I was doing a talk about Hacking APIs @ Plattform Summit 2025. Here is the presentation and all the commands. Applications / Toolshttps://www.apisec.ai/https://cloud.apisecapps.com/https://www.usebruno.com/ Educationhttps://www.home.apimasters.io/learnhttps://www.apisecuniversity.com/ crAPIhttps://github.com/OWASP/crAPI/bhttp://crapi.apisec.ai/loginhttp://crapi2.apisec.ai/login Information:https://danaepp.com/https://nordicapis.com/api Installation Install kali BurpSuitesudo apt-get install burpsuite Brunohttps://www.usebruno.com/downloadssudo apt-get install ./bruno_2.11.0_amd64_linux.deb FireFoxFoxyProxy Burpsuite Certifcatehttp://burpsuite Mitmproxy Certificatehttp://mitm.it Postmansudo wget https://dl.pstmn.io/download/latest/linux64 -O postman-linux-x64.tar.gz && sudo tar -xvzf postman-linux-x64.tar.gz -C /opt &&... Continue Reading →
What do I think of the Designing and Implementing API Systems course from apimasters with Mike Amundsen
In today’s interconnected digital world, APIs those quiet enablers of data exchange power everything from your favorite apps to complex enterprise systems. Yet for many professionals APIs still feel like a black box technical, mysterious and not something they need to “understand” to do their job. That’s where this API Learning Path with Mike Amundsen... Continue Reading →
What do I think of the Getting Started in API Pen-Testing from APIsec University with Teresa Pereira
If you’re curious about diving into API security and want to learn how to test APIs like a pro, you’re in the right place. The Getting Started in API Pen-Testing course by Teresa Pereira breaks down everything you need to know from the basics of common API attack methods to hands-on testing tips. You’ll get... Continue Reading →
What do I think of the Building Security into AI from APIsec University with Robert Herbig
As AI becomes a bigger part of our apps and systems, it’s also becoming a new target for cyber threats. This course, Building Security into AI is all about helping you understand where those risks come from and what you can actually do about them. Taught by Robert Herbig an experienced AI practitioner and security... Continue Reading →
What do I think of the API Security Fundamentals from APIsec University with Dan Barahona
Just finished the API Security Fundamentals course from APIsec University with Dan Barahona and it was packed with solid insights. Coming from the hacking side I usually focus on how to break things, but this course gave me a broader view of why APIs are such attractive targets and how attackers actually approach them. My... Continue Reading →
What do I think of the API Product Management Masterclass from APIsec University with Erik Wilde, Mike Amundsen, Audrey Kolski, Jeremy Glassenberg, Ilona Koren-Deutsch and Gabrielle Botbol
APIs do a lot more than just move data they’re a big part of how modern products work. This free learning path is a solid intro to how APIs are planned, designed, documented and kept secure. It is made for people who are new to API product roles or just want to better understand how... Continue Reading →
What do I think of the API Security in DevSecOps from APIsec University with Scott Bly
APIs are everywhere and so are the risks. If you're working in DevOps or dev teams and want to build more secure apps the API Security in the World of DevSecOps course from APIsec University is a solid place to start. It’s free, practical and perfect for anyone looking to bring security into their development... Continue Reading →
What do I think of the Hacking Enterprises 2025 Edition course from In.Security with Will Hunt?
Offensive security courses are everywhere these days, but very few truly deliver a deep, hands-on experience that feels like the real deal. I recently completed the Hacking Enterprises 2025 Edition course from In.Security, led by Will Hunt, and after taking it twice now, I’m excited to share what makes this course stand out. Personal Experience... Continue Reading →
Securing LLM & NLP APIs: Lessons from APIuniversity
Securing LLM & NLP APIs: Lessons from APIuniversity As the use of large language models (LLMs) and generative AI continues to grow, so does the importance of understanding how to secure these technologies effectively. Recently, I completed the Securing LLM & NLP APIs course from APIuniversity, an essential training that arms developers, data scientists, and... Continue Reading →
What do I think of passing the ASCP exam from Apisec University
Passing the ASCP (API Security Certified Professional) exam is a notable achievement for anyone in the field of API security. APIsec University provides a structured and comprehensive approach to prepare for this challenging exam, and I can vouch for its effectiveness. Here are my thoughts on the experience and some advice for future candidates.Sign up... Continue Reading →
What do I think of Practical Bug Bounty course from TCM Security with Heath Adam, Alex Olsen, and Jonah Burgess from Intigriti
The Practical Bug Bounty course by TCM Security, led by Heath Adams, Alex Olsen, and Jonah Burgess from Intigriti, is a thorough exploration of hacking and web application security. Alex's extensive knowledge and Heath's significant community contributions are evident throughout the course. Despite its focus on bug bounty hunting, the course offers a wide range... Continue Reading →
What do I think of Practical Web Hacking course from TCM Security with Alex Olsen
Web security is an ever-evolving field, requiring continuous learning and adaptation. TCM's course "Practical Web Hacking," led by the exceptional instructor Alex Olsen, is designed to equip cybersecurity enthusiasts and professionals with hands-on knowledge and skills to tackle real-world web security challenges. This blog post delves into what this course offers, who should consider enrolling,... Continue Reading →
What do I think of API Authentication course from APIsec University with Jacob Ideskog from Curity
In the ever-evolving landscape of digital interactions, ensuring secure communication between clients and servers is paramount. API authentication and authorization are fundamental concepts that protect sensitive data and ensure that only authorized users can access specific resources. In this blog post, we will explore key aspects of API authentication and authorization, drawing insights from the... Continue Reading →
What do I think of Practical API Hacking Testing course from TCM Security with Alex Olsen
Hi! As someone who has recently completed the Practical API Hacking Testing course from TCM Security, taught by Alex Olsen, I wanted to share my thoughts and experiences. This course is designed to provide comprehensive knowledge and practical skills for testing and securing APIs, an increasingly critical area in cybersecurity. As a final word I... Continue Reading →