Completed
Why this happens
Class Central Classrooms beta
YouTube videos curated by Class Central.
Classroom Contents
Hidden in Plain Site - Disclosing Information via Your APIs - Peter Yaworski, Bugcrowd's LevelUp 2017
Automatically move to the next video in the Classroom when playback concludes
- 1 Introduction
- 2 About Peter Yaworski
- 3 Agenda
- 4 What is API
- 5 Why we care
- 6 Why this happens
- 7 Rails example
- 8 Removing information from view
- 9 The JSON file
- 10 The handy method merge
- 11 Adding a sensitive parameter
- 12 Personal anecdote
- 13 How do we find it
- 14 Examples
- 15 Customer ID
- 16 Vulnerability
- 17 Private Address
- 18 Wrapup