Need More Sleep? REST Could Help

Presented at ToorCon San Diego 18 (2016), Oct. 16, 2016, 2 p.m. (20 minutes)

Increasingly, RESTful APIs are utilized to provide a communication avenue for web servers and clients to exchange data via HTTP(S). Historically SOAP APIs were used for this purpose however, implementation, client development, and documentation have been proved more complicated than that of REST. Further, REST provides a greater level of performance and scalability over SOAP, which adds to the benefits of using RESTful APIs. In this talk, key differences between SOAP and REST and core REST concepts will be discussed as well as testing methodologies and techniques that an analyst or developer could utilize to discover vulnerabilities within RESTful APIs. Burp Suite will be used to demonstrate testing when discussing focus areas of interests of a RESTful API, which will include authorization and input validation.


Presenters:

  • Drew Branch
    Drew Branch is an Associate Security Analyst for Independent Security Evaluators, where he is challenged with assessing Fortune 500 company’s implementations of security such as DRM systems, cryptography and secure configurations/development within mobile and web applications, etc. Mr. Branch holds a B.S. in Electrical/Computer Engineering from Morgan State University as well as a M.S. in Cybersecurity from the University of Maryland, Baltimore County. He is a cutting edge technology enthusiast with a passion for security in all aspects and is intrigued with how things work and how to break them.

Similar Presentations: