Video yükleniyor...
Video Yüklenemedi
SSRF & Rate Limiting Bypass: How APIs Get Abused
83,277 görüntüleme • 9 ay önce •via X (Twitter)
36 Yorum

~> Rate limiting bypass • use IP+user+device+api key not just IP • slow down retries after each failures • use API gateway and Captcha when necessary (when high risk endpoints are involved)

This war is mostly between us backend devs. and hackers. 😭 Anyways, I note down some fixes. 👇 ~>SSRF • ensure you have a deny-list and allow-list • disable redirects to unknown domains • use network segmentation ...

Thanks a lot Chief, I always make sure to keep note 😂

Sharp

Someone will now wake up one day and say backend dev. is just CRUD. 😬 Na you know why you never turn on notification ooo. Not missing an episode from this series, hackers *gats respect me. 😂 Lemme go and ruminate over these for now. 🙂

Excellent educational content as always. Blocking internal metadata endpoints is non-negotiable these days. Appreciate you sharing this @AmosPikins 🙌

There's so much to learn

Anytime oga amos video pops up, i dey carry pen and paper 😂😂, you will learn something New, make i go tiff money register for your next cohort 🥲🥲

I love your videos

I like the fact that this is done is local language. Well done

Another suggestion is HMAC add signature to your endpoints especially if you're working with micro services and headless APIS Nice points chief.

Omo

Great content. Recently there was an hack on our server - I noticed some polyglot files (disguised as images). Although the attack was directed towards the wordpress sites also hosted on it. I now re-encode anything uploaded aside the previous MIME checks I was doing.

You just saved me thank you 😂

Do you know we are building this solution and your expertise will be valuable in this research. Modern infrastructure is defended by a stack that is fundamentally reactive: logs arrive after actions occur, detections trigger after damage begins, and response depends on human triage under time pressure. This architecture fails against AI-speed adversaries because the time constant of defense is dominated by people and brittle rules. We introduce Autonomous Defense Transformers (ADT), a security-native model class designed to reason over live infrastructure state, interpret threats under uncertainty, validate actions against explicit constraints, and produce auditable defense decisions. ADT is defined by five design principles: defense-first pretraining, continuous model-level reasoning, integrated actuation under constraints, zero-trust alignment, and guardrailed learning. We present an end-to-end architecture that separates context ingestion, threat interpretation, action validation, and audit generation, and we analyze why existing SIEM/SOAR/rule engines and “LLM wrapper” approaches are structurally insufficient for autonomous defense. We conclude with implications for enterprise resilience, regulatory enforcement, and national infrastructure security. Send me your email for the full paper and pls visit: to learn more. Our young researcher’s program is now open to everyone.

In a simple language, it’s called an open redirect

Frontend dev here, but I don't stop at the UI. I build the whole thing if needed—React interfaces, Node backends, database setup, deployment. Built a few full- stack web-app over the years. Ready for the next challenge. Open to freelance/contract work. DM if interested 💼

Thanks just implementated this both in server level and app level

We are expecting your response chief. Thank you.

@NkyEzenwa come here abeg na here e dey happen try follow amospikins for more cybersecurity tips e go give you joy like mad 😂

Omo I don turn on notifications for your matter my oga

Thank you 📚✍🏾

Thank you boss

Another one! Great video.

Super educative man Making me interested in hacking

Wawuuuuu... Thanks my boss

Cyber threat profiling

Damn. 😬😬

I’m learning a lot from your page, thank you 🙏

@TAIWOTOFUNMISON Well done bro, so apparently I am remediating same ssrf vulnerability, one of my client get over 100 instances with this vulnerability, imagine just as you mentioned them allow IMDSv1 with IMDSv2 as optional. I was able to upgrade 30% the rest needs code upgrade first….

use

Dope stuff

Thanks for this , learnt something new here

The way i dy follow u, I fit hold your leg 🦵 make you no leave. I just identify SSRF VULNERABILITY and fixing

Can WAF rules stop this attempt

Love this you content style chief
Benzer Videolar
DO NOT BE THIS GUY ❌ This is how you get used and abused.
Jedediah Bila
13,590 görüntüleme • 1 ay önce


