Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

SSRF & Rate Limiting Bypass: How APIs Get Abused

83,277 Aufrufe • vor 9 Monaten •via X (Twitter)

36 Kommentare

Profilbild von Jethro Ayegbe
Jethro Ayegbevor 9 Monaten

~> Rate limiting bypass • use IP+user+device+api key not just IP • slow down retries after each failures • use API gateway and Captcha when necessary (when high risk endpoints are involved)

Profilbild von Jethro Ayegbe
Jethro Ayegbevor 9 Monaten

This war is mostly between us backend devs. and hackers. 😭 Anyways, I note down some fixes. 👇 ~>SSRF • ensure you have a deny-list and allow-list • disable redirects to unknown domains • use network segmentation ...

Profilbild von Chidile
Chidilevor 9 Monaten

Thanks a lot Chief, I always make sure to keep note 😂

Profilbild von The Tech Prophet (Amospikins)
The Tech Prophet (Amospikins)vor 9 Monaten

Sharp

Profilbild von Jethro Ayegbe
Jethro Ayegbevor 9 Monaten

Someone will now wake up one day and say backend dev. is just CRUD. 😬 Na you know why you never turn on notification ooo. Not missing an episode from this series, hackers *gats respect me. 😂 Lemme go and ruminate over these for now. 🙂

Profilbild von Exploit-Forge
Exploit-Forgevor 9 Monaten

Excellent educational content as always. Blocking internal metadata endpoints is non-negotiable these days. Appreciate you sharing this @AmosPikins 🙌

Profilbild von __ken17th__
__ken17th__vor 9 Monaten

There's so much to learn

Profilbild von Ade'Tayo Atanda 👑
Ade'Tayo Atanda 👑vor 9 Monaten

Anytime oga amos video pops up, i dey carry pen and paper 😂😂, you will learn something New, make i go tiff money register for your next cohort 🥲🥲

Profilbild von IRIS ☘️👩🏼‍💻
IRIS ☘️👩🏼‍💻vor 9 Monaten

I love your videos

Profilbild von Dream Chaser
Dream Chaservor 9 Monaten

I like the fact that this is done is local language. Well done

Profilbild von I'm~dart~flutter~guy
I'm~dart~flutter~guyvor 9 Monaten

Another suggestion is HMAC add signature to your endpoints especially if you're working with micro services and headless APIS Nice points chief.

Profilbild von Gideon
Gideonvor 9 Monaten

Omo

Profilbild von Sadiq Salau
Sadiq Salauvor 9 Monaten

Great content. Recently there was an hack on our server - I noticed some polyglot files (disguised as images). Although the attack was directed towards the wordpress sites also hosted on it. I now re-encode anything uploaded aside the previous MIME checks I was doing.

Profilbild von P_kay🚀
P_kay🚀vor 9 Monaten

You just saved me thank you 😂

Profilbild von David Idris
David Idrisvor 9 Monaten

Do you know we are building this solution and your expertise will be valuable in this research. Modern infrastructure is defended by a stack that is fundamentally reactive: logs arrive after actions occur, detections trigger after damage begins, and response depends on human triage under time pressure. This architecture fails against AI-speed adversaries because the time constant of defense is dominated by people and brittle rules. We introduce Autonomous Defense Transformers (ADT), a security-native model class designed to reason over live infrastructure state, interpret threats under uncertainty, validate actions against explicit constraints, and produce auditable defense decisions. ADT is defined by five design principles: defense-first pretraining, continuous model-level reasoning, integrated actuation under constraints, zero-trust alignment, and guardrailed learning. We present an end-to-end architecture that separates context ingestion, threat interpretation, action validation, and audit generation, and we analyze why existing SIEM/SOAR/rule engines and “LLM wrapper” approaches are structurally insufficient for autonomous defense. We conclude with implications for enterprise resilience, regulatory enforcement, and national infrastructure security. Send me your email for the full paper and pls visit: to learn more. Our young researcher’s program is now open to everyone.

Profilbild von Black Magicc
Black Magiccvor 9 Monaten

In a simple language, it’s called an open redirect

Profilbild von RÕBØTĪÑÎÇ17👨‍💻🤖
RÕBØTĪÑÎÇ17👨‍💻🤖vor 9 Monaten

Frontend dev here, but I don't stop at the UI. I build the whole thing if needed—React interfaces, Node backends, database setup, deployment. Built a few full- stack web-app over the years. Ready for the next challenge. Open to freelance/contract work. DM if interested 💼

Profilbild von Adike Kizito
Adike Kizitovor 9 Monaten

Thanks just implementated this both in server level and app level

Profilbild von 5Point1Nexus
5Point1Nexusvor 9 Monaten

We are expecting your response chief. Thank you.

Profilbild von Dominic Microsoft Certified Trainer
Dominic Microsoft Certified Trainervor 9 Monaten

@NkyEzenwa come here abeg na here e dey happen try follow amospikins for more cybersecurity tips e go give you joy like mad 😂

Profilbild von Joseph
Josephvor 9 Monaten

Omo I don turn on notifications for your matter my oga

Profilbild von Christabel Aurora
Christabel Auroravor 9 Monaten

Thank you 📚✍🏾

Profilbild von Mathew Oluwagbeminija Diamomndstar-MOD
Mathew Oluwagbeminija Diamomndstar-MODvor 9 Monaten

Thank you boss

Profilbild von Baby Products & Markets
Baby Products & Marketsvor 9 Monaten

Another one! Great video.

Profilbild von Mechanic 𝕏
Mechanic 𝕏vor 9 Monaten

Super educative man Making me interested in hacking

Profilbild von Mace
Macevor 9 Monaten

Wawuuuuu... Thanks my boss

Profilbild von dahmmy and 99 others
dahmmy and 99 othersvor 9 Monaten

Cyber threat profiling

Profilbild von Sẹ́gun
Sẹ́gunvor 9 Monaten

Damn. 😬😬

Profilbild von Bambo | CloudFOrge
Bambo | CloudFOrgevor 9 Monaten

I’m learning a lot from your page, thank you 🙏

Profilbild von Moses
Mosesvor 9 Monaten

@TAIWOTOFUNMISON Well done bro, so apparently I am remediating same ssrf vulnerability, one of my client get over 100 instances with this vulnerability, imagine just as you mentioned them allow IMDSv1 with IMDSv2 as optional. I was able to upgrade 30% the rest needs code upgrade first….

Profilbild von levleontyev
levleontyevvor 9 Monaten

use

Profilbild von Spending.js
Spending.jsvor 9 Monaten

Dope stuff

Profilbild von Damollar
Damollarvor 9 Monaten

Thanks for this , learnt something new here

Profilbild von Darlington Kio
Darlington Kiovor 9 Monaten

The way i dy follow u, I fit hold your leg 🦵 make you no leave. I just identify SSRF VULNERABILITY and fixing

Profilbild von Elijah
Elijahvor 9 Monaten

Can WAF rules stop this attempt

Profilbild von Godwin
Godwinvor 9 Monaten

Love this you content style chief

Ähnliche Videos