API Penetration Testing
- Course Duration14 HRS
- Course LanguageArabic
What you'll learn
- Understand how REST, SOAP, and GraphQL APIs work under the hood
- Build a complete API testing lab with Burp Suite, Postman, and vulnerable apps
- Perform reconnaissance and enumerate hidden API endpoints
- Exploit the full OWASP API Security Top 10 in real scenarios
- Attack and bypass API authentication, including JWT-based flows
- Discover and exploit BOLA / IDOR and broken function-level authorization
- Test for injection, SSRF, and business logic vulnerabilities
- Test GraphQL APIs and abuse introspection and batching
- Automate testing with ffuf, OWASP ZAP, and Postman
- Write professional pentest reports and apply secure API best practices
APIs have become the backbone of modern applications, cloud services, and mobile apps — and with that ubiquity they have become one of the most heavily targeted attack surfaces in cybersecurity. This course delivers a comprehensive, hands-on approach to API penetration testing, taking you from understanding how APIs work all the way to discovering, exploiting, and securing their vulnerabilities.
Using controlled, intentionally vulnerable labs such as crAPI, VAmPI, and OWASP Juice Shop, you will learn how to enumerate endpoints, intercept and analyze traffic, and exploit the full OWASP API Security Top 10 — from Broken Object Level Authorization (BOLA) through broken authentication, JWT attacks, injection, SSRF, and business logic flaws. Every vulnerability is paired with its corresponding defense and remediation strategy.
By the end of this course, you will be able to perform a complete, professional penetration test against any API, write a structured report of findings and risks, and provide practical remediation guidance — walking away knowing both sides of the equation: attack and defense.
Disclaimer: This course is intended strictly for educational and authorised security testing purposes. All attacks are performed within isolated lab environments. Unauthorised use of any technique taught in this course is illegal and strictly prohibited.
Course content
01Welcome to the Course2 lectures
- Important Before You Start
- Course Roadmap & Objectives
02API Fundamentals8 lectures
- What Is an API?
- How the Web & HTTP Work
- HTTP Methods & Status Codes
- REST APIs Explained
- SOAP & RPC APIs
- GraphQL APIs Explained
- JSON & Data Formats
- API Authentication Models
03Building Your API Testing Lab8 lectures
- Introduction to Virtualization
- Setting Up Kali Linux
- Installing & Configuring Burp Suite
- Setting Up the Proxy
- Installing Postman
- Deploying the crAPI Vulnerable Lab
- Deploying VAmPI & OWASP Juice Shop
- Very Important
04API Reconnaissance & Discovery6 lectures
- Passive API Discovery
- Active Endpoint Enumeration
- Analyzing API Documentation
- Swagger / OpenAPI Inspection
- Discovering Hidden Endpoints via Fuzzing
- Mapping the Attack Surface
05Intercepting & Manipulating API Traffic4 lectures
- Capturing Requests with Burp
- Repeater & Intruder Basics
- Tampering with Parameters
- Working with API Tokens & Headers
06OWASP API Security Top 10 — Overview1 lectures
- Introduction to the OWASP API Top 10
07API1: Broken Object Level Authorization (BOLA)4 lectures
- Understanding BOLA / IDOR
- Exploiting Object IDs
- Accessing Other Users' Data
- Defending Against BOLA
08API2: Broken Authentication4 lectures
- Weak Authentication Flows
- Brute-Forcing API Credentials
- Bypassing Authentication
- Securing API Authentication
09Attacking JSON Web Tokens (JWT)5 lectures
- JWT Structure Explained
- The "none" Algorithm Attack
- Weak Secret & Signature Cracking
- JWT Tampering & Replay
- Securing JWT Implementations
10API3: Broken Object Property Level Authorization3 lectures
- Excessive Data Exposure
- Mass Assignment Attacks
- Defending Property-Level Access
11API4: Unrestricted Resource Consumption3 lectures
- Rate Limiting Weaknesses
- API Denial-of-Service & Flooding
- Implementing Rate Limits
12API5: Broken Function Level Authorization4 lectures
- Accessing Admin Functions
- HTTP Method Manipulation
- Privilege Escalation via APIs
- Enforcing Function-Level Access
13Injection Attacks in APIs4 lectures
- SQL Injection in APIs
- NoSQL Injection
- Command Injection
- Defending Against Injection
14API7: Server-Side Request Forgery (SSRF)4 lectures
- Understanding SSRF
- Exploiting SSRF in APIs
- Accessing Internal Services & Cloud Metadata
- Mitigating SSRF
15Testing GraphQL APIs4 lectures
- GraphQL Attack Surface
- Introspection & Schema Discovery
- GraphQL Injection & Abuse
- Batching & DoS Attacks
16API6, API8, API9 & API10: Remaining Risks4 lectures
- Unrestricted Access to Sensitive Business Flows
- Security Misconfiguration
- Improper Inventory Management
- Unsafe Consumption of Third-Party APIs
17Business Logic Vulnerabilities3 lectures
- Identifying Business Logic Flaws
- Exploiting Workflow Bypasses
- Race Conditions in APIs
18Automating API Testing4 lectures
- Using Postman Collections & Scripts
- Fuzzing APIs with ffuf
- Scanning with OWASP ZAP
- Useful API Testing Tools
19Reporting & Remediation3 lectures
- Writing a Professional Pentest Report
- Risk Rating & CVSS Scoring
- Remediation Best Practices
20API Security Best Practices (Defense)4 lectures
- Secure API Design Principles
- Authentication & Authorization Hardening
- Input Validation & Rate Limiting
- API Gateway & Monitoring
Requirements
- A computer with a virtualization-capable processor and at least 8GB RAM (16GB recommended)
- At least 40GB of free disk space for the lab environment
- Basic familiarity with HTTP and the web (helpful but not required)
- A stable internet connection to download tools and lab apps
Who this course is for
- Penetration testers and bug bounty hunters who want to specialise in API security
- Web and backend developers who want to build more secure APIs
- Cybersecurity professionals looking to expand into modern application security
- Students and beginners with basic web knowledge who want to enter API pentesting