0% found this document useful (0 votes)
23 views6 pages

API Penetration Testing Course Overview

The API Pentest course offered by Ignite Technologies focuses on modern API security issues, emphasizing the OWASP API Top 10 to help participants understand vulnerabilities and necessary patches. It is designed for individuals involved in mobile or web applications with API backends, providing hands-on experience and practical knowledge. The course includes various topics related to API security testing and is led by certified trainers with extensive industry experience.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
23 views6 pages

API Penetration Testing Course Overview

The API Pentest course offered by Ignite Technologies focuses on modern API security issues, emphasizing the OWASP API Top 10 to help participants understand vulnerabilities and necessary patches. It is designed for individuals involved in mobile or web applications with API backends, providing hands-on experience and practical knowledge. The course includes various topics related to API security testing and is led by certified trainers with extensive industry experience.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

E T R A T

API
I O N TESTING
PEN

+91 95993-87841
CONTACT US
FOR MORE DETAILS [Link]
ABOUT COURSE
What is API Pentest course?
The OWASP API Top 10 will be focused in the API Pentest course to create awareness
about modern API security issues. If you're familiar with the OWASP Top 10 series,
you'll notice the similarities: they are intended for readability and adoption. APIs play a
very important role in modern applications' architecture and APIs handle a very high
volume of sensitive data, ensuring their safety through persistent testing is critical.
Its purpose is to ascertain whether an API is vulnerable and then to suggest to the client
what patches should be applied.

Who needs API Pentest?


API penetration testing should be conducted regularly for every company that uses
mobile or web applications with an API backend. The security of APIs is crucial to the
security of applications.

Ignite Training Objective


API Security Top 10
API Security Cheat Sheet
crAPI - Completely Ridiculous API, an intentionally vulnerable API project)

Prerequisites
Basic knowledge of Web Application Pentesting as per OWASP top 10, ethical hacking,
Kali Linux and BurpSuite,

Course Duration: 30 Hours (Tentative)


Price: Contact us
ABOUT IGNITE Well-Known Entity for Offensive Security
Training and Services

About us
With an outreach to over a million students and over thousand colleges, Ignite
Technologies stood out to be a trusted brand in cyber security training and services.

WHO
CAN
College Students
IS/IT specialist, analyst, or manager
IS/IT auditor or consultant
IT operations manager WHY
Network security officers and
Practitioners US
Site administrators
Level up each candidate by providing the
Technical support engineer
fundamental knowledge required to begin the
Senior systems engineer
Sessions.
Systems analyst or administrator
Hands-on Experience for all Practical Sessions.
IT security specialist, analyst, manager,
Get Course PDF and famous website links for
architect, or administrator
content and Tools
IT security officer, auditor, or engineer
Customized and flexible training schedule.
Network specialist, analyst, manager,
Get recorded videos after the session for each
Architect, consultant, or administrator
participant.
Get post-training assistance and backup
sessions.
Common Platform for Group discussion along
with the trainer.
Work-in Professional Trainer to provide real-
time exposure.
Get a training certificate of participation.
Ignite Trainers
Ignite Trainers are well-experienced and have vast experience with real-time threats.
Had working exposure in Big Fours and MNCs and Fortune 500 companies and clients such
as Tata, Facebook, Google, Microsoft, Adobe, Nokia, Paypal, Blackberry, AT&T and many
more.
Certified Trainers: CEH, OSCP, OSWP, Iso- Lead Auditor, ECSA, CHFI, CISM

This will help the candidate to


understand the backend
functionality and Implementation

Learn the fundamentals


In-house lab concept and works flow of
APIs
setup

Building the
gaps Test and identify the
misconfiguration and

Approach exploitable vulnerabilities as


per OWASP

Threat &
Analysis

Provide recommendations for


Mitigation patching the vulnerabilities by
addressing CVSS Risk score
COURSE CONTENT
1. Course Introduction 21. Attacking 0Auth 2.0
2. How API works with Web application 22. Introduction to OWASP TOP 10 API
3. Types of APIs and their advantages/ 23. Hunting and exploiting XXS in API
disadvantages 24. Testing for the ReDOS attack in the API
4. Analysing HTTP request and web application
response headers 25. Exploiting XML vulnerabilities
5. API Hacking methodologies 26. WordPress XML-RPC attack
6. Enumerate web pages and analyse 27. Exploiting WSDL/SOAP to RFI
functionalities 28. API Automated Vulnerability scanning
7. API passive reconnaissance 29. Testing SQL/NoSQL Injection in an API
Strategies 30. Exploiting object-level access control
8. API active reconnaissance (Kite 31. Exploiting Function level access
runner) control
9. Introduction to POSTMAN 32. Testing in band SSRF vulnerabilities in
10. Testing for the Excessive data an API
exposure 33. Testing out band SSRF vulnerabilities
11. Directory indexing /brute force in an API
12. Password mutation 34. Testing OS Command Injection
35. Exploiting Java deserialization
13. Password spray attacks against web
vulnerabilities
application
36. Testing for improper assets
14. Introduction to JSON Web Token
management
15. Hunting for JWT authentication 37. Testing for Mass assignment
vulnerabilities vulnerabilities
16. Exploiting JWT unverified signature 38. Bypass filter, space, and blacklisted
17. Cracking JWT secret keys characters
18. Bypass JWT removing signature 39. Bypass Captcha and MFA
19. Exploit jku header injection 40. Remediations and Reporting
20. Exploit KID in JSON web tokens
PHONE
+91-9599387841

WHATSAPP
[Link]

EMAIL ADDRESS
info@[Link]

WEBSITE
[Link]

BLOG
[Link]

LINKEDIN
[Link]

TWITTER
[Link]

GITHUB
[Link]

You might also like