Тёмный

HakByte: How to use Postman to Reverse Engineer Private APIs 

Hak5
Подписаться 941 тыс.
Просмотров 76 тыс.
50% 1

Опубликовано:

 

5 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 71   
@danielm1359
@danielm1359 3 года назад
Amazing, reverse engineered a wireless controller the same way. It was a great way to start network automation.
@lazerusmfh
@lazerusmfh 3 года назад
Good timing. I need a simple integration to a device with an api without documentation, and this will definitely help!
@c0ri
@c0ri 2 года назад
Postman is awesome, been using it for a long time. It is extremely helpful writting code to interface APIs.. even if they are undocumented.
@finbom
@finbom Год назад
Thanks!!!! Amazing! Well worth spent 10 minutes to give me a MUCH better understanding. No fuzz, straight on with good examples and a working result.
@Belioyt
@Belioyt 3 года назад
Really enjoyed this, eyes are wide open for possibilities
@davidabba7663
@davidabba7663 19 дней назад
This was so understandable I think that’s what I was waiting for I feel much more confident on the vectors now or what to ask Bless you!
@oglothenerd
@oglothenerd Месяц назад
I am trying to learn this stuff so I can archive Netflix original series as local video files! I hate the fact that if Netflix decides to remove these series, they will no longer exist.
@cristianbam
@cristianbam 3 года назад
Why not just filter by XHR requests?
@janpost8598
@janpost8598 Год назад
Sometimes they put the data (like json) in the html code.
@robertfacella846
@robertfacella846 3 года назад
Using Runescape as the ideal case example, I see you
@drygordspellweaver8761
@drygordspellweaver8761 2 года назад
Do RuneScape API bots even work? Most I know use Ahk
@John_Smith__
@John_Smith__ 3 года назад
The entire header section is going to be used by ebay in this case to fingerprint the browsers. Should be anonymized. But I've noticed servers on ebay sometimes do not have all the required fields populated, that is a search like that will miss a Lot of servers simply because the seller does not fill in all data on the required description of the item.
@georgesmith9178
@georgesmith9178 Год назад
Really nice vid. Thumbs-up of course. Just a quick suggestion - bump up your font size a bit (on some screens it is hard to see) and use some sort of pointer tracking tool, so that people can see where you click. I had to go back a couple of times in several sections of the video to see where you were clicking.
@coder159
@coder159 Год назад
Please not the pointer tracking tool dear god
@firesnake6311
@firesnake6311 3 года назад
Oh yeah wait a minute Mr.postman hey ey ey ye Mr.postman
@uboxtech
@uboxtech Год назад
what to do about cors error? i tried this multiple times, checked all headers but still giving me cors error
@drygordspellweaver8761
@drygordspellweaver8761 2 года назад
Nice video- any resources on reversing a mobil app API?
@notamindninja2003
@notamindninja2003 3 месяца назад
Exactly like when a ho up in this house is taking too much of the pie and you need to take more from their available code so you can reverse engineer to thief back and take a higher position and more of your commission back- gig workers- get on that. They love to give opaque information but no helpful data. - Thanks for this-
@bukalter
@bukalter Год назад
I would like to use your method but I get error 401 meassage "Access denied due to missing subscription key. Make sure to include subscription key when making requests to an API." Is there some method to find it or use other way?
@BusinessIdeasHub
@BusinessIdeasHub 5 месяцев назад
Can you decompile an app and search api and can you use in postman? If yes then I'll send apk
@kizhissery
@kizhissery 2 года назад
to be frank the website you want most likely have cookies which changes in 12_24 hr , hence they will send 404
@sihmy9870
@sihmy9870 3 года назад
What is he wearing? Is that a mic?
@mmaranta785
@mmaranta785 3 года назад
Good info. Can I do that with C#?
@mamupelu565
@mamupelu565 3 года назад
What if there's a really shitty website and I want to make another one on top of it, just to use it as a database basically?
@dr.groove7957
@dr.groove7957 3 года назад
Brah, you need to hit up a boot camp.
@zuberkariye2299
@zuberkariye2299 3 года назад
Hey Micheal from the Security FWD
@bigbooduh
@bigbooduh Год назад
Enjoyed this, does Michael Raymond have any courses on api Hacking?
@Benedikt.05
@Benedikt.05 5 месяцев назад
want to create a zalando invoive scraper but I am completely new in that theme. Already checked that there is a specific link which triggers the download of the invoive. But I need an efficient way to scrape the ordernumbers and orderdates. Can I use the technique shown in the video to scrape those informations?
@SamoCoder
@SamoCoder 2 года назад
Great video. Liked and subscribed. Thanks.
@LeanneGrhymes
@LeanneGrhymes Год назад
does this work on websites that requires user log ins
@Rheaded
@Rheaded 5 месяцев назад
can i do this with safari and brave
@ryanrozario1195
@ryanrozario1195 2 года назад
Can we do the same thing for air tickets??
@ignaciokairuz
@ignaciokairuz Год назад
Great information!!
@statesponsored9435
@statesponsored9435 3 года назад
Wow great michael.
@gasparem16
@gasparem16 3 года назад
thanks! great video!!!
@shemmo
@shemmo 3 года назад
i like scraping sites but many times it can be illegal when you tap on the source with PII in it.. just saying, btw, nice tutorial
@zapbeeblebrox1053
@zapbeeblebrox1053 3 года назад
Maybe against terms of service but illegal? Not sure about that. The data is being delivered publicly. You can do what you want.
@kingsleyben297
@kingsleyben297 3 года назад
For this, You can search for *Hacklord Tom* a business page on fäcebóok.. he offers a wide range of hacking and spy services
@denissetiawan3645
@denissetiawan3645 3 года назад
Yummy yummy, time to scrape.
@evancunningham9872
@evancunningham9872 3 года назад
Very cool indeed.
@randyallen8610
@randyallen8610 Год назад
I need help scraping data from a website that has a firewall. Will pay
@TabletMini
@TabletMini 2 месяца назад
Just be careful to use the online version, as you might disclose sensitive information public.
@river1711
@river1711 3 года назад
Very cool!
@RohanVetale
@RohanVetale 7 месяцев назад
thankyouu
@midimusicforever
@midimusicforever 3 года назад
Cool. :)
@Pervy
@Pervy 3 года назад
Jason.
@mindyabiznarc
@mindyabiznarc 3 года назад
💯
@ismailachabi8627
@ismailachabi8627 Год назад
💚
@ca7986
@ca7986 3 года назад
👌
@ianp6742
@ianp6742 3 года назад
First
@DD_MN
@DD_MN 3 года назад
Second
@edoch3700
@edoch3700 3 года назад
Fourth
@xseflx
@xseflx 3 года назад
5
@harshdesai7957
@harshdesai7957 3 года назад
third
@saberint
@saberint 3 года назад
omfg you are claiming you are 'reverse engineering' lmfao, this is pathetic...
@Christian-mn8dh
@Christian-mn8dh 2 года назад
what is this then?
@saberint
@saberint 2 года назад
@@Christian-mn8dh it’s simply monitoring the results. It’s not giving you the code behind or data access layers. Sure it shows a how to *sniff* an api, but that’s it.
@Christian-mn8dh
@Christian-mn8dh 2 года назад
@@saberint interesting. im trynna learn reverse engineering, have any advice on how I should start? it's kinda hard to find a good structured education for this
@mandc20022
@mandc20022 3 года назад
This guy has very feminine qualities
@retiallc
@retiallc 3 года назад
He is wearing a pride shirt.
@CelesteOnYoutube
@CelesteOnYoutube 3 года назад
WTF is wrong with you people
@letsgetto1millwithoutvids
@letsgetto1millwithoutvids 3 года назад
I prefer web based APIs I only know how to use those types by loading the content into a variable and splitting the string by the values I want
Далее
Hacking APIs: Fuzzing 101
13:29
Просмотров 51 тыс.
Reverse Engineering Obfuscated JavaScript
14:04
Просмотров 153 тыс.
Песня РАСПУТИН на русском!🔥
00:56
Мои РОДИТЕЛИ - БОТАНЫ !
31:36
Просмотров 428 тыс.
Web Scraping + Reverse Engineering APIs
52:33
Просмотров 6 тыс.
How To Do Recon: API Enumeration
56:12
Просмотров 60 тыс.
Hacking/Reverse Engineering a PRIVATE api
6:35
Просмотров 108 тыс.
How To Hack APIs with Python
22:55
Просмотров 87 тыс.
Песня РАСПУТИН на русском!🔥
00:56