API Hacking Advanced
Course Description
Beyond REST. Learn to attack gRPC, WebSocket, SOAP, and microservice architectures.
Learning Objectives
- Exploit gRPC services
- Attack WebSocket connections
- Test SOAP web services
- Compromise microservice architectures
- Abuse API gateways
- Evade API security controls
Course Structure
Modules
Module 1: Advanced Protocols (5h)
- Protocol comparison
- gRPC basics
- WebSocket fundamentals
- SOAP/XML basics
Module 2: gRPC Exploitation (7h)
- Protobuf analysis
- Reflection abuse
- Method enumeration
- Message manipulation
Module 3: WebSocket Attacks (6h)
- Connection hijacking
- Message manipulation
- CSWSH attacks
- Authentication bypass
Module 4: SOAP/XML Attacks (6h)
- XML injection
- XXE exploitation
- WSDL analysis
- SOAP action manipulation
Module 5: Microservices (7h)
- Service mesh attacks
- Inter-service auth
- Container exploitation
- Service discovery abuse
Module 6: API Gateways (5h)
- Gateway enumeration
- Bypass techniques
- Rate limit evasion
- WAF bypass
Module 7: Event-Driven APIs (5h)
- Message queue attacks
- Kafka exploitation
- Event injection
- Subscription abuse
Module 8: Reporting (4h)
- API testing methodology
- Documentation
- Risk scoring
- Remediation
Tools
| Tool | Purpose |
|---|---|
| grpcurl | gRPC testing |
| Postman | API client |
| WSSiP | WebSocket proxy |
| SoapUI | SOAP testing |
📄️ Overview
Advanced API exploitation: gRPC, WebSocket, and microservice attacks