Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

SSRF & Rate Limiting Bypass: How APIs Get Abused

83,277 görüntüleme • 9 ay önce •via X (Twitter)

36 Yorum

Jethro Ayegbe profil fotoğrafı
Jethro Ayegbe9 ay önce

~> Rate limiting bypass • use IP+user+device+api key not just IP • slow down retries after each failures • use API gateway and Captcha when necessary (when high risk endpoints are involved)

Jethro Ayegbe profil fotoğrafı
Jethro Ayegbe9 ay önce

This war is mostly between us backend devs. and hackers. 😭 Anyways, I note down some fixes. 👇 ~>SSRF • ensure you have a deny-list and allow-list • disable redirects to unknown domains • use network segmentation ...

Chidile profil fotoğrafı
Chidile9 ay önce

Thanks a lot Chief, I always make sure to keep note 😂

The Tech Prophet (Amospikins) profil fotoğrafı
The Tech Prophet (Amospikins)9 ay önce

Sharp

Jethro Ayegbe profil fotoğrafı
Jethro Ayegbe9 ay önce

Someone will now wake up one day and say backend dev. is just CRUD. 😬 Na you know why you never turn on notification ooo. Not missing an episode from this series, hackers *gats respect me. 😂 Lemme go and ruminate over these for now. 🙂

Exploit-Forge profil fotoğrafı
Exploit-Forge9 ay önce

Excellent educational content as always. Blocking internal metadata endpoints is non-negotiable these days. Appreciate you sharing this @AmosPikins 🙌

__ken17th__ profil fotoğrafı
__ken17th__9 ay önce

There's so much to learn

Ade'Tayo Atanda 👑 profil fotoğrafı
Ade'Tayo Atanda 👑9 ay önce

Anytime oga amos video pops up, i dey carry pen and paper 😂😂, you will learn something New, make i go tiff money register for your next cohort 🥲🥲

IRIS ☘️👩🏼‍💻 profil fotoğrafı
IRIS ☘️👩🏼‍💻9 ay önce

I love your videos

Dream Chaser profil fotoğrafı
Dream Chaser9 ay önce

I like the fact that this is done is local language. Well done

I'm~dart~flutter~guy profil fotoğrafı
I'm~dart~flutter~guy9 ay önce

Another suggestion is HMAC add signature to your endpoints especially if you're working with micro services and headless APIS Nice points chief.

Gideon profil fotoğrafı
Gideon9 ay önce

Omo

Sadiq Salau profil fotoğrafı
Sadiq Salau9 ay önce

Great content. Recently there was an hack on our server - I noticed some polyglot files (disguised as images). Although the attack was directed towards the wordpress sites also hosted on it. I now re-encode anything uploaded aside the previous MIME checks I was doing.

P_kay🚀 profil fotoğrafı
P_kay🚀9 ay önce

You just saved me thank you 😂

David Idris profil fotoğrafı
David Idris9 ay önce

Do you know we are building this solution and your expertise will be valuable in this research. Modern infrastructure is defended by a stack that is fundamentally reactive: logs arrive after actions occur, detections trigger after damage begins, and response depends on human triage under time pressure. This architecture fails against AI-speed adversaries because the time constant of defense is dominated by people and brittle rules. We introduce Autonomous Defense Transformers (ADT), a security-native model class designed to reason over live infrastructure state, interpret threats under uncertainty, validate actions against explicit constraints, and produce auditable defense decisions. ADT is defined by five design principles: defense-first pretraining, continuous model-level reasoning, integrated actuation under constraints, zero-trust alignment, and guardrailed learning. We present an end-to-end architecture that separates context ingestion, threat interpretation, action validation, and audit generation, and we analyze why existing SIEM/SOAR/rule engines and “LLM wrapper” approaches are structurally insufficient for autonomous defense. We conclude with implications for enterprise resilience, regulatory enforcement, and national infrastructure security. Send me your email for the full paper and pls visit: to learn more. Our young researcher’s program is now open to everyone.

Black Magicc profil fotoğrafı
Black Magicc9 ay önce

In a simple language, it’s called an open redirect

RÕBØTĪÑÎÇ17👨‍💻🤖 profil fotoğrafı
RÕBØTĪÑÎÇ17👨‍💻🤖9 ay önce

Frontend dev here, but I don't stop at the UI. I build the whole thing if needed—React interfaces, Node backends, database setup, deployment. Built a few full- stack web-app over the years. Ready for the next challenge. Open to freelance/contract work. DM if interested 💼

Adike Kizito profil fotoğrafı
Adike Kizito9 ay önce

Thanks just implementated this both in server level and app level

5Point1Nexus profil fotoğrafı
5Point1Nexus9 ay önce

We are expecting your response chief. Thank you.

Dominic Microsoft Certified Trainer profil fotoğrafı
Dominic Microsoft Certified Trainer9 ay önce

@NkyEzenwa come here abeg na here e dey happen try follow amospikins for more cybersecurity tips e go give you joy like mad 😂

Joseph profil fotoğrafı
Joseph9 ay önce

Omo I don turn on notifications for your matter my oga

Christabel Aurora profil fotoğrafı
Christabel Aurora9 ay önce

Thank you 📚✍🏾

Mathew Oluwagbeminija Diamomndstar-MOD profil fotoğrafı
Mathew Oluwagbeminija Diamomndstar-MOD9 ay önce

Thank you boss

Baby Products & Markets profil fotoğrafı
Baby Products & Markets9 ay önce

Another one! Great video.

Mechanic 𝕏 profil fotoğrafı
Mechanic 𝕏9 ay önce

Super educative man Making me interested in hacking

Mace profil fotoğrafı
Mace9 ay önce

Wawuuuuu... Thanks my boss

dahmmy and 99 others profil fotoğrafı
dahmmy and 99 others9 ay önce

Cyber threat profiling

Sẹ́gun profil fotoğrafı
Sẹ́gun9 ay önce

Damn. 😬😬

Bambo | CloudFOrge profil fotoğrafı
Bambo | CloudFOrge9 ay önce

I’m learning a lot from your page, thank you 🙏

Moses profil fotoğrafı
Moses9 ay önce

@TAIWOTOFUNMISON Well done bro, so apparently I am remediating same ssrf vulnerability, one of my client get over 100 instances with this vulnerability, imagine just as you mentioned them allow IMDSv1 with IMDSv2 as optional. I was able to upgrade 30% the rest needs code upgrade first….

levleontyev profil fotoğrafı
levleontyev9 ay önce

use

Spending.js profil fotoğrafı
Spending.js9 ay önce

Dope stuff

Damollar profil fotoğrafı
Damollar9 ay önce

Thanks for this , learnt something new here

Darlington Kio profil fotoğrafı
Darlington Kio9 ay önce

The way i dy follow u, I fit hold your leg 🦵 make you no leave. I just identify SSRF VULNERABILITY and fixing

Elijah profil fotoğrafı
Elijah9 ay önce

Can WAF rules stop this attempt

Godwin profil fotoğrafı
Godwin9 ay önce

Love this you content style chief

Benzer Videolar