<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[I Red Team DEV - Red Teaming ]]></title>
		<link>https://ired.dev/</link>
		<description><![CDATA[I Red Team DEV - https://ired.dev]]></description>
		<pubDate>Tue, 04 Aug 2026 22:26:26 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Yankees Draft: Working day 1 investigate for the 2026 study course]]></title>
			<link>https://ired.dev/showthread.php?tid=192</link>
			<pubDate>Wed, 29 Jul 2026 08:20:32 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://ired.dev/member.php?action=profile&uid=407">RavenDantas</a>]]></dc:creator>
			<guid isPermaLink="false">https://ired.dev/showthread.php?tid=192</guid>
			<description><![CDATA[PHILADELPHIA, PA JULY 11: Commissioner of Greatest League Baseball Robert D. Manfred Jr. announces Hunter Dietz as the 35th total pick out via the Fresh new York Yankees through the 2026 MLB Draft offered by way of Nippon Categorical at Pennsylvania Conference Middle upon Saturday, July 11, 2026 within Philadelphia, Pennsylvania. Photograph by way of Rob TringaliMLB Shots as a result of Getty Visuals MLB Shots by way of Getty ImagesToday <a href="https://www.yankeesfannation.com/collections/johnny-damon-t-shirt" target="_blank" rel="noopener" class="mycode_url">Johnny Damon T-Shirt</a>, a great deal of wishes arrived correct. The Yankees ended up the genie in the direction of grant 4 of those people wants, producing the 35th, 63rd, 99th, and 127th decisions inside the 2026 Greatest League Baseball Yankees have been presented a 10destination penalty upon their firstround pick out mainly because they exceeded the leagues luxurious tax threshold. Regrettably, it was truly worth the be reluctant. As anyone who watches a large amount of Arkansas Razorback baseball, Ill say this was an uncomplicated determination for my favored Yankees final decision of the draft not simply just this calendar year, nonetheless within just several the 35th pick out, the Yankees picked out Hunter Dietz, a lefthanded pitcher versus Arkansas. For these unknown, the OmaHogs are in essence the college or university edition of Matt Blakes pitching manufacturing facility. Simply because 2019, the Razorbacks include experienced even further pitchers drafted than any other higher education application, with 30 previous towards this choice. Dietz presently joins Hagen Smith and Gage Wooden as Razorback pitchers chosen within just the to start with spherical within just 3 consecutive drafts. Transferring extra back again, 2 Cy Youngs consist of occur towards Arkansas as properly: Cliff Lee and Dallas is Terrific. Together with, truly, rather very good. Popularity 6foot6 and weighing 235 weight, his shipping and delivery and pitch incorporate remind me of a lefty Cam Schlittler. Thats the fashion of pitcher I imagine he may possibly turn into. If variables crack his direction healthwise he did comprise 2023 medical procedures for a tension fracture inside his elbow, I imagine his ceiling is surprisingly substantial, and countless evaluators believe that he could possibly go abruptly throughout the minorleague ranks. Dietz recorded 131 strikeouts, such as an SECbest 47 developed all those strikeouts with a fastball that sits within the mid90s and consists of touched 99 mph. That fastball contains the identical higher experience that can make Schlittler thus thriving, and he pairs it with a slider that tunnels off it just before breaking late. Dietz was a firstteam AllSEC preference, a semifinalist for the two the Golden Spikes Award and Dick Howser Trophy <a href="https://www.yankeesfannation.com/" target="_blank" rel="noopener" class="mycode_url">Yankees T-Shirt Jerseys</a>, and a secondteam AllAmerican. I dont notice irrespective of whether there was some slot gaming included, still the Yankees getting to be this model of upside at No. 35 is extraordinary just the minute spherical, with the 63rd pick out, the Yankees chosen a different southpaw inside Sean Duncan out of Terry Fox Secondary Faculty inside British Columbia. A Canadian prep product or service who basically grew to become 18 within just Might, Duncan incorporates been pitching within Canadas Nationwide Staff members application due to the fact getting old out of Very little League. The Vanderbilt invest experienced been growing draft discussion boards prior to an elbow destruction finished his spring research imply Duncan would desire towards rehab his alreadycompleted Tommy John surgical procedure with the company that drafts him. If that is the circumstance, it could be a despite the fact that right before we look at him upon the mound, yet Blake and the Yankees?participant progress workers will consist of an likelihood in the direction of operate with a more youthful pitcher who currently fills up the hit zone with a reduced90s fastball and several offspeed pitches. Substantial college decisions often convey the chance of honoring a faculty enthusiasm, nonetheless the Yankees need to seem to be guaranteed within their electric power toward signal Duncan absent versus the very last select right before triple digits, the Yankees decided on catcher Brendan Brock out of the School of Oklahoma. Brock used 1 period with the Sooners as soon as participating in the preceding a few decades at Southwestern Illinois Higher education in just one matter I found out all through my period in just faculty sporting activities was by no means in the direction of depend out a genuine JUCO grinder. Brock, a righthanded hitting catcher, strike 13 residence operates, drove inside 55 operates, and stole 28 bases this further than period When serving to Oklahoma get its very first College or university International Sequence within just 32 several years. This boy or girl is a legit athlete who flashes additionally ability and tempo, despite the fact that hell require in direction of minimize down upon the strikeouts as he climbs the well-informed their fourth and top amount upon Working day 1, the Yankees went again towards the JUCO move effectively and picked out righthanded hitter Paul GutierrezContreras II. GutierrezContreras transferred toward Cal Region Fullerton soon after starting up his collegiate vocation at Modesto Junior last period, the 20yearold adopted a constructive summer season within just the woodbat Northwoods League as a result of slashing.346.441.633 although generating Huge West CoPlayer of the 12 months honors. Recognized for not putting on batting gloves at the plate, GutierrezContreras will by now feel towards commence his progress inside of the Yankees?course of after Working day 1, the Yankees contain arrive absent with a few of lefthanded pitchers and 2 righthanded hitting prior JUCO items. The draft normally feels which includes the fantastic year toward open up the home windows <a href="https://www.yankeesfannation.com/collections/cam-schlittler-t-shirt" target="_blank" rel="noopener" class="mycode_url">Cam Schlittler T-Shirt</a>, enable inside of some contemporary air, and aspiration around what may well day 2 turns into underway tomorrow at 11:30 a.m. ET, with all of Rounds 520 upon MearnsStarJul 12PollPinstripe AlleyHow would your self quality the Yankees x27; very first working day of the MLB Draft?Spherical 1: Hunter Dietz; Spherical 2: Sean Duncan; Spherical 3: Brendan Brock; Spherical 4: Paul GutierrezContreras IIClosed ?96 over-all votesA47%B41%C6%D4%F2%Rec 0CommentsThin Stroke Remark Icon BubbleReplyRead 8 repliesTTommy StokkeStarJul 11PollPinstripe AlleyGrade the Yankees range of Hunter Dietz with the 35th opt for within just the MLB DraftClosed ?89 sum votesA70%B24%C7%D0%F0%Rec 0CommentsThin Stroke Remark Icon BubbleReplyRead 6 replies]]></description>
			<content:encoded><![CDATA[PHILADELPHIA, PA JULY 11: Commissioner of Greatest League Baseball Robert D. Manfred Jr. announces Hunter Dietz as the 35th total pick out via the Fresh new York Yankees through the 2026 MLB Draft offered by way of Nippon Categorical at Pennsylvania Conference Middle upon Saturday, July 11, 2026 within Philadelphia, Pennsylvania. Photograph by way of Rob TringaliMLB Shots as a result of Getty Visuals MLB Shots by way of Getty ImagesToday <a href="https://www.yankeesfannation.com/collections/johnny-damon-t-shirt" target="_blank" rel="noopener" class="mycode_url">Johnny Damon T-Shirt</a>, a great deal of wishes arrived correct. The Yankees ended up the genie in the direction of grant 4 of those people wants, producing the 35th, 63rd, 99th, and 127th decisions inside the 2026 Greatest League Baseball Yankees have been presented a 10destination penalty upon their firstround pick out mainly because they exceeded the leagues luxurious tax threshold. Regrettably, it was truly worth the be reluctant. As anyone who watches a large amount of Arkansas Razorback baseball, Ill say this was an uncomplicated determination for my favored Yankees final decision of the draft not simply just this calendar year, nonetheless within just several the 35th pick out, the Yankees picked out Hunter Dietz, a lefthanded pitcher versus Arkansas. For these unknown, the OmaHogs are in essence the college or university edition of Matt Blakes pitching manufacturing facility. Simply because 2019, the Razorbacks include experienced even further pitchers drafted than any other higher education application, with 30 previous towards this choice. Dietz presently joins Hagen Smith and Gage Wooden as Razorback pitchers chosen within just the to start with spherical within just 3 consecutive drafts. Transferring extra back again, 2 Cy Youngs consist of occur towards Arkansas as properly: Cliff Lee and Dallas is Terrific. Together with, truly, rather very good. Popularity 6foot6 and weighing 235 weight, his shipping and delivery and pitch incorporate remind me of a lefty Cam Schlittler. Thats the fashion of pitcher I imagine he may possibly turn into. If variables crack his direction healthwise he did comprise 2023 medical procedures for a tension fracture inside his elbow, I imagine his ceiling is surprisingly substantial, and countless evaluators believe that he could possibly go abruptly throughout the minorleague ranks. Dietz recorded 131 strikeouts, such as an SECbest 47 developed all those strikeouts with a fastball that sits within the mid90s and consists of touched 99 mph. That fastball contains the identical higher experience that can make Schlittler thus thriving, and he pairs it with a slider that tunnels off it just before breaking late. Dietz was a firstteam AllSEC preference, a semifinalist for the two the Golden Spikes Award and Dick Howser Trophy <a href="https://www.yankeesfannation.com/" target="_blank" rel="noopener" class="mycode_url">Yankees T-Shirt Jerseys</a>, and a secondteam AllAmerican. I dont notice irrespective of whether there was some slot gaming included, still the Yankees getting to be this model of upside at No. 35 is extraordinary just the minute spherical, with the 63rd pick out, the Yankees chosen a different southpaw inside Sean Duncan out of Terry Fox Secondary Faculty inside British Columbia. A Canadian prep product or service who basically grew to become 18 within just Might, Duncan incorporates been pitching within Canadas Nationwide Staff members application due to the fact getting old out of Very little League. The Vanderbilt invest experienced been growing draft discussion boards prior to an elbow destruction finished his spring research imply Duncan would desire towards rehab his alreadycompleted Tommy John surgical procedure with the company that drafts him. If that is the circumstance, it could be a despite the fact that right before we look at him upon the mound, yet Blake and the Yankees?participant progress workers will consist of an likelihood in the direction of operate with a more youthful pitcher who currently fills up the hit zone with a reduced90s fastball and several offspeed pitches. Substantial college decisions often convey the chance of honoring a faculty enthusiasm, nonetheless the Yankees need to seem to be guaranteed within their electric power toward signal Duncan absent versus the very last select right before triple digits, the Yankees decided on catcher Brendan Brock out of the School of Oklahoma. Brock used 1 period with the Sooners as soon as participating in the preceding a few decades at Southwestern Illinois Higher education in just one matter I found out all through my period in just faculty sporting activities was by no means in the direction of depend out a genuine JUCO grinder. Brock, a righthanded hitting catcher, strike 13 residence operates, drove inside 55 operates, and stole 28 bases this further than period When serving to Oklahoma get its very first College or university International Sequence within just 32 several years. This boy or girl is a legit athlete who flashes additionally ability and tempo, despite the fact that hell require in direction of minimize down upon the strikeouts as he climbs the well-informed their fourth and top amount upon Working day 1, the Yankees went again towards the JUCO move effectively and picked out righthanded hitter Paul GutierrezContreras II. GutierrezContreras transferred toward Cal Region Fullerton soon after starting up his collegiate vocation at Modesto Junior last period, the 20yearold adopted a constructive summer season within just the woodbat Northwoods League as a result of slashing.346.441.633 although generating Huge West CoPlayer of the 12 months honors. Recognized for not putting on batting gloves at the plate, GutierrezContreras will by now feel towards commence his progress inside of the Yankees?course of after Working day 1, the Yankees contain arrive absent with a few of lefthanded pitchers and 2 righthanded hitting prior JUCO items. The draft normally feels which includes the fantastic year toward open up the home windows <a href="https://www.yankeesfannation.com/collections/cam-schlittler-t-shirt" target="_blank" rel="noopener" class="mycode_url">Cam Schlittler T-Shirt</a>, enable inside of some contemporary air, and aspiration around what may well day 2 turns into underway tomorrow at 11:30 a.m. ET, with all of Rounds 520 upon MearnsStarJul 12PollPinstripe AlleyHow would your self quality the Yankees x27; very first working day of the MLB Draft?Spherical 1: Hunter Dietz; Spherical 2: Sean Duncan; Spherical 3: Brendan Brock; Spherical 4: Paul GutierrezContreras IIClosed ?96 over-all votesA47%B41%C6%D4%F2%Rec 0CommentsThin Stroke Remark Icon BubbleReplyRead 8 repliesTTommy StokkeStarJul 11PollPinstripe AlleyGrade the Yankees range of Hunter Dietz with the 35th opt for within just the MLB DraftClosed ?89 sum votesA70%B24%C7%D0%F0%Rec 0CommentsThin Stroke Remark Icon BubbleReplyRead 6 replies]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Advanced dork generator (AI)]]></title>
			<link>https://ired.dev/showthread.php?tid=36</link>
			<pubDate>Sun, 06 Jul 2025 21:07:44 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://ired.dev/member.php?action=profile&uid=2">Unix_Root</a>]]></dc:creator>
			<guid isPermaLink="false">https://ired.dev/showthread.php?tid=36</guid>
			<description><![CDATA[<a href="https://syntax.goldenowl.ai/" target="_blank" rel="noopener" class="mycode_url">https://syntax.goldenowl.ai/<!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://ired.dev/images/attachtypes/image.png" title="JPG Image" border="0" alt=".jpg" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=10" target="_blank" title="">516111888_24302351256119353_6576024617761025469_n.jpg</a> (Size: 27.33 KB / Downloads: 3)
<!-- end: postbit_attachments_attachment --></a>]]></description>
			<content:encoded><![CDATA[<a href="https://syntax.goldenowl.ai/" target="_blank" rel="noopener" class="mycode_url">https://syntax.goldenowl.ai/<!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://ired.dev/images/attachtypes/image.png" title="JPG Image" border="0" alt=".jpg" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=10" target="_blank" title="">516111888_24302351256119353_6576024617761025469_n.jpg</a> (Size: 27.33 KB / Downloads: 3)
<!-- end: postbit_attachments_attachment --></a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Automated Atomic Adversary Lab for Red Team Operations]]></title>
			<link>https://ired.dev/showthread.php?tid=20</link>
			<pubDate>Tue, 17 Jun 2025 21:12:16 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://ired.dev/member.php?action=profile&uid=2">Unix_Root</a>]]></dc:creator>
			<guid isPermaLink="false">https://ired.dev/showthread.php?tid=20</guid>
			<description><![CDATA[Link:<br />
<a href="https://bak3n3ko.medium.com/atomic-red-team-handbook-70ef1ef2f59a" target="_blank" rel="noopener" class="mycode_url">https://bak3n3ko.medium.com/atomic-red-t...ef1ef2f59a</a>]]></description>
			<content:encoded><![CDATA[Link:<br />
<a href="https://bak3n3ko.medium.com/atomic-red-team-handbook-70ef1ef2f59a" target="_blank" rel="noopener" class="mycode_url">https://bak3n3ko.medium.com/atomic-red-t...ef1ef2f59a</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[2025 Red Team Tools – C2 Frameworks, Active Directory & Network Exploitation]]></title>
			<link>https://ired.dev/showthread.php?tid=17</link>
			<pubDate>Tue, 17 Jun 2025 14:00:52 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://ired.dev/member.php?action=profile&uid=2">Unix_Root</a>]]></dc:creator>
			<guid isPermaLink="false">https://ired.dev/showthread.php?tid=17</guid>
			<description><![CDATA[Link:<br />
<a href="https://bishopfox.com/blog/2025-red-team-tools-c2-frameworks-active-directory-network-exploitation" target="_blank" rel="noopener" class="mycode_url">https://bishopfox.com/blog/2025-red-team...ploitation</a>]]></description>
			<content:encoded><![CDATA[Link:<br />
<a href="https://bishopfox.com/blog/2025-red-team-tools-c2-frameworks-active-directory-network-exploitation" target="_blank" rel="noopener" class="mycode_url">https://bishopfox.com/blog/2025-red-team...ploitation</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Hack APIs Like a Pro: A Comprehensive Guide]]></title>
			<link>https://ired.dev/showthread.php?tid=16</link>
			<pubDate>Mon, 16 Jun 2025 08:15:14 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://ired.dev/member.php?action=profile&uid=2">Unix_Root</a>]]></dc:creator>
			<guid isPermaLink="false">https://ired.dev/showthread.php?tid=16</guid>
			<description><![CDATA[In today's digital landscape, APIs (Application Programming Interfaces) are a vital part of applications. However, they are also prime targets for attackers. Here's a detailed post covering API security, bypass techniques, and how to defend against them.<br />
---<br />
1. Understanding API Vulnerabilities<br />
APIs often expose application logic and sensitive data, making them susceptible to several vulnerabilities. Here are some common API vulnerabilities:<br />
A. Broken Authentication<br />
APIs with flawed authentication mechanisms can allow attackers to impersonate legitimate users.<br />
Example: Missing or weak authentication tokens.<br />
Attack Scenario: Attacker intercepts an API request and reuses an old token to access resources.<br />
B. Rate Limiting Bypass<br />
APIs without proper rate limiting can be exploited to perform brute force attacks or DoS (Denial of Service).<br />
Example: Login endpoints without request throttling.<br />
Attack Scenario: Automated scripts try thousands of username/password combinations.<br />
C. Sensitive Data Exposure<br />
Poorly designed APIs might leak sensitive data like credentials, PII (Personally Identifiable Information), or system configurations.<br />
Example: API responses include sensitive fields such as passwords or API keys.<br />
Attack Scenario: Attacker views these fields in API responses to gain unauthorized access.<br />
---<br />
2. Bypass Techniques for APIs<br />
Here are common API bypass techniques attackers use and examples of how they work:<br />
A. Authentication Bypass Using JWT Tampering<br />
JWTs (JSON Web Tokens) are commonly used for API authentication. Improperly validated tokens can be tampered with.<br />
Example: A JWT payload:<br />
{<br />
  "user_id": 123,<br />
  "role": "user"<br />
}<br />
The attacker modifies it to:<br />
{<br />
  "user_id": 123,<br />
  "role": "admin"<br />
}<br />
Attack Scenario:<br />
1. The attacker modifies the JWT payload.<br />
2. If the signature validation is weak, the server accepts the tampered token.<br />
B. Rate Limiting Bypass with IP Rotation<br />
Technique: Use proxy tools to rotate IPs and bypass IP-based rate limiting.<br />
Tools: Tools like burp suite with Turbo Intruder can automate this.<br />
C. Exploiting Insufficient Input Validation<br />
Example:<br />
GET /user?id=123<br />
The attacker modifies the parameter to SQL injection payload:<br />
GET /user?id=123 OR 1=1<br />
Attack Scenario: The API fails to validate inputs and executes malicious queries.<br />
---<br />
3. Defense Strategies for Secure APIs<br />
Protecting APIs requires a multi-layered approach. Here’s how you can secure your APIs against common vulnerabilities:<br />
A. Strong Authentication and Authorization<br />
1. Use OAuth 2.0 and OpenID Connect: Implement token-based authentication.<br />
2. Validate JWTs Properly: Ensure the token’s signature and expiration date are checked.<br />
B. Implement Rate Limiting<br />
1. Throttle Requests: Limit the number of requests per IP.<br />
2. Use API Gateways: Tools like AWS API Gateway or Apigee help enforce rate limiting.<br />
C. Secure Data Handling<br />
1. Avoid Exposing Sensitive Data: Exclude fields like passwords and keys from API responses.<br />
2. Encrypt Data: Use TLS for data transmission.<br />
D. Input Validation and Sanitization<br />
1. Use Allowlists: Accept only known good inputs.<br />
2. Validate All Inputs: Use server-side validation to prevent injection attacks.<br />
E. Monitoring and Logging<br />
1. Log API Activities: Record all API requests and responses for auditing.<br />
2. Monitor for Anomalies: Use tools like WAFs (Web Application Firewalls) to detect unusual patterns.<br />
---<br />
4. Real-World Example: API Testing and Defense<br />
Scenario:<br />
An e-commerce API endpoint:<br />
POST /api/order<br />
{<br />
    "user_id": 123,<br />
    "product_id": 456,<br />
    "quantity": 2<br />
}<br />
Vulnerability: The API does not validate the user_id. An attacker modifies the request:<br />
{<br />
    "user_id": 789,<br />
    "product_id": 456,<br />
    "quantity": 2<br />
}<br />
The attacker places an order on behalf of another user.<br />
Defense:<br />
1. Validate the user_id against the authenticated user’s session.<br />
2. Use authorization middleware to enforce user access controls.<br />
---<br />
5. Tools to Strengthen API Security<br />
1. Postman: For API endpoint testing and validation.<br />
2. Burp Suite: For manual testing and vulnerability detection.<br />
3. OWASP ZAP: For automated security scans.<br />
4. ffuf: For fuzzing API endpoints.<br />
5. JWT.io: To decode and validate JWT tokens.<br />
---<br />
Conclusion<br />
API security is critical in modern application development. Ethical hackers and developers must stay vigilant, understand vulnerabilities, and implement robust defenses. Always think like an attacker to protect your systems effectively.<br />
What’s your favorite API testing tool? Let us know in the comments!`<br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://ired.dev/images/attachtypes/image.png" title="JPG Image" border="0" alt=".jpg" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=6" target="_blank" title="">506493416_735518915718843_6954188513551734564_n.jpg</a> (Size: 114.43 KB / Downloads: 5)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[In today's digital landscape, APIs (Application Programming Interfaces) are a vital part of applications. However, they are also prime targets for attackers. Here's a detailed post covering API security, bypass techniques, and how to defend against them.<br />
---<br />
1. Understanding API Vulnerabilities<br />
APIs often expose application logic and sensitive data, making them susceptible to several vulnerabilities. Here are some common API vulnerabilities:<br />
A. Broken Authentication<br />
APIs with flawed authentication mechanisms can allow attackers to impersonate legitimate users.<br />
Example: Missing or weak authentication tokens.<br />
Attack Scenario: Attacker intercepts an API request and reuses an old token to access resources.<br />
B. Rate Limiting Bypass<br />
APIs without proper rate limiting can be exploited to perform brute force attacks or DoS (Denial of Service).<br />
Example: Login endpoints without request throttling.<br />
Attack Scenario: Automated scripts try thousands of username/password combinations.<br />
C. Sensitive Data Exposure<br />
Poorly designed APIs might leak sensitive data like credentials, PII (Personally Identifiable Information), or system configurations.<br />
Example: API responses include sensitive fields such as passwords or API keys.<br />
Attack Scenario: Attacker views these fields in API responses to gain unauthorized access.<br />
---<br />
2. Bypass Techniques for APIs<br />
Here are common API bypass techniques attackers use and examples of how they work:<br />
A. Authentication Bypass Using JWT Tampering<br />
JWTs (JSON Web Tokens) are commonly used for API authentication. Improperly validated tokens can be tampered with.<br />
Example: A JWT payload:<br />
{<br />
  "user_id": 123,<br />
  "role": "user"<br />
}<br />
The attacker modifies it to:<br />
{<br />
  "user_id": 123,<br />
  "role": "admin"<br />
}<br />
Attack Scenario:<br />
1. The attacker modifies the JWT payload.<br />
2. If the signature validation is weak, the server accepts the tampered token.<br />
B. Rate Limiting Bypass with IP Rotation<br />
Technique: Use proxy tools to rotate IPs and bypass IP-based rate limiting.<br />
Tools: Tools like burp suite with Turbo Intruder can automate this.<br />
C. Exploiting Insufficient Input Validation<br />
Example:<br />
GET /user?id=123<br />
The attacker modifies the parameter to SQL injection payload:<br />
GET /user?id=123 OR 1=1<br />
Attack Scenario: The API fails to validate inputs and executes malicious queries.<br />
---<br />
3. Defense Strategies for Secure APIs<br />
Protecting APIs requires a multi-layered approach. Here’s how you can secure your APIs against common vulnerabilities:<br />
A. Strong Authentication and Authorization<br />
1. Use OAuth 2.0 and OpenID Connect: Implement token-based authentication.<br />
2. Validate JWTs Properly: Ensure the token’s signature and expiration date are checked.<br />
B. Implement Rate Limiting<br />
1. Throttle Requests: Limit the number of requests per IP.<br />
2. Use API Gateways: Tools like AWS API Gateway or Apigee help enforce rate limiting.<br />
C. Secure Data Handling<br />
1. Avoid Exposing Sensitive Data: Exclude fields like passwords and keys from API responses.<br />
2. Encrypt Data: Use TLS for data transmission.<br />
D. Input Validation and Sanitization<br />
1. Use Allowlists: Accept only known good inputs.<br />
2. Validate All Inputs: Use server-side validation to prevent injection attacks.<br />
E. Monitoring and Logging<br />
1. Log API Activities: Record all API requests and responses for auditing.<br />
2. Monitor for Anomalies: Use tools like WAFs (Web Application Firewalls) to detect unusual patterns.<br />
---<br />
4. Real-World Example: API Testing and Defense<br />
Scenario:<br />
An e-commerce API endpoint:<br />
POST /api/order<br />
{<br />
    "user_id": 123,<br />
    "product_id": 456,<br />
    "quantity": 2<br />
}<br />
Vulnerability: The API does not validate the user_id. An attacker modifies the request:<br />
{<br />
    "user_id": 789,<br />
    "product_id": 456,<br />
    "quantity": 2<br />
}<br />
The attacker places an order on behalf of another user.<br />
Defense:<br />
1. Validate the user_id against the authenticated user’s session.<br />
2. Use authorization middleware to enforce user access controls.<br />
---<br />
5. Tools to Strengthen API Security<br />
1. Postman: For API endpoint testing and validation.<br />
2. Burp Suite: For manual testing and vulnerability detection.<br />
3. OWASP ZAP: For automated security scans.<br />
4. ffuf: For fuzzing API endpoints.<br />
5. JWT.io: To decode and validate JWT tokens.<br />
---<br />
Conclusion<br />
API security is critical in modern application development. Ethical hackers and developers must stay vigilant, understand vulnerabilities, and implement robust defenses. Always think like an attacker to protect your systems effectively.<br />
What’s your favorite API testing tool? Let us know in the comments!`<br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://ired.dev/images/attachtypes/image.png" title="JPG Image" border="0" alt=".jpg" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=6" target="_blank" title="">506493416_735518915718843_6954188513551734564_n.jpg</a> (Size: 114.43 KB / Downloads: 5)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Pwning the Domain: Active directory]]></title>
			<link>https://ired.dev/showthread.php?tid=14</link>
			<pubDate>Sun, 15 Jun 2025 08:38:48 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://ired.dev/member.php?action=profile&uid=2">Unix_Root</a>]]></dc:creator>
			<guid isPermaLink="false">https://ired.dev/showthread.php?tid=14</guid>
			<description><![CDATA[Link:<br />
<a href="https://drive.google.com/file/d/1KJ0MzqECF80YFTeJS25QWk4ZNb5iUMfH/view?fbclid=IwY2xjawK7ZcxleHRuA2FlbQIxMQBicmlkETB1dnBkekhmbW9JMWU1ckV2AR7Q4PnMH7IiTpfYuNatKvKI7JV-77hxZTRUdLDMrfLmuU4mPhISDtmMb93AZg_aem_kUmKTfvqn7Ny_XGpusg3Zg" target="_blank" rel="noopener" class="mycode_url">https://drive.google.com/file/d/1KJ0MzqE..._XGpusg3Zg</a>]]></description>
			<content:encoded><![CDATA[Link:<br />
<a href="https://drive.google.com/file/d/1KJ0MzqECF80YFTeJS25QWk4ZNb5iUMfH/view?fbclid=IwY2xjawK7ZcxleHRuA2FlbQIxMQBicmlkETB1dnBkekhmbW9JMWU1ckV2AR7Q4PnMH7IiTpfYuNatKvKI7JV-77hxZTRUdLDMrfLmuU4mPhISDtmMb93AZg_aem_kUmKTfvqn7Ny_XGpusg3Zg" target="_blank" rel="noopener" class="mycode_url">https://drive.google.com/file/d/1KJ0MzqE..._XGpusg3Zg</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[A curated list of awesome search engines useful during Penetration testing.]]></title>
			<link>https://ired.dev/showthread.php?tid=8</link>
			<pubDate>Sat, 14 Jun 2025 10:33:45 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://ired.dev/member.php?action=profile&uid=2">Unix_Root</a>]]></dc:creator>
			<guid isPermaLink="false">https://ired.dev/showthread.php?tid=8</guid>
			<description><![CDATA[<a href="https://awesome-hacker-search-engines.com" target="_blank" rel="noopener" class="mycode_url">https://awesome-hacker-search-engines.com</a>]]></description>
			<content:encoded><![CDATA[<a href="https://awesome-hacker-search-engines.com" target="_blank" rel="noopener" class="mycode_url">https://awesome-hacker-search-engines.com</a>]]></content:encoded>
		</item>
	</channel>
</rss>