APIs in the real world are huge, especially on large scope programs. In this video I share with you my top tools I use when testing and what I have in my toolbox. I tried to make this one short, but I really want to present a full methodology so you know what each tool does and how I use it to actually find bugs.
The Tools -
Recon: Amass, Lazyrecon, webscreenshot, BBHT
API Enumeration: Kiterunner, fuff, Axiom, TomNomNom Wordlist method, inQL
Vulnerabilities: Autorize, logger++, SQLMap, NoSQLMap, JWT_Tool, Burp
Social Media -
Discord: https://insiderphd.dev/discord
Patreon: / insiderphd
Twitter: / insiderphd