

Buy anything from 5,000+ international stores. One checkout price. No surprise fees. Join 2M+ shoppers on Desertcart.
Desertcart purchases this item on your behalf and handles shipping, customs, and support to Italy.
You'll learn how REST and GraphQL APIs work in the wild and set up a streamlined API testing lab with Burp Suite and Postman. Then you'll master tools useful for reconnaissance, endpoint analysis, and fuzzing, such as Kiterunner and OWASP Amass. Next, you'll learn to perform common attacks, like those targeting an API's authentication mechanisms and the injection vulnerabilities commonly found in web applications. You'll also learn techniques for bypassing protections against these attacks. In the book's nine guided labs, which target intentionally vulnerable APIs, you'll practice: Enumerating APIs users and endpoints using fuzzing techniques; Using Postman to discover an excessive data exposure vulnerability; Performing a JSON Web Token attack against an API authentication process; Combining multiple API attack techniques to perform a NoSQL injection; Attacking a GraphQL API to uncover a broken object level authorization vulnerability. By the end of the book, you'll be prepared to uncover those high-payout API bugs other hackers aren't finding and improve the security of applications on the web. Review: Good Paper quality and fast delivery - Paper quality was good and it arrived quickly Review: Very useful book - The book is full of valuable information and walks you through deliberately vulnerable API Labs to reinforce what you've learned. Brilliant!





| Best Sellers Rank | 425,701 in Books ( See Top 100 in Books ) 46 in APIs 319 in Web Scripting & Programming |
| Customer Reviews | 4.7 out of 5 stars 322 Reviews |
A**A
Good Paper quality and fast delivery
Paper quality was good and it arrived quickly
A**T
Very useful book
The book is full of valuable information and walks you through deliberately vulnerable API Labs to reinforce what you've learned. Brilliant!
W**.
Very informative
A very informative book but unfortunately it sends me to sleep. Iโm unsure if itโs my dyslexia or if I just donโt find the subject as interesting as I had hoped. However it is a very informative book which though Iโm struggling to fully grasp I am glad I brought it.
S**.
Must read book for bug hunters and api developers
Amazing book by corey....i wish i would have bought this book early
F**S
Very good
I have read the book on 10 days and i feel i can hack APIs, whereas i had a backgroud about web hacking issues, the book is well organized and the reading was done seamlessly. There is a minor caveat, sometimes there is a lack of screenshot when operations in tools are describted, but It just occurs a couple of times or more.
T**R
A high tech and foundational cyber security book
"Hacking APIs" by Corey Ball, published in 2022 by No Starch Press, is a comprehensive guide to web API security testing. APIs, or Application Programming Interfaces, serve as intermediaries between software programs, enabling seamless communication. This book uniquely delves into API fundamentals and security practices, offering clear explanations and practical examples. It covers enumeration tools, vulnerability discovery, and emphasizes the importance of API security in the context of modern cyber trends like microservices. Despite the negative connotations associated with hacking, the book aims to educate cybersecurity enthusiasts on protecting systems rather than causing harm. For beginners, it provides a solid introduction to APIs and their vulnerabilities, while experienced professionals can benefit from its insights into advanced tools and techniques. In a rapidly evolving tech landscape dominated by mobile apps, understanding API security is paramount. "Hacking APIs" reframes the term "hacker" in its original context of creative problem-solving and system improvement, highlighting the crucial role of API security in safeguarding against cyber threats.
C**Y
Excellent
One of the best books Iโve read in a long time. Corey is an exceptional pen tester and mentor. He simplifies and deliver the content is an easy to digest way. The subject is very interesting. He covered a real need in that book. I practically like all No Starch Press publications. ๐
A**R
Pirated copy
Received a pirated copy with a substandard print quality, images are not in a readable condition.
Trustpilot
2 weeks ago
2 days ago