Pentest Journeys
search
Ctrlk
Connectchevron-down
  • 👋 Welcome
  • Boxes
    • Categories
    • Starting Pointchevron-right
    • Easychevron-right
    • Mediumchevron-right
    • Hardchevron-right
    • Insanechevron-right
  • Cloudchevron-right
  • TL;DR
    • Active Directorychevron-right
    • Cloudchevron-right
    • External Platformschevron-right
    • Infrachevron-right
  • Logschevron-right
  • Networkingchevron-right
  • Pivotingchevron-right
  • Red Teamingchevron-right
  • Social Engineeringchevron-right
  • Webchevron-right
    • APIchevron-right
      • What is an API?
      • Useful Terms
      • Collection Creation
      • Enumeration
      • Testschevron-right
        • General
        • Security Headers
        • Security Misconfigurations
        • Authorizationchevron-right
        • Authenticationchevron-right
        • Excessive Data Exposure
        • HTTP Verb Tampering
        • Content Type Tampering
        • Improper Asset Management
        • Mass Assignment
        • SSRF
        • Unrestriced Resource Consumption
        • Unrestricted Access to Sensitive Business Flows
        • Unsafe API Consumption
      • Toolschevron-right
    • Applicationschevron-right
    • Common Findingschevron-right
    • Authenticationchevron-right
    • Authorizationchevron-right
    • CMSchevron-right
    • Cross-Originchevron-right
    • DevOpschevron-right
    • Dirbusting
    • File Inclusionchevron-right
    • File Uploadschevron-right
    • Frameworkschevron-right
    • Injectionschevron-right
    • Mass Assignment
    • Open Redirects
    • OpenFire
    • Race Conditions
    • SSRFchevron-right
    • WAFs
    • WebDAV
    • Web Serverschevron-right
    • WebSockets
    • Web Toolschevron-right
  • Tools
    • Hydra
    • Creds
    • Port Scanners
    • Passwordschevron-right
    • Searchsploit
    • Metasploitchevron-right
    • Wordlists
    • Vulnerability Scanners
    • Text Processing
    • Shells
    • File Transfers
    • Cryptography
    • Files
    • Steganography
    • KeePass
  • Traffic Capture
  • Package Managerschevron-right
  • Services
    • TCPchevron-right
    • UDPchevron-right
  • Methodologies
    • OSCPchevron-right
    • CRTP
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Webchevron-right
  2. API

Tests

Generalchevron-rightSecurity Headerschevron-rightSecurity Misconfigurationschevron-rightAuthorizationchevron-rightAuthenticationchevron-rightExcessive Data Exposurechevron-rightHTTP Verb Tamperingchevron-rightContent Type Tamperingchevron-rightImproper Asset Managementchevron-rightMass Assignmentchevron-rightSSRFchevron-rightUnrestriced Resource Consumptionchevron-rightUnrestricted Access to Sensitive Business Flowschevron-rightUnsafe API Consumptionchevron-right
PreviousEnumerationchevron-leftNextGeneralchevron-right

Last updated 1 year ago

Was this helpful?