API Hacking

Advanced API security testing methodology for bug bounty and application security work. Use when testing or reviewing REST APIs, GraphQL APIs, mobile APIs, internal or undocumented APIs, exposed infrastructure APIs, API key or token leaks, broken API authentication or authorization, BOLA/IDOR, sensitive response data, CORS/cache/CSRF flaws, SSRF through preview/export APIs, injection through API parameters, cloud or Kubernetes/Docker/control-plane APIs, webhook/callback APIs, and API-driven account, tenant, admin, file, billing, or operational workflows.

yafet-dev Updated

File contents

yafet-dev/bugbounty-codex-skills/tree/main/bug-type-skills/api-hacking commit 79a7cf9e64

Frequently asked questions

npx skillmds@latest add yafet-dev/api-hacking