Top Tweets for #SafeHack
ZAP Proxy was adopted as one of the tools @Geekulcha #SafeHack hackathon for web apps since 2017. Glad to see it as number 2.
Top 22 Web Application Hacking Tools

We use OWASP Top 10 as a basis for cyber security hackathons. OWASP ZAP also came in handy in the beginning of the journey with #SafeHack back in 2017.
๐ข๐ช๐๐ฆ๐ฃ ๐ง๐ผ๐ฝ ๐ญ๐ฌ ๐๐ฃ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฅ๐ถ๐๐ธ๐
Here is the list of the top 10 API security risks in 2023.
๐ญ. ๐๐ฟ๐ผ๐ธ๐ฒ๐ป ๐ข๐ฏ๐ท๐ฒ๐ฐ๐ ๐๐ฒ๐๐ฒ๐น ๐๐๐๐ต๐ผ๐ฟ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป - APIs tend to expose endpoints that handle object identifiers, creating a broad attack surface of Object Level Access Control issues.
๐ฎ. ๐๐ฟ๐ผ๐ธ๐ฒ๐ป ๐๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป - Authentication mechanisms are often implemented incorrectly, allowing attackers to compromise authentication tokens or exploit implementation flaws to temporarily or permanently assume other users' identities.
๐ฏ. ๐๐ฟ๐ผ๐ธ๐ฒ๐ป ๐ข๐ฏ๐ท๐ฒ๐ฐ๐ ๐ฃ๐ฟ๐ผ๐ฝ๐ฒ๐ฟ๐๐ ๐๐ฒ๐๐ฒ๐น ๐๐๐๐ต๐ผ๐ฟ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป - The lack of or improper authorization validation at the object property level.
๐ฐ. ๐จ๐ป๐ฟ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐๐ฒ๐ฑ ๐ฅ๐ฒ๐๐ผ๐๐ฟ๐ฐ๐ฒ ๐๐ผ๐ป๐๐๐บ๐ฝ๐๐ถ๐ผ๐ป - Satisfying API requests require network bandwidth, CPU, memory, and storage resources.
๐ฑ. ๐๐ฟ๐ผ๐ธ๐ฒ๐ป ๐๐๐ป๐ฐ๐๐ถ๐ผ๐ป ๐๐ฒ๐๐ฒ๐น ๐๐๐๐ต๐ผ๐ฟ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป - Complex access control policies with different hierarchies, groups, and roles, and an unclear separation between administrative and regular functions, tend to lead to authorization flaws.
๐ฒ. ๐จ๐ป๐ฟ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐๐ฒ๐ฑ ๐๐ฐ๐ฐ๐ฒ๐๐ ๐๐ผ ๐ฆ๐ฒ๐ป๐๐ถ๐๐ถ๐๐ฒ ๐๐๐๐ถ๐ป๐ฒ๐๐ ๐๐น๐ผ๐๐ - APIs vulnerable to this risk expose a business flow - such as posting a comment - without compensating for how the functionality could harm the business if used excessively in an automated manner.
๐ณ. ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฆ๐ถ๐ฑ๐ฒ ๐ฅ๐ฒ๐พ๐๐ฒ๐๐ ๐๐ผ๐ฟ๐ด๐ฒ๐ฟ๐ - Can occur when an API fetches a remote resource without validating the user-supplied URI.
๐ด. ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป - APIs and the systems supporting them typically contain complex configurations, meant to make the APIs more customizable.
๐ต. ๐๐บ๐ฝ๐ฟ๐ผ๐ฝ๐ฒ๐ฟ ๐๐ป๐๐ฒ๐ป๐๐ผ๐ฟ๐ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐บ๐ฒ๐ป๐ - APIs expose more endpoints than traditional web applications, making proper and updated documentation necessary.
๐ญ๐ฌ. ๐จ๐ป๐๐ฎ๐ณ๐ฒ ๐๐ผ๐ป๐๐๐บ๐ฝ๐๐ถ๐ผ๐ป ๐ผ๐ณ ๐๐ฃ๐๐ - Developers tend to trust data received from third-party APIs more than user input and adopt weaker security standards.
Check the details in the comments.
_______
If you like my posts, please follow me, @milan_milanovic, and hit the ๐ on my profile to get a notification for all my new posts.
Grow with me ๐!
#technology #softwareengineering #programming #techworldwithmilan #api

@iamkira420 Thatโs the #SafeHack hackathon coming up later on in July.
There is also the Security Summit Hackathon in June
.@Geekulcha gets a mention by @Startupgrind East London Chapter Director @VuyoNcwaiba for the #SafeHack hackathon.
Team #Cyberninjas were the 2021 edition winners

The importance of education in managing the cybersecurity skills shortage with Steve Jump
This reminds me of the work @Geekulcha does with #SafeHack and @ITWeb Security Summit Hackathon
#AfricaTechFestival

One of the ways @Geekulcha is playing itโs part in the skills gap is by hosting Cybersecurity hackathons like โฆ@ITWebโฉ Security Summit and #SafeHack
#SS22Hack https://t.co/thbWsdfFJf
Join us in congratulating our CIO, Ms @Keitu_Tsotetsi on being named one of the @mailandguardian Top 200 Young South African for 2021. #MG200Young
We commend her work and efforts in building information security skills onto local geeks through #SafeHack and others. ๐๐๐ ๐๐

Is your company/organisation POPIA ready?
Deadline is 30 June 2021
Missed the parallel sessions or couldn't attend all 3? We got you
Here is the THREAD to the recordings
1โฃSafeHack - Secure By Design Workshop by @InfoSecGrue & @Keitu_Tsotetsi
๐https://t.co/cVJhEfm005
#GKHack21 #Security #SafeHack
The OWASP Top 10
1. Injection
2. Broken Authentication
3. Sensitive Data Exposure
4. XML External Entities
5. Boken Access Control
#GKHack21 #Safehack #Owasp @Keitu_Tsotetsi
https://t.co/gA93Auz1dR
Are you a data scientist?
Learn about the ten most common
data science skills in job postings.
Source: Glassdoor
#datascience #safehack #careers


Uyaphi? reply as an African ๐
Malware!
We all know about what is malware?
Today, Let's learn about the
types of malware.
๐ง๐ต๐ฒ๐ฟ๐ฒ ๐ฎ๐ฟ๐ฒ ๐ต ๐๐๐ฝ๐ฒ๐ ๐ผ๐ณ ๐บ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ.
#malware #infosec #cybersecurity #safehack

Love to learn from Books?
Here are the top 4 books to
learn bug hunting.
You can get in-depth knowledge
of bug hunting through these books.
Learn More, Grow More ๐
Want to add any book?
Comment Below ๐
#cybersecurity #hacking #safehack #infosec #learning

Self Education!
Formal education is good but
using formal education as a
hiring filter is nonsense.
The approach of team-based and self
learning works better.
Thoughts?
#selflearning #learning #safehack #skilldevelopment


Do you know?
๐ฑ๐ฌ% ๐ผ๐ณ ๐๐๐ฒ๐ฟ๐ does not check whether the
link is authentic or not.
Do not make this mistake again, verify the
link before clicking or opening.
#cybersecurity #infosec #hacking #safehack #phishing

Last Seen Hashtags on Sotwe
เนเธญเธเนเธขเนเธเธเธฑเธ
Seen from Thailand
trampling
Seen from Greece
angeldust
Seen from Kuwait
เธฃเธฑเธเธเธฒเธเธจเธฃเธตเธเธเธฃเธดเธเธเธฃเน
Seen from Thailand
เธเธฑเธขเธเธฒเธเธเธฑเธเนเธขเนเธ
Seen from Thailand
malefarting
Seen from Germany
mandingo
Seen from Turkey
perliners
Seen from Canada
tanlines
Seen from United Kingdom
ethiopianfuck
Seen from Netherlands
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
109M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
86.8M followers

Taylor Swift 
@taylorswift13
80.6M followers

Lady Gaga 
@ladygaga
72.2M followers

Kim Kardashian 
@kimkardashian
69.4M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.6M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.1M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
59.9M followers








