Loading video...

Video Failed to Load

Go Home

SSRF & Rate Limiting Bypass: How APIs Get Abused

83,277 views • 9 months ago •via X (Twitter)

36 Comments

Jethro Ayegbe's profile picture
Jethro Ayegbe9 months ago

~> Rate limiting bypass • use IP+user+device+api key not just IP • slow down retries after each failures • use API gateway and Captcha when necessary (when high risk endpoints are involved)

Jethro Ayegbe's profile picture
Jethro Ayegbe9 months ago

This war is mostly between us backend devs. and hackers. 😭 Anyways, I note down some fixes. 👇 ~>SSRF • ensure you have a deny-list and allow-list • disable redirects to unknown domains • use network segmentation ...

Chidile's profile picture
Chidile9 months ago

Thanks a lot Chief, I always make sure to keep note 😂

The Tech Prophet (Amospikins)'s profile picture
The Tech Prophet (Amospikins)9 months ago

Sharp

Jethro Ayegbe's profile picture
Jethro Ayegbe9 months ago

Someone will now wake up one day and say backend dev. is just CRUD. 😬 Na you know why you never turn on notification ooo. Not missing an episode from this series, hackers *gats respect me. 😂 Lemme go and ruminate over these for now. 🙂

Exploit-Forge's profile picture
Exploit-Forge9 months ago

Excellent educational content as always. Blocking internal metadata endpoints is non-negotiable these days. Appreciate you sharing this @AmosPikins 🙌

__ken17th__'s profile picture
__ken17th__9 months ago

There's so much to learn

Ade'Tayo Atanda 👑's profile picture
Ade'Tayo Atanda 👑9 months ago

Anytime oga amos video pops up, i dey carry pen and paper 😂😂, you will learn something New, make i go tiff money register for your next cohort 🥲🥲

IRIS ☘️👩🏼‍💻's profile picture
IRIS ☘️👩🏼‍💻9 months ago

I love your videos

Dream Chaser's profile picture
Dream Chaser9 months ago

I like the fact that this is done is local language. Well done

I'm~dart~flutter~guy's profile picture
I'm~dart~flutter~guy9 months ago

Another suggestion is HMAC add signature to your endpoints especially if you're working with micro services and headless APIS Nice points chief.

Gideon's profile picture
Gideon9 months ago

Omo

Sadiq Salau's profile picture
Sadiq Salau9 months ago

Great content. Recently there was an hack on our server - I noticed some polyglot files (disguised as images). Although the attack was directed towards the wordpress sites also hosted on it. I now re-encode anything uploaded aside the previous MIME checks I was doing.

P_kay🚀's profile picture
P_kay🚀9 months ago

You just saved me thank you 😂

David Idris's profile picture
David Idris9 months ago

Do you know we are building this solution and your expertise will be valuable in this research. Modern infrastructure is defended by a stack that is fundamentally reactive: logs arrive after actions occur, detections trigger after damage begins, and response depends on human triage under time pressure. This architecture fails against AI-speed adversaries because the time constant of defense is dominated by people and brittle rules. We introduce Autonomous Defense Transformers (ADT), a security-native model class designed to reason over live infrastructure state, interpret threats under uncertainty, validate actions against explicit constraints, and produce auditable defense decisions. ADT is defined by five design principles: defense-first pretraining, continuous model-level reasoning, integrated actuation under constraints, zero-trust alignment, and guardrailed learning. We present an end-to-end architecture that separates context ingestion, threat interpretation, action validation, and audit generation, and we analyze why existing SIEM/SOAR/rule engines and “LLM wrapper” approaches are structurally insufficient for autonomous defense. We conclude with implications for enterprise resilience, regulatory enforcement, and national infrastructure security. Send me your email for the full paper and pls visit: to learn more. Our young researcher’s program is now open to everyone.

Black Magicc's profile picture
Black Magicc9 months ago

In a simple language, it’s called an open redirect

RÕBØTĪÑÎÇ17👨‍💻🤖's profile picture
RÕBØTĪÑÎÇ17👨‍💻🤖9 months ago

Frontend dev here, but I don't stop at the UI. I build the whole thing if needed—React interfaces, Node backends, database setup, deployment. Built a few full- stack web-app over the years. Ready for the next challenge. Open to freelance/contract work. DM if interested 💼

Adike Kizito's profile picture
Adike Kizito9 months ago

Thanks just implementated this both in server level and app level

5Point1Nexus's profile picture
5Point1Nexus9 months ago

We are expecting your response chief. Thank you.

Dominic Microsoft Certified Trainer's profile picture
Dominic Microsoft Certified Trainer9 months ago

@NkyEzenwa come here abeg na here e dey happen try follow amospikins for more cybersecurity tips e go give you joy like mad 😂

Joseph's profile picture
Joseph9 months ago

Omo I don turn on notifications for your matter my oga

Christabel Aurora's profile picture
Christabel Aurora9 months ago

Thank you 📚✍🏾

Mathew Oluwagbeminija Diamomndstar-MOD's profile picture
Mathew Oluwagbeminija Diamomndstar-MOD9 months ago

Thank you boss

Baby Products & Markets's profile picture
Baby Products & Markets9 months ago

Another one! Great video.

Mechanic 𝕏's profile picture
Mechanic 𝕏9 months ago

Super educative man Making me interested in hacking

Mace's profile picture
Mace9 months ago

Wawuuuuu... Thanks my boss

dahmmy and 99 others's profile picture
dahmmy and 99 others9 months ago

Cyber threat profiling

Sẹ́gun's profile picture
Sẹ́gun9 months ago

Damn. 😬😬

Bambo | CloudFOrge's profile picture
Bambo | CloudFOrge9 months ago

I’m learning a lot from your page, thank you 🙏

Moses's profile picture
Moses9 months ago

@TAIWOTOFUNMISON Well done bro, so apparently I am remediating same ssrf vulnerability, one of my client get over 100 instances with this vulnerability, imagine just as you mentioned them allow IMDSv1 with IMDSv2 as optional. I was able to upgrade 30% the rest needs code upgrade first….

levleontyev's profile picture
levleontyev9 months ago

use

Spending.js's profile picture
Spending.js9 months ago

Dope stuff

Damollar's profile picture
Damollar9 months ago

Thanks for this , learnt something new here

Darlington Kio's profile picture
Darlington Kio9 months ago

The way i dy follow u, I fit hold your leg 🦵 make you no leave. I just identify SSRF VULNERABILITY and fixing

Elijah's profile picture
Elijah9 months ago

Can WAF rules stop this attempt

Godwin's profile picture
Godwin9 months ago

Love this you content style chief

Related Videos