0% found this document useful (0 votes)
10 views2 pages

API Security and Fuzzing Roadmap

The document outlines a 16-week roadmap for a Master in Web Hacking program, covering various topics such as HTTP, API security, authentication, and advanced exploitation techniques. Each week includes specific labs and tools to enhance practical skills in web hacking. The program culminates in a professional report and the publication of a technique or script.

Uploaded by

davidferreir
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views2 pages

API Security and Fuzzing Roadmap

The document outlines a 16-week roadmap for a Master in Web Hacking program, covering various topics such as HTTP, API security, authentication, and advanced exploitation techniques. Each week includes specific labs and tools to enhance practical skills in web hacking. The program culminates in a professional report and the publication of a technique or script.

Uploaded by

davidferreir
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Roadmap Master em Web Hacking - 16 Semanas

Semana 1 - HTTP Deep Dive + REST API Fundamentals


- RFCs, REST constraints, status codes, verbs
- Lab: Inspecionar trfego com Burp e Postman

Semana 2 - Recon de APIs + OpenAPI/Swagger abuse


- Ferramentas: nuclei, swagger-vuln
- Lab: APIs pblicas com Swagger exposto

Semana 3 - Autenticao: JWT, OAuth2, API Keys


- Ataques: key leakage, token replay, scope abuse
- Lab: JWT fuzzing com jwt_tool

Semana 4 - Broken Object Level Authorization (BOLA)


- IDORs em endpoints REST/GraphQL
- Lab: BOLA com mltiplos usurios

Semana 5 - Rate Limit + Abuse de lgica de negcio


- Ferramentas: Burp, ffuf paralelo
- Lab: bypass de limites via IP rotation

Semana 6 - GraphQL Ataques Avanados


- Query batching, introspection, injections
- Lab: GraphQL injection + exfiltrao

Semana 7 - WebSockets + SSE Exploits


- Fuzzing de mensagens, hijack de conexo
- Lab: Interceptar WebSocket com Burp

Semana 8 - SSRF via APIs + Cloud Metadata


- Exfiltrao de tokens via SSRF
- Lab: SSRF AWS Metadata Credenciais

Semana 9 - API Fuzzing Automtico + Custom tools


- Ferramentas: fuzzapi, OWASP ZAP automation
- Misso: criar script para fuzz de endpoints

Semana 10 - Deserialization + Unsafe parsing (XML/JSON/YAML)


- Ataques: XXE, insecure deserialization
- Lab: Explorar bibliotecas Java/Python
Roadmap Master em Web Hacking - 16 Semanas

Semana 11 - Broken Function Level Authorization (BFLA)


- Privilege escalation entre perfis
- Lab: Admin access via role bypass

Semana 12 - Exploits de cache, CORS, headers


- Cache poisoning, permissive CORS abuse
- Lab: Exploit cache inconsistente

Semana 13 - Automao de ataque com Python


- Construir scanner de API + PoC automticas
- Misso: script CLI para detectar falhas

Semana 14 - Red Team API: Ataques furtivos


- Timing attack, evasion, API traffic cloaking
- Lab: explorao sem alertar SIEM

Semana 15 - Bug bounty em APIs pblicas


- Recon e explorao real
- Lab: Testar API pblica real

Semana 16 - Relatrio + CVE-style disclosure


- Relatrio profissional e tcnico
- Misso: publicar tcnica ou script

You might also like