Webhooks Hookups - Abusing API Developers
Offered By: OWASP Foundation via YouTube
Course Description
Overview
Explore the potential security risks of webhooks in this 26-minute conference talk from OWASP Global AppSec Tel Aviv. Delve into how the open-ended nature of webhook integrations can lead API developers to inadvertently expose sensitive data beyond intended boundaries, potentially resulting in network compromises. Examine real-world examples of vulnerable applications and learn about the researchers' experiences with discovering and responsibly disclosing webhook-related vulnerabilities. Gain insights into how webhook development tools are being exploited in the wild and discover practical preventive measures to mitigate these threats. Learn about a new toolkit designed to help audit organizational webhook exposure. Presented by Tomer Zait, Principal Security Researcher at F5, and Maxim Zavodchik, Security Research Manager at F5 Networks, this talk offers valuable knowledge for anyone involved in API development or cybersecurity.
Syllabus
Webhooks Hookups Abusing API Developers TOMER ZAIT & MAXIM ZAVODCHIK
Taught by
OWASP Foundation
Related Courses
MongoDB for .NET DevelopersMongoDB University Web Application Development – Capstone Course
University of New Mexico via Coursera Ciberseguridad: ataques y contramedidas
Universidad Rey Juan Carlos via Independent Reliable Cloud Infrastructure: Design and Process auf Deutsch
Google Cloud via Coursera Securing and Integrating Components of your Application 日本語版
Google Cloud via Coursera