Top 5 API Vulnerabilities That Pay in Bug Bounties
Автор: Medusa
Загружено: 2025-10-24
Просмотров: 5796
🐍 Portfolio: https://portfolio.medusa0xf.com/
✍️ Bug Bounty WriteUps: / medusa0xf
--------------------------------------------------------------------------------------------------------------------------------------------
In this video, I break down the Top 5 API Vulnerabilities Every Hacker Should Look For, including BOLA (IDOR), broken authentication, excessive data exposure, missing rate limits, and common security misconfigurations. You’ll learn what each one means, how to spot them, and why they matter in real-world bug bounty hunting. Whether you’re new to API hacking or already deep in recon, this guide will help you find more impactful bugs and level up your game.
--------------------------------------------------------------------------------------------------------------------------------------------
📱 Socials:
X: / medusa_0xf
Discord: / discord
LinkedIn: / insha-j-38b822225
Instagram: / medusa_0xf
--------------------------------------------------------------------------------------------------------------------------------------------
Links shown in the Video:
https://hackerone.com/reports/1372216
https://hackerone.com/reports/1709881
https://owasp.org/API-Security/editio...
/ how-i-discovered-a-pii-leak-in-a-developer...
https://owasp.org/API-Security/editio...
JWT Hacking: • JWT Hacking
API Pentesting crAPI: • API Pentesting crAPI
--------------------------------------------------------------------------------------------------------------------------------------------
Timestamps:
Introduction: 0:00
BOLA: 0:31
Broken Authentication: 4:04
Excessive Data Exposure: 7:31
No Rate Limiting: 9:50
BFLA: 13:50
Thoughts: 19:27
-------------------------------------------------------------------------------------------------------------------------------------------
#bugbounty #pentesting #infosec #cybersecurity #websecurity #portswigger #DOMInvader #securityresearch #ethicalhacking #vulnerability #exploit #javascript #webhacking #bugbountytips #reportwriting #zeroday #cve #idor #xss #oauth #chatgpt #owasp #owasptop10 #ssrf #recon #ethicalhacking #portswigger #owasp #bugbounty #cve #cybersecurity #graphql #apihacking #developer #hackerone #jwt #api #subdomain #portswigger #bugbounty #bola #postman #podcast #pentesting #api #hack #bola #tryhackme #hackerone
--------------------------------------------------------------------------------------------------------------------------------------------
Music from #InAudio: https://inaudio.org/
Infraction - Press Start
massobeats - rose water
massobeats - until then
massobeats - moonlit
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: