TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Demystifying API Attacks Using Gamification

2020-05-04 · Read original ↗

ATT&CK techniques detected

1 predictions
T1555.003Credentials from Web Browsers
42%
"google chrome app, postman. - weak tokens : json web token ( jwt ) has soared in popularity for use within apis for its ability to provide integrity. however, an implementation of jwt without a proper cryptographic signing mechanism can lead to privilege escalation. - credential …"

Summary

Learn about authentication, authorization, and security misconfiguration in API compromises by exploring this capture-the-flag game.