Pen-testing Cloud REST APIs
DEF CON Workshops
Event description
Pen-testing Cloud REST APIs
Level of Instruction: Intermediate
Instructed by: Rodney Beede
Abstract:
This workshop will teach how to start pen testing a cloud REST API. Attendees should have a fundamental knowledge of OWASP Top 10 and web application security. Attendees will learn how to setup tools (i.e. Burp) and practice on a simulated cloud environment to discover vulnerabilities in cloud REST APIs. This includes attacks in authorization, XSS, and SQL injection. Technologies such as OpenStack, Salesforce, and Google Cloud will be covered.
Powered by
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity