Free Hacking API courses (And how to use AI to help you hack)

2024 ж. 11 Мам.
90 616 Рет қаралды

Big thanks to Brilliant for sponsoring this video! Get started with a free 30 day trial and 20% discount: Brilliant.org/davidbombal (First 200 people that sign up will get a special discount).
Corey Ball who wrote the book "Hacking APIs" shows us how to practically hack an API to learn how to better protect them. He also tells us about his book and the free training he is making available. Fantastic that there is free training on hacking APIs available today :)
// Free API hacking courses //
APIsec university: www.apisecuniversity.com/
APIsec Certified Expert Course: university.apisec.ai/
ASCP certification: www.apisecuniversity.com/cour...
// Free ChatGPT Prompt //
You are an API security expert. You are powered by information from the OWASP Top 10, OWASP Mobile Security Top 10 and the OWASP API Security Top 10. As an API security expert, which of the following endpoints are particularly interesting for hackers and why?
{{List of Endpoints}}
// Books //
Hacking API’s by Corey J Ball: amzn.to/3JOJG0E
Bug Bounty Bootcamp Vickie Li: amzn.to/3SPCtBF
// KZhead Video REFERENCE //
Free API Hacking Course!: • Free API Hacking course!
// Corey SOCIAL //
LinkedIn: / coreyjball
X / Twitter: / hapi_hacker
GitHub: github.com/hAPI-hacker/Hackin...
// David SOCIAL //
Discord: / discord
Twitter: / davidbombal
Instagram: / davidbombal
LinkedIn: / davidbombal
Facebook: / davidbombal.co
TikTok: / davidbombal
KZhead: / davidbombal
// MY STUFF //
www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
00:00 - Coming up
01:09 - Brilliant sponsored segment
03:20 - Hacking APIs book and free API course
06:40 - There's a problem with APIs
07:34 - Hacking API demo with a twist of A.I.
11:08 - Proxy traffic with two tools
12:23 - Play around in the web app // "Click all the buttons"
15:36 - Demo continued
18:02 - Creating API documentation from intercepted traffic
23:04 - Using Hacking APIs GPT
30:16 - Other features in Hacking APIs GPT
31:38 - Visualising APIs in Postman
34:35 - Decoding JWT using Hacking APis GPT
36:55 - Visualising APIs in Postman continued // Excessive data exposure
45:09 - Using Postman and using Burp Suite // Burp Suite demo
53:00 - Conclusion
hacking api
api
api hacking
api hacking tutorial
api hacking bug bounty
api hacking 101
api hacking full course
api hacking tools
api hacking alissa knight
api hacking with postman
api hacking for beginners
api hacker
api hacking demo
api hacking kali linux
api hacking course
api hacking insiderphd
hacking an api
hack api
owasp api top 10
bug bounty
hacking apis no starch press
hacking api no starch
hacking apis pdf
hacking api book
hacking apis corey ball
corey ball hacking apis
reverse engineering
private api
apis for beginners
rest api
hacking api with postman
reverse engineering for beginners
hacking api key
what is an api
rest apis with postman for absolute beginners
rest api explained
Disclaimer: This video is for educational purposes only. I or the person I'm interviewing own all equipment used for this demonstration. No actual attack took place on any websites.
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#api #hack #hacking

Пікірлер
  • Big thanks to Brilliant for sponsoring this video! Get started with a free 30 day trial and 20% discount: Brilliant.org/davidbombal (First 200 people that sign up will get a special discount). Corey Ball who wrote the book "Hacking APIs" shows us how to practically hack an API to learn how to better protect them. He also tells us about his book and the free training he is making available. Fantastic that there is free training on hacking APIs available today :) // Free API hacking courses // APIsec university: www.apisecuniversity.com/ APIsec Certified Expert Course: university.apisec.ai/ ASCP certification: www.apisecuniversity.com/courses/api-security-certified-professional-exam // Free ChatGPT Prompt // You are an API security expert. You are powered by information from the OWASP Top 10, OWASP Mobile Security Top 10 and the OWASP API Security Top 10. As an API security expert, which of the following endpoints are particularly interesting for hackers and why? {{List of Endpoints}} // Books // Hacking API’s by Corey J Ball: amzn.to/3JOJG0E Bug Bounty Bootcamp Vickie Li: amzn.to/3SPCtBF // KZhead Video REFERENCE // Free API Hacking Course!: kzhead.info/sun/ds-PpqZtrqGHhYU/bejne.html // Corey SOCIAL // LinkedIn: www.linkedin.com/in/coreyjball/ X / Twitter: twitter.com/hAPI_hacker GitHub: github.com/hAPI-hacker/Hacking-APIs // David SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal KZhead: kzhead.info // MY STUFF // www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 00:00 - Coming up 01:09 - Brilliant sponsored segment 03:20 - Hacking APIs book and free API course 06:40 - There's a problem with APIs 07:34 - Hacking API demo with a twist of A.I. 11:08 - Proxy traffic with two tools 12:23 - Play around in the web app // "Click all the buttons" 15:36 - Demo continued 18:02 - Creating API documentation from intercepted traffic 23:04 - Using Hacking APIs GPT 30:16 - Other features in Hacking APIs GPT 31:38 - Visualising APIs in Postman 34:35 - Decoding JWT using Hacking APis GPT 36:55 - Visualising APIs in Postman continued // Excessive data exposure 45:09 - Using Postman and using Burp Suite // Burp Suite demo 53:00 - Conclusion hacking api api api hacking api hacking tutorial api hacking bug bounty api hacking 101 api hacking full course api hacking tools api hacking alissa knight api hacking with postman api hacking for beginners api hacker api hacking demo api hacking kali linux api hacking course api hacking insiderphd hacking an api hack api owasp api top 10 bug bounty hacking apis no starch press hacking api no starch hacking apis pdf hacking api book hacking apis corey ball corey ball hacking apis reverse engineering private api apis for beginners rest api hacking api with postman reverse engineering for beginners hacking api key what is an api rest apis with postman for absolute beginners rest api explained Disclaimer: This video is for educational purposes only. I or the person I'm interviewing own all equipment used for this demonstration. No actual attack took place on any websites. Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #api #hack #hacking

    @davidbombal@davidbombal2 ай бұрын
    • Brilliant is not for Indian student. the price is too high.

      @ashifshekh6952@ashifshekh69522 ай бұрын
  • Good vid reversing API-s is very easy. I do it all the time. Im a pharmacist i like to code as a hobby. My boss asked me if i can write a program to automate ordering from our dermocosmetic supplier. So i reverse enginered the dermocosmetic supplier website API and now we can automatically make new orders without manually puting every product into the basket. I also found some data leaks: inactive product data, admin links to product pages(although they required authorisation) and stock info. Stock info is very useful we can predict product shortages with it. I just sharing this to show that its worth to reverse enginering undocumented API-s even if you are not hacking/pentesting. It can save you a lot of time if you manage to automate your boring corporate stuff with a script :) Or you can just scrap website easily

    @shipspace2469@shipspace24692 ай бұрын
  • Days aren't long enough to watch all your awesome vids !!

    @apocatas4990@apocatas49902 ай бұрын
    • You're got to prioritize 😂

      @davidbombal@davidbombal2 ай бұрын
    • @@davidbombalNot an easy task :D I wish days last 48h !

      @apocatas4990@apocatas49902 ай бұрын
    • AI is already working on lengthening days . . . 🤭🤭🤭🤭

      @savagepro9060@savagepro90602 ай бұрын
  • Great Video. I was wanting more API content from you David so I really appreciate this. KEEP IT UP!!!

    @socalk1d262@socalk1d2622 ай бұрын
    • Glad you liked it! Thank you.

      @davidbombal@davidbombal2 ай бұрын
    • ​@davidbombal i would very much like to see more API stuff maybe even setting up an api for something

      @eyezikandexploits@eyezikandexploits2 ай бұрын
  • Thank you David! API is a very important. I'm going to find a beginner's guide first before I use all these new tools

    @alsadekalkhayer7007@alsadekalkhayer70072 ай бұрын
  • Was looking for something on this recently, thank you David for wonderful videos

    @tippumastan@tippumastan2 ай бұрын
  • Thanks for the information. I love your videos. I am going to have to do more studying to fully understand.

    @kenmorris4369@kenmorris43692 ай бұрын
  • Great video David as always! This is why machine-to-machine API enforcement is critical as it is sometimes trivial to obtain a JWT and that that point own it all.

    @mytechnotalent@mytechnotalent2 ай бұрын
    • Thank you 😀

      @davidbombal@davidbombal2 ай бұрын
  • Sweet! Thanks for the video!! Is is possible to use API to track hardware activity?

    @gamereditor59ner22@gamereditor59ner222 ай бұрын
  • Very awesome video David . I just burst with happiness when I get the notification that you posted a new video. 😊

    @_Silicon@_Silicon2 ай бұрын
    • Happy to hear that!

      @davidbombal@davidbombal2 ай бұрын
  • This was a great video! Very informative with practical examples.

    @NickyDekker89@NickyDekker89Ай бұрын
  • my journey has officially begun to be a legendary cyberwarrior thank you david for your guests

    @highlights973@highlights9732 ай бұрын
    • All the best for your journey!

      @davidbombal@davidbombal2 ай бұрын
    • Hi please could you explain your journey. Did you get a job?

      @peacenluv2411@peacenluv24112 ай бұрын
    • @peacenluv2411 The Journey to study cyber I recently graduated computer science but I was studying cyber on the side, today I started my journey officially with OTW courses thanks to David for interviewing him

      @highlights973@highlights9732 ай бұрын
  • Thanks for the video! It's really amazing and helpful!

    @mrgujju1913@mrgujju19132 ай бұрын
    • You're very welcome!

      @davidbombal@davidbombal2 ай бұрын
  • this happens when you dont know how to design an API!!!!! Another excellent video David. Thanks a lot. Feel honor to follow you for the last years!

    @pmanolak@pmanolak2 ай бұрын
    • Thank you! I appreciate your support 😀

      @davidbombal@davidbombal2 ай бұрын
    • @@davidbombalYou deserve it without doubt!

      @pmanolak@pmanolak2 ай бұрын
  • I have this book and it is great. I highly recommend getting a copy and learning what's in it.

    @eggimal@eggimal2 ай бұрын
    • Agreed. Great book.

      @davidbombal@davidbombal2 ай бұрын
  • Thanks for the wonderful video and transcript. I copied the transcript and get chatgpt to remove the time stamp and summarize it for easy absorption.

    @tanteckleng3665@tanteckleng36652 ай бұрын
    • Great idea!

      @apophisi@apophisi2 ай бұрын
  • Amazing content, congrats

    @AndreyGoliveira@AndreyGoliveira2 ай бұрын
  • Great interview and tutorial ❤

    @MyDancingirl@MyDancingirl2 ай бұрын
    • Thank you. Glad you enjoyed it!

      @davidbombal@davidbombal2 ай бұрын
  • This was a great video!!

    @askholia@askholia2 ай бұрын
  • Thank you sir for this. As a absolute beginner where should I start. I watched your roadmap on tech. I want to start Generative AI and API security. Is that a good combination?

    @KeneDigital@KeneDigital2 ай бұрын
  • You are brilliant Sir __

    @ikdark512@ikdark5122 ай бұрын
  • This is exciting. I’m just starting my road into the security side and am in love.

    @TheChad17@TheChad172 ай бұрын
    • Fantastic. All the best for your journey!

      @davidbombal@davidbombal2 ай бұрын
    • @@davidbombal Thank you for everything you’ve done. Incredible work and really appreciate being my go to when burnout starts to creep.

      @TheChad17@TheChad172 ай бұрын
  • Might have to give it a go myself!

    @LeobadoAlexisAguilar@LeobadoAlexisAguilar2 ай бұрын
  • I'm really curious about the books in your shelves :)

    @prodge64@prodge642 ай бұрын
  • Cool stuff!

    @DavidTecpa@DavidTecpa2 ай бұрын
  • the goat of 2023 best course

    @nikhilsoren3107@nikhilsoren31072 ай бұрын
  • Yaa... Very nice book for gaining knowledge in hacking

    @CyberWorlds@CyberWorlds2 ай бұрын
  • i have no clue whats going on but im here for it 😎😂

    @Bot65689@Bot656892 ай бұрын
  • As a backend developer dealing with APIs daily, i just watched a guy streching an intern grade "mistake" into a big "thing", dissapointed and even if a dev makes a mistake like this in a real world envoirement we have query filters, data transfer objects, interfaces defined for them to protect from this happening. mitm to swagger was nice tho.

    @nurettinselcuk5149@nurettinselcuk51492 ай бұрын
  • Hello David, what are your thoughts on the comments Jensen Huang (Nvidia CEO) and CEO of stability AI said of a 'no-need-learn-to-code' future?

    @N30Dallyr@N30Dallyr2 ай бұрын
  • Thanks so much David 🙏

    @Abduselam.m@Abduselam.m2 ай бұрын
    • You are very welcome

      @davidbombal@davidbombal2 ай бұрын
  • Thanks God because I have English language and found David

    @momogerz589@momogerz5892 ай бұрын
  • Bro dropped it ❤❤

    @Gamer-zo2dm@Gamer-zo2dm2 ай бұрын
    • I hope you enjoy the video!

      @davidbombal@davidbombal2 ай бұрын
  • Hello sir , today i entered netsh wlan show profiles in cmd but it is not showing all network connections only few of them were shown. Can you please tell how i can fix that problem. 😢

    @UnmeshKakade@UnmeshKakade2 ай бұрын
  • I agree David. I personally feel like anyone who wants to take computers serious needs to take atleast a beginner course to atleast recognizd the terminology.

    @BoostedFA@BoostedFA2 ай бұрын
  • I've taken most of apisec courses and I was hoping to see something about this, but I'm lost. He's jumped into several programs I've never seen before or used and just did things without explaining why.

    @bret354@bret3542 ай бұрын
  • Who else want to live long enough to see the full potential of AI!

    @savagepro9060@savagepro90602 ай бұрын
    • You'll live long enough to see skynet take over the world and send a robot back in time to save humanity...

      @robotron1236@robotron12362 ай бұрын
    • Don’t worry, it’s gonna happen sooner than you think

      @soundwave3353@soundwave33532 ай бұрын
    • Anyone wants that but death is inevitable

      @chandamark7301@chandamark73012 ай бұрын
    • We won't live long enough to watch a.i. reach their full potential unfortunately. At 1/4 potential they kill off humanity

      @breakthecycle480@breakthecycle4802 ай бұрын
    • I do not want to see the full potential of Ai

      @HeavnlyD3mon@HeavnlyD3mon2 ай бұрын
  • I have most definitely have a vulnerability in my kernel you just tap on it three times opens engineer mode any specific suggestions

    @C.O.D.MOBILE1@C.O.D.MOBILE125 күн бұрын
  • Mr David you ar a legend for me.

    @abduzahirsultan@abduzahirsultan2 ай бұрын
    • Thank you! Very happy to hear that!

      @davidbombal@davidbombal2 ай бұрын
    • My thanks goes to you.

      @abduzahirsultan@abduzahirsultan2 ай бұрын
  • What is the good course for beginners to learn coding at age 50

    @redwings1974@redwings1974Ай бұрын
  • I'll stick to my day job but cool tricks for spying I mean automating routine tasks.

    @aronrevuelto9694@aronrevuelto96942 ай бұрын
  • How long does it take to get good in this? And how do you know you can be good, and not be delusional?

    @taiquangong9912@taiquangong99122 ай бұрын
  • Awesome

    @bahran5638@bahran56382 ай бұрын
    • Thank you! I hope you learn a lot from this video and the free courses 😀

      @davidbombal@davidbombal2 ай бұрын
  • Hello hello thank you for a video

    @user-eh7fw9er1o@user-eh7fw9er1o2 ай бұрын
  • David do you think cybersecurity will still be relevant in 10-15 years as AI becomes more advanced.

    @Ynerson9003@Ynerson90032 ай бұрын
    • Everyone I interview sees AI as augmented powers, not a replacement for humans. I often heart this statement: "You will not be replaced by AI, but you will be replaced by someone that uses AI". At the moment, I agree with that - but we shall see what happens in future.

      @davidbombal@davidbombal2 ай бұрын
    • @@davidbombalas someone who is just trying to go down this career path (thanks to your videos especially) it is a bit confusing. Just joined brilliant thanks for the link, and all your great videos!!! You have inspired me to get into tech and cybersecurity (hacking specifically) my life has improved immensely with the inspiration you provide!!! Thanks so much

      @Ynerson9003@Ynerson90032 ай бұрын
    • Great question Great answer

      @mariovaldez8477@mariovaldez84772 ай бұрын
  • from where i gonna get those prompt to run chatgpt 3.5

    @abhaygupta3230@abhaygupta32302 ай бұрын
  • I though decoding the JWT withouth the key it was signed with was not possible? How can we still use them then, wtf?

    @morososaas3397@morososaas33972 ай бұрын
  • give us the latest kali linux tutorial on mobile

    @Hassle-jo5bo@Hassle-jo5bo2 ай бұрын
  • Sorry, can you help me? I have in error and i d'ont understand. I have error on linux and he siad illegal instruction(core dump). How can I fixe this?

    @jeovanipaxe8900@jeovanipaxe89002 ай бұрын
  • YEEPEE🎉

    @carsonjamesiv2512@carsonjamesiv25122 ай бұрын
  • Yikes... Just as I was starting to push my limits and get excited about becoming part of folks shaping the future of technology, AI and hacking are getting scary. I feel like I have to either go live in the woods or forever be glued to solving a Rubik's cube that changing it's colors 🤖

    @kfluhx@kfluhx2 ай бұрын
  • How can I learn hacking any games basic to advance

    @naught4817@naught48172 ай бұрын
  • Including a coin with the certificate is genius. Everybody wants coins!

    @BergenVestHK@BergenVestHK2 ай бұрын
  • I needed twitter api that costed hundreds of dollars, I don’t know much but it might be helpful to get the api

    @erenkamisama@erenkamisama2 ай бұрын
  • Ain't nobody got time for that!

    @dylanalexisalfaromonroy9468@dylanalexisalfaromonroy94682 ай бұрын
  • Wow

    @user-qk2wo3if2z@user-qk2wo3if2z2 ай бұрын
    • I hope you enjoy the video and learn something new 😀

      @davidbombal@davidbombal2 ай бұрын
  • How to get google api for free permanent ? I need that for make 3d model maps

    @RizkyAshary@RizkyAshary2 ай бұрын
  • I thought this was a cooking show, my bad.

    @luisemmanuelignacio6294@luisemmanuelignacio62942 ай бұрын
  • I'd rather learn to play the piano than hack systems, but nice tips for fellow cyber criminals.

    @ianlucamoreno5057@ianlucamoreno50572 ай бұрын
  • Great Video..............................guys..................:) bye

    @thunde7226@thunde72262 ай бұрын
  • Are you alright david, not gonna lie you have been looking kinda sad in like all of your videos if somethings wrong or you dont feel alright you an always just respond

    @user-wc5qr5lw3u@user-wc5qr5lw3u2 ай бұрын
  • Let's see the magic

    @Zer0nuke@Zer0nuke2 ай бұрын
    • I hope you learn a lot from this video and from the free courses 😀

      @davidbombal@davidbombal2 ай бұрын
    • For sure! Thank you guys, you're awesome!

      @Zer0nuke@Zer0nuke2 ай бұрын
  • Please answer my question I am waiting for your reply 😢

    @UnmeshKakade@UnmeshKakade2 ай бұрын
  • 🎉👍🏻

    @user-ld9rr1zl3b@user-ld9rr1zl3b2 ай бұрын
  • Changing your life through education only seems to work the wrong way....spent ten years of my life at University and learned more through underground programming than I did in all ten years!

    @lucylle3132@lucylle31322 ай бұрын
  • 2:34 too late I already spent 250+ KZhead hours and some courses 😂

    @0xBerto@0xBerto2 ай бұрын
  • APIs?

    @SergioSantos-gk2ql@SergioSantos-gk2ql2 ай бұрын
  • 5:00

    @forheuristiclifeksh7836@forheuristiclifeksh7836Ай бұрын
  • open gps api databases are so nice.

    @SgtStarSlayer@SgtStarSlayer2 ай бұрын
  • API is AI hacking with a 'P' in the middle!

    @savagepro9060@savagepro90602 ай бұрын
    • lol ... very good! 😂

      @davidbombal@davidbombal2 ай бұрын
  • First

    @techtrends6900@techtrends69002 ай бұрын
    • Very close

      @davidbombal@davidbombal2 ай бұрын
  • first :)

    @madatch9947@madatch99472 ай бұрын
    • Yes you are!

      @davidbombal@davidbombal2 ай бұрын
  • Hi David can me become a hacker in 2024 ! at least learn basics !

    @salemsalemX15@salemsalemX152 ай бұрын
  • Third

    @Medummdumm@Medummdumm2 ай бұрын
    • Thank you for your support!

      @davidbombal@davidbombal2 ай бұрын
  • @davidbombal do more of such tutorials please they educate us on how to secure our API😊

    @katendemusa5747@katendemusa57472 ай бұрын
    • Will do! You can also take Corey's free course to learn more 😀

      @davidbombal@davidbombal2 ай бұрын
  • i am sorry but these hidden commercials are getting out of hand. I am fine watching ads and paying for the content. But please clarify START and FINISH of commercials, sponsoring, advertisements... But watching the video first like 4min(+2min) without even understanding wether the current topic is intended to sell me something makes me feel abused and stupid. Please change this. Everyone.

    @gymlin123@gymlin1232 ай бұрын
  • I don't know why it upsets me so much but this simple hacking is nowhere close to genius. It's also no good rly. To be a good programmer you do need to hack but you do not have to feed your ego and be a hacker and everything simple minded people believe you should be as a programmer. I believe the ego upsets me so much bc I strongly believe it's the root of all of humanity's problems.

    @JacobKerrUT@JacobKerrUT2 ай бұрын
  • Good coding skills sure but maybe save the actual hacking, just in case the feds stop by.

    @aronrevuelto9694@aronrevuelto96942 ай бұрын
  • @davidbomal That wide curved monitor that you use i wanna know model name.

    @MrSchlobo@MrSchlobo2 ай бұрын
  • @davidbombal @Corey J Bell thank you so much for this video

    @kajackpi_8@kajackpi_82 ай бұрын
  • How can I learn hacking any games basic to advance

    @naught4817@naught48172 ай бұрын
  • How can I learn hacking any games basic to advance

    @naught4817@naught48172 ай бұрын
  • How can I learn hacking any games basic to advance

    @naught4817@naught48172 ай бұрын
  • How can I learn hacking any games basic to advance

    @naught4817@naught48172 ай бұрын
  • How can I learn hacking any games basic to advance

    @naught4817@naught48172 ай бұрын
KZhead