hAPI_hacker
@hAPI_hacker
Followers
14K
Following
4K
Media
83
Statuses
1K
{ "name": "Corey J. Ball", "author": "Hacking APIs", "creator": "https://t.co/y3EHBlzHvJ", "is_admin": true }
Grants Pass, OR
Joined May 2020
๐ก ๐จ ๐ก ๐จ ๐ก ๐จ ๐ก ๐จ Since the release of Hacking APIs, I've wanted to create a way for you to demonstrate your API hacking skills to yourself and to others. I'd like to introduce you to the API Security Certified Professional (ASCP)!
12
56
517
"Burp AI can bring up a new generation of hackers faster and more effectively.โโโโโโ" In his new article, @hAPI_hacker explores how Burp AI: ๐ฌ Analyzes requests and adapts when attacks fail. ๐ฌ Explains findings in clear language. ๐ช Enhances human decision-making. ๐
portswigger.net
AI isnโt just reshaping cybersecurity - itโs challenging testers to rethink their entire playbook. In his latest article, โHacking with Burp AI in the Chesspocalypseโ, API expert Corey Ball draws less
1
5
44
You've learned SQL injection, but have you learned NoSQL injection? This learning path covers the detection, exploitation, and prevention of NoSQL injection vulnerabilities. Youโll learn: ๐ถ The core principles behind NoSQL injection and the different types of attacks. ๐ถ How
0
10
71
Somehow this old bug class keeps popping up in modern web apps! Path traversal is the gift that keeps on giving ๐ This learning path covers path traversal vulnerabilities, teaching you how to perform attacks, circumvent common obstacles, and prevent them in your applications.
0
8
53
Bug Bounty Tool: Kiterunner bruteforces API routes using contextual wordlists to uncover hidden endpoints fast: GitHub https://t.co/D6m5We4yMP
github.com
Contextual Content Discovery Tool. Contribute to assetnote/kiterunner development by creating an account on GitHub.
3
22
154
BONUS: Your ticket includes full access to: โ @APIdaysGlobal โ GenerationAI @GenerationAICon โ GreenIO Paris 2025 Four conferences, one ticket, zero cost Reserve now:
0
0
1
What you'll learn: - AI agent security - Practical API hacking techniques - Mobile app security deep dives - Deep dive into vibe-coded risks
1
0
1
The speaker lineup is absolutely stacked: Keynotes from hacker Chris Roberts and @isamauny Presentations and workshops by @Gabrielle_BGB @brentonhouse @PortSwigger @AikidoSecurity and @getpostman !
1
0
1
Hacking APIs Conference Paris is December 11th and it's completely FREE ๐ฏ with the code in this thread. Here's why you should be there ๐งต
1
0
1
Launching The Hab by @hapilabs_ai, a content hub for research, reflections, and real talk about cybersecurity. โ 1 Blog / month commitment ๐ฏ Fun, authentic, slightly unhinged ๐ค No AI slop, guaranteed First up: "Hacking with Burp AI in the Chesspocalypse" I explore our place
2
3
7
The details on the CVSS 9.9 request smuggling in Kestrel are finally out! Great find by @praetorianlabs. https://t.co/ej5QVIbm04
praetorian.com
Introduction Earlier this year, I earned a $10,000 bounty from Microsoft after discovering a critical HTTP request smuggling vulnerability in ASP.NET Coreโs Kestrel server (CVE-2025-55315). The...
2
70
275
starting in 10 mins!!! 1pm est get there and learn some amazing skills that can help you on the job search with @apollographql link below
Today's the day! ๐ Apollo GraphQL Workshop Part 1 starting in a few hours. Building MCP tools from scratch + optimizing for LLMs. ๐ 13:00 PM EST ๐ https://t.co/4RrD5kgwAs Still time to join! See you there ๐
4
1
8
Sharpen your API expertise at apidays Paris !ย This December, apidays introduces a new serie of in-person masterclasses : deep, hands-on learning sessions led by some of the most respected voices in the API community.ย Join @mamundย , @erikwilde, @fkilcommins, and @mgboydcom
1
1
8
๐ New Course Alert! ๐ MCP Security Fundamentals is completely FREE over at @apisecu . I had a lot of fun making this one. ๐ Vibe coded an MCP Server using Cursor for @apisec_ai ๐ Showed off the power of MCP servers ๐ Demonstrated how MCP security can go so wrong This
1
0
3
โ๏ธ Clever Cloud Enterprise Summit joins FOST Paris 2025! Dec 11 ยท CNIT FOREST ยท Paris La Dรฉfense With @clever_cloud, Carine Guillemet, & Clovis Carbone โ shaping the future of European cloud sovereignty & digital resilience. ๐๏ธ Join us โ https://t.co/mgHSOiaus2
#apidaysParis
2
1
3
I usually brute-force API paths with "Debug":true parameter and often it leads to reveal internal debug info to reverse proxies exposing API secrets and tokens.
13
87
966
Thinking of starting a career in cyber security? I've got you! โจ Join The Hacking Games and I for an AMA where I discuss how to get work ready in the tech field! https://t.co/Eus1T9A2xA
0
13
32
AI The Docs โ joins FOST Paris 2025! Dec 10 ยท CNIT FOREST ยท Paris La Dรฉfense One day. All about docs ร AI ร DX. Join the community shaping the future of developer experience. More info: https://t.co/bYomD9wjMp
#AITheDocs #FOSTParis #APIDocs #FutureOfSoftware
1
1
2