introspection: The Feature That Hands Attackers Your API Blueprint
════════════════════════
𐀪 Author: johnnattakit 0xDD
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 12:56:35 GMT
════════════════════════
⌗ Tags: #owasp_api_security_top_10 #penetration_testing #vulnerability #graphql #cybersecurity
════════════════════════
𐀪 Author: johnnattakit 0xDD
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 12:56:35 GMT
════════════════════════
⌗ Tags: #owasp_api_security_top_10 #penetration_testing #vulnerability #graphql #cybersecurity
Medium
GraphQL Introspection: The Feature That Hands Attackers Your API Blueprint
TL;DR: GraphQL introspection is a built-in, spec-compliant feature that — when left enabled on production endpoints — gives attackers a…
⤷ Title: API Attacks 102: Login Olmak Yetmez, Yetki Kontrolü Şart
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Sat, 13 Jun 2026 13:44:26 GMT
════════════════════════
⌗ Tags: #api_security #cybersecurity #owasp_api_security_top_10 #application_security #web_security
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Sat, 13 Jun 2026 13:44:26 GMT
════════════════════════
⌗ Tags: #api_security #cybersecurity #owasp_api_security_top_10 #application_security #web_security
Medium
API Attacks 102: Login Olmak Yetmez, Yetki Kontrolü Şart
API güvenliğinde en sık yapılan hatalardan biri şudur:
⤷ Title: API Attacks 101: API’ler Neden Kritik Bir Saldırı Yüzeyi?
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Sat, 13 Jun 2026 13:28:47 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #owasp_api_security_top_10 #application_security #api_security
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Sat, 13 Jun 2026 13:28:47 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #owasp_api_security_top_10 #application_security #api_security
Medium
API Attacks 101: API’ler Neden Kritik Bir Saldırı Yüzeyi?
Bugün kullandığımız neredeyse her dijital ürünün arka planında API’ler var.
⤷ Title: API Attacks 102: Login Olmak Yetmez, Yetki Kontrolü Şart
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 18:33:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #api_security #owasp_api_security_top_10 #web_security #application_security
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 18:33:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #api_security #owasp_api_security_top_10 #web_security #application_security
Medium
API Attacks 102: Login Olmak Yetmez, Yetki Kontrolü Şart
API güvenliğinde en sık yapılan hatalardan biri şudur:
⤷ Title: API Attacks 103: Fazla Veri, Fazla Yetki ve Mass Assignment Riski
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 09:27:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #owasp_api_security_top_10 #web_security #application_security #api_security
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 09:27:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #owasp_api_security_top_10 #web_security #application_security #api_security
Medium
API Attacks 103: Fazla Veri, Fazla Yetki ve Mass Assignment Riski
Bir önceki yazıda API güvenliğinde en kritik ayrımlardan birini konuşmuştuk:
⤷ Title: API Attacks 104: Rate Limit Yoksa, API Kötüye Kullanılabilir
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 06:42:00 GMT
════════════════════════
⌗ Tags: #owasp_api_security_top_10 #web_security #application_security #cybersecurity #api_security
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 06:42:00 GMT
════════════════════════
⌗ Tags: #owasp_api_security_top_10 #web_security #application_security #cybersecurity #api_security
Medium
API Attacks 104: Rate Limit Yoksa, API Kötüye Kullanılabilir
Bir API endpoint’i doğru çalışıyor olabilir, kullanıcı giriş yapıyor olabilir, yetki kontrolü de belirli ölçüde uygulanıyor olabilir…
⤷ Title: API Attacks 105: SSRF ve Security Misconfiguration
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:25:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #application_security #api_security #owasp_api_security_top_10
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:25:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #application_security #api_security #owasp_api_security_top_10
Medium
API Attacks 105: SSRF ve Security Misconfiguration
API güvenliğinde bazı zafiyetler doğrudan veri erişimiyle ilgilidir.
⤷ Title: API Attacks 106: Eski API’ler, Yeni Riskler
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 06:31:38 GMT
════════════════════════
⌗ Tags: #application_security #owasp_api_security_top_10 #api_security #cybersecurity #web_security
════════════════════════
𐀪 Author: İlkan Aydoğan
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 06:31:38 GMT
════════════════════════
⌗ Tags: #application_security #owasp_api_security_top_10 #api_security #cybersecurity #web_security
Medium
API Attacks 106: Eski API’ler, Yeni Riskler
API güvenliğinde çoğu zaman aktif kullanılan endpoint’lere odaklanırız.
⤷ Title: Finding and Exploiting an unused API endpoint
════════════════════════
𐀪 Author: Dalila
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 14:00:05 GMT
════════════════════════
⌗ Tags: #rest_api_security #api_security #owasp_api #owasp_api_security_top_10 #api_endpoint_monitoring
════════════════════════
𐀪 Author: Dalila
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 14:00:05 GMT
════════════════════════
⌗ Tags: #rest_api_security #api_security #owasp_api #owasp_api_security_top_10 #api_endpoint_monitoring
Medium
Finding and Exploiting an unused API endpoint
This lab demonstrates how an unused API endpoint can be exploited. By analyzing HTTP requests and taking advantage of gaps revealed in…
⤷ Title: OWASP API Security Top 10 (2023)
════════════════════════
𐀪 Author: Mitty
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 06:07:35 GMT
════════════════════════
⌗ Tags: #owasp_api_security #api_security #api_security_testing #owasp_api_security_top_10 #owasp
════════════════════════
𐀪 Author: Mitty
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 06:07:35 GMT
════════════════════════
⌗ Tags: #owasp_api_security #api_security #api_security_testing #owasp_api_security_top_10 #owasp
Medium
OWASP API Security Top 10 (2023)
API1: Broken Object Level Authorization (BOLA)