Book
Hacking APIs
Corey Ball
Summary
REST・GraphQLなど現代のWeb API特有の脆弱性とペネトレーションテストの手法に特化した実践書。 BOLA/IDORやマスアサインメントなど認可の欠如に起因する脆弱性を攻撃者の視点から学び、その手法を リバースエンジニアリングすることで、堅牢なAPI設計を逆算的に導けるようになる。
Target Readers
- Web APIの脆弱性を攻撃者視点で理解したいエンジニア
- 堅牢なAPI設計をペネトレーションテストから逆算したい開発者
Tags
Colophon
- Publisher
- オライリー・ジャパン
- ISBN
- 978-4-8144-0024-9
- Published
- Mar 2023
- List price
- ¥4,400incl. taxMay differ from the actual selling price on Amazon
Get this book
* The link above is an advertisement via Amazon Associates.Related Books
Prerequisites
- Recommended
Grokking Web Application Security
Malcolm McDonald
Reason: Once the principles of defense are solid, adopt the attacker's view. Learning API vulnerabilities (BOLA/IDOR, etc.) — now the main battleground for SPAs and microservices — from the offensive side lets you work backward to robust API design.
- Related
セキュアAPI
José Haro Peralta
Reason: After learning to defend APIs from the design stage with a shift-left mindset, check from the attacker's side whether that design actually holds up. Learning authorization-gap vulnerabilities like BOLA/IDOR from the offensive side lets you work backward to reassess the robustness of your design.
Sources