Dana Epp  

@danaepp@infosec.exchange
419 Followers
108 Following
411 Posts
Builder and Breaker of code. Microsoft Security MVP focused on security (de)engineering.
Websitehttps://danaepp.com
Twitterhttps://twitter.com/danaepp
LinkedInhttps://www.linkedin.com/in/danaepp/

Looks like I’m a finalist for β€œAPI Security Person of the Year”. Like my articles and research? I’d appreciate your vote.

https://www.linkedin.com/posts/coreyjball_the-api-security-person-of-the-year-finalists-activity-7276021618643030016-5sqI?utm_source=share&utm_medium=member_ios

Corey J. Ball on LinkedIn: 🌟 The API Security Person of the Year Finalists Are Here! 🌟 πŸŽ‰ We’re…

🌟 The API Security Person of the Year Finalists Are Here! 🌟 πŸŽ‰ We’re thrilled to announce the ASPY finalists: βœ… Dana Epp βœ… Katie Paxton-Fear βœ… Kishor…

Let me show you how to stay professionally detached from the vulnerabilities you discover and disclose as part of your security research.

https://danaepp.com/staying-professionally-detached-from-your-security-research

Staying "professionally detached" from your security research

Learn how to stay professionally detached from the vulnerabilities you discover and disclose as part of your security research.

Dana Epp's Blog

Learn why shadow APIs sometimes provide a defenseless path for threat actors, and learn what YOU can do about it.

https://danaepp.com/why-shadow-apis-provide-a-defenseless-path-for-threat-actors

Why Shadow APIs provide a defenseless path for threat actors

Learn why shadow APIs sometimes provide a defenseless path for threat actors, and learn what YOU can do about it.

Dana Epp's Blog

Let's explore the latest book by Packt Publishing on "Pentesting APIs" and see if it's worth putting on an API hacker's bookshelf.

#apihacking #apisecurity

https://danaepp.com/is-the-latest-book-on-pentesting-apis-any-good

Is the latest book on "Pentesting APIs" any good?

Let's explore the latest book by Packt Publishing on "Pentesting APIs" and see if it's worth putting on an API hacker's bookshelf.

Dana Epp's Blog

Check out how to use upstream residential and mobile proxies in Burp Suite to evade IP blocking during your API security testing.

#apihacking #apisecurity

https://danaepp.com/evade-ip-blocking-by-using-residential-proxies

Evade IP blocking by using residential proxies

Learn how to use upstream residential and mobile proxies in Burp Suite to evade IP blocking during your API security testing.

Dana Epp's Blog

Let me show you how to cross-reference Known Exploit Vulnerabilities (KEV) against CWE to find the best attack vectors to use during security testing.

https://danaepp.com/kev-cwe-attack-vector

KEV + CWE = Attack Vector ❀️‍πŸ”₯

Learn how to cross-reference Known Exploit Vulnerabilities (KEV) against CWE to find the best attack vectors to use during security testing.

Dana Epp's Blog

Learn how to write exploits that take advantage of blind command injection vulnerabilities using a time-delayed boolean oracle attack.

https://danaepp.com/from-exploit-to-extraction-data-exfil-in-blind-rce-attacks

From Exploit to Extraction: Data Exfil in Blind RCE Attacks

Learn how to write exploits that take advantage of blind command injection vulnerabilities using a time-delayed boolean oracle attack.

Dana Epp's Blog

Let me show you how to use JSON injection to manipulate API payloads to control the flow of data and business logic within an API.

#apihacking #apisecurity

https://danaepp.com/attacking-apis-using-json-injection

Attacking APIs using JSON Injection

Learn how to use JSON injection to manipulate API payloads to control the flow of data and business logic within an API.

Dana Epp's Blog

Check out these five tips to help improve the API exploits you submit into security triage as part of your vulnerability research.

https://danaepp.com/5-tips-to-improve-your-api-exploits

5 tips to improve your API exploits

Learn five tips that help improve the API exploits you submit into security triage as part of your API security testing.

Dana Epp's Blog

Learn how to improve your API discovery with a custom Burp Suite extension dedicated to automatically finding API document artifacts for you.

https://danaepp.com/hacking-api-discovery-with-a-custom-burp-extension

Hacking API discovery with a custom Burp extension

Learn how to improve your API discovery with a custom Burp Suite extension dedicated to automatically finding API document artifacts for you.

Dana Epp's Blog