Загрузка видео...

Не удалось загрузить видео

На главную

SSRF & Rate Limiting Bypass: How APIs Get Abused

83,277 просмотров • 9 месяцев назад •via X (Twitter)

Комментарии: 36

Фото профиля Jethro Ayegbe
Jethro Ayegbe9 месяцев назад

~> Rate limiting bypass • use IP+user+device+api key not just IP • slow down retries after each failures • use API gateway and Captcha when necessary (when high risk endpoints are involved)

Фото профиля Jethro Ayegbe
Jethro Ayegbe9 месяцев назад

This war is mostly between us backend devs. and hackers. 😭 Anyways, I note down some fixes. 👇 ~>SSRF • ensure you have a deny-list and allow-list • disable redirects to unknown domains • use network segmentation ...

Фото профиля Chidile
Chidile9 месяцев назад

Thanks a lot Chief, I always make sure to keep note 😂

Фото профиля The Tech Prophet (Amospikins)
The Tech Prophet (Amospikins)9 месяцев назад

Sharp

Фото профиля Jethro Ayegbe
Jethro Ayegbe9 месяцев назад

Someone will now wake up one day and say backend dev. is just CRUD. 😬 Na you know why you never turn on notification ooo. Not missing an episode from this series, hackers *gats respect me. 😂 Lemme go and ruminate over these for now. 🙂

Фото профиля Exploit-Forge
Exploit-Forge9 месяцев назад

Excellent educational content as always. Blocking internal metadata endpoints is non-negotiable these days. Appreciate you sharing this @AmosPikins 🙌

Фото профиля __ken17th__
__ken17th__9 месяцев назад

There's so much to learn

Фото профиля Ade'Tayo Atanda 👑
Ade'Tayo Atanda 👑9 месяцев назад

Anytime oga amos video pops up, i dey carry pen and paper 😂😂, you will learn something New, make i go tiff money register for your next cohort 🥲🥲

Фото профиля IRIS ☘️👩🏼‍💻
IRIS ☘️👩🏼‍💻9 месяцев назад

I love your videos

Фото профиля Dream Chaser
Dream Chaser9 месяцев назад

I like the fact that this is done is local language. Well done

Фото профиля I'm~dart~flutter~guy
I'm~dart~flutter~guy9 месяцев назад

Another suggestion is HMAC add signature to your endpoints especially if you're working with micro services and headless APIS Nice points chief.

Фото профиля Gideon
Gideon9 месяцев назад

Omo

Фото профиля Sadiq Salau
Sadiq Salau9 месяцев назад

Great content. Recently there was an hack on our server - I noticed some polyglot files (disguised as images). Although the attack was directed towards the wordpress sites also hosted on it. I now re-encode anything uploaded aside the previous MIME checks I was doing.

Фото профиля P_kay🚀
P_kay🚀9 месяцев назад

You just saved me thank you 😂

Фото профиля David Idris
David Idris9 месяцев назад

Do you know we are building this solution and your expertise will be valuable in this research. Modern infrastructure is defended by a stack that is fundamentally reactive: logs arrive after actions occur, detections trigger after damage begins, and response depends on human triage under time pressure. This architecture fails against AI-speed adversaries because the time constant of defense is dominated by people and brittle rules. We introduce Autonomous Defense Transformers (ADT), a security-native model class designed to reason over live infrastructure state, interpret threats under uncertainty, validate actions against explicit constraints, and produce auditable defense decisions. ADT is defined by five design principles: defense-first pretraining, continuous model-level reasoning, integrated actuation under constraints, zero-trust alignment, and guardrailed learning. We present an end-to-end architecture that separates context ingestion, threat interpretation, action validation, and audit generation, and we analyze why existing SIEM/SOAR/rule engines and “LLM wrapper” approaches are structurally insufficient for autonomous defense. We conclude with implications for enterprise resilience, regulatory enforcement, and national infrastructure security. Send me your email for the full paper and pls visit: to learn more. Our young researcher’s program is now open to everyone.

Фото профиля Black Magicc
Black Magicc9 месяцев назад

In a simple language, it’s called an open redirect

Фото профиля RÕBØTĪÑÎÇ17👨‍💻🤖
RÕBØTĪÑÎÇ17👨‍💻🤖9 месяцев назад

Frontend dev here, but I don't stop at the UI. I build the whole thing if needed—React interfaces, Node backends, database setup, deployment. Built a few full- stack web-app over the years. Ready for the next challenge. Open to freelance/contract work. DM if interested 💼

Фото профиля Adike Kizito
Adike Kizito9 месяцев назад

Thanks just implementated this both in server level and app level

Фото профиля 5Point1Nexus
5Point1Nexus9 месяцев назад

We are expecting your response chief. Thank you.

Фото профиля Dominic Microsoft Certified Trainer
Dominic Microsoft Certified Trainer9 месяцев назад

@NkyEzenwa come here abeg na here e dey happen try follow amospikins for more cybersecurity tips e go give you joy like mad 😂

Фото профиля Joseph
Joseph9 месяцев назад

Omo I don turn on notifications for your matter my oga

Фото профиля Christabel Aurora
Christabel Aurora9 месяцев назад

Thank you 📚✍🏾

Фото профиля Mathew Oluwagbeminija Diamomndstar-MOD
Mathew Oluwagbeminija Diamomndstar-MOD9 месяцев назад

Thank you boss

Фото профиля Baby Products & Markets
Baby Products & Markets9 месяцев назад

Another one! Great video.

Фото профиля Mechanic 𝕏
Mechanic 𝕏9 месяцев назад

Super educative man Making me interested in hacking

Фото профиля Mace
Mace9 месяцев назад

Wawuuuuu... Thanks my boss

Фото профиля dahmmy and 99 others
dahmmy and 99 others9 месяцев назад

Cyber threat profiling

Фото профиля Sẹ́gun
Sẹ́gun9 месяцев назад

Damn. 😬😬

Фото профиля Bambo | CloudFOrge
Bambo | CloudFOrge9 месяцев назад

I’m learning a lot from your page, thank you 🙏

Фото профиля Moses
Moses9 месяцев назад

@TAIWOTOFUNMISON Well done bro, so apparently I am remediating same ssrf vulnerability, one of my client get over 100 instances with this vulnerability, imagine just as you mentioned them allow IMDSv1 with IMDSv2 as optional. I was able to upgrade 30% the rest needs code upgrade first….

Фото профиля levleontyev
levleontyev9 месяцев назад

use

Фото профиля Spending.js
Spending.js9 месяцев назад

Dope stuff

Фото профиля Damollar
Damollar9 месяцев назад

Thanks for this , learnt something new here

Фото профиля Darlington Kio
Darlington Kio9 месяцев назад

The way i dy follow u, I fit hold your leg 🦵 make you no leave. I just identify SSRF VULNERABILITY and fixing

Фото профиля Elijah
Elijah9 месяцев назад

Can WAF rules stop this attempt

Фото профиля Godwin
Godwin9 месяцев назад

Love this you content style chief

Похожие видео