HakByte: How to use Postman to Reverse Engineer Private APIs

Sdílet
Vložit
  • čas přidán 21. 07. 2024
  • In this episode we’ll show how to use Chrome or Firefox along with Postman to go from a website using a private API all the way to Python code.
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Our Site → www.hak5.org
    Shop → hakshop.myshopify.com/
    Subscribe → czcams.com/users/Hak5Darr...
    Support → / threatwire
    Contact Us → / hak5
    Threat Wire RSS → shannonmorse.podbean.com/feed/
    Threat Wire iTunes → itunes.apple.com/us/podcast/t...
    Host: Michael Raymond → / the_hoid
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
  • Věda a technologie

Komentáře • 68

  • @lazerusmfh
    @lazerusmfh Před 3 lety +9

    Good timing. I need a simple integration to a device with an api without documentation, and this will definitely help!

  • @finbom
    @finbom Před rokem +2

    Thanks!!!! Amazing! Well worth spent 10 minutes to give me a MUCH better understanding. No fuzz, straight on with good examples and a working result.

  • @danielm1359
    @danielm1359 Před 3 lety +18

    Amazing, reverse engineered a wireless controller the same way. It was a great way to start network automation.

  • @c0ri
    @c0ri Před rokem +6

    Postman is awesome, been using it for a long time. It is extremely helpful writting code to interface APIs.. even if they are undocumented.

  • @Belioyt
    @Belioyt Před 3 lety +12

    Really enjoyed this, eyes are wide open for possibilities

  • @uboxtech
    @uboxtech Před rokem +1

    what to do about cors error? i tried this multiple times, checked all headers but still giving me cors error

  • @bukalter
    @bukalter Před rokem +1

    I would like to use your method but I get error 401 meassage "Access denied due to missing subscription key. Make sure to include subscription key when making requests to an API." Is there some method to find it or use other way?

  • @cristianbam
    @cristianbam Před 3 lety +21

    Why not just filter by XHR requests?

    • @janpost8598
      @janpost8598 Před rokem +5

      Sometimes they put the data (like json) in the html code.

  • @John_Smith__
    @John_Smith__ Před 3 lety +4

    The entire header section is going to be used by ebay in this case to fingerprint the browsers. Should be anonymized. But I've noticed servers on ebay sometimes do not have all the required fields populated, that is a search like that will miss a Lot of servers simply because the seller does not fill in all data on the required description of the item.

  • @Benedikt.05
    @Benedikt.05 Před 3 měsíci

    want to create a zalando invoive scraper but I am completely new in that theme. Already checked that there is a specific link which triggers the download of the invoive. But I need an efficient way to scrape the ordernumbers and orderdates. Can I use the technique shown in the video to scrape those informations?

  • @BusinessIdeasHub
    @BusinessIdeasHub Před 3 měsíci

    Can you decompile an app and search api and can you use in postman? If yes then I'll send apk

  • @ryanrozario1195
    @ryanrozario1195 Před 2 lety

    Can we do the same thing for air tickets??

  • @user-di6yc8cr1k
    @user-di6yc8cr1k Před rokem

    does this work on websites that requires user log ins

  • @georgesmith9178
    @georgesmith9178 Před rokem +1

    Really nice vid. Thumbs-up of course. Just a quick suggestion - bump up your font size a bit (on some screens it is hard to see) and use some sort of pointer tracking tool, so that people can see where you click. I had to go back a couple of times in several sections of the video to see where you were clicking.

    • @coder159
      @coder159 Před rokem +1

      Please not the pointer tracking tool dear god

  • @mmaranta785
    @mmaranta785 Před 3 lety +1

    Good info. Can I do that with C#?

  • @mamupelu565
    @mamupelu565 Před 3 lety +1

    What if there's a really shitty website and I want to make another one on top of it, just to use it as a database basically?

  • @Rheaded
    @Rheaded Před 3 měsíci

    can i do this with safari and brave

  • @drygordspellweaver8761
    @drygordspellweaver8761 Před 2 lety +2

    Nice video- any resources on reversing a mobil app API?

  • @SamoCoder
    @SamoCoder Před 2 lety

    Great video. Liked and subscribed. Thanks.

  • @bigbooduh
    @bigbooduh Před rokem

    Enjoyed this, does Michael Raymond have any courses on api Hacking?

  • @gasparem16
    @gasparem16 Před 3 lety

    thanks! great video!!!

  • @notamindninja2003
    @notamindninja2003 Před měsícem

    Exactly like when a ho up in this house is taking too much of the pie and you need to take more from their available code so you can reverse engineer to thief back and take a higher position and more of your commission back- gig workers- get on that. They love to give opaque information but no helpful data. - Thanks for this-

  • @ignaciokairuz
    @ignaciokairuz Před rokem

    Great information!!

  • @sihmy9870
    @sihmy9870 Před 3 lety +2

    What is he wearing? Is that a mic?

  • @kizhissery
    @kizhissery Před rokem +2

    to be frank the website you want most likely have cookies which changes in 12_24 hr , hence they will send 404

  • @robertfacella846
    @robertfacella846 Před 2 lety +2

    Using Runescape as the ideal case example, I see you

  • @letsgetto1millwithoutvids

    I prefer web based APIs I only know how to use those types by loading the content into a variable and splitting the string by the values I want

  • @zuberkariye2299
    @zuberkariye2299 Před 3 lety

    Hey Micheal from the Security FWD

  • @firesnake6311
    @firesnake6311 Před 3 lety +4

    Oh yeah wait a minute Mr.postman hey ey ey ye Mr.postman

  • @river1711
    @river1711 Před 3 lety

    Very cool!

  • @statesponsored9435
    @statesponsored9435 Před 3 lety

    Wow great michael.

  • @evancunningham9872
    @evancunningham9872 Před 3 lety

    Very cool indeed.

  • @dr.groove7957
    @dr.groove7957 Před 3 lety +2

    Brah, you need to hit up a boot camp.

  • @randyallen8610
    @randyallen8610 Před rokem

    I need help scraping data from a website that has a firewall. Will pay

  • @shemmo
    @shemmo Před 3 lety

    i like scraping sites but many times it can be illegal when you tap on the source with PII in it.. just saying, btw, nice tutorial

    • @zapbeeblebrox1053
      @zapbeeblebrox1053 Před 3 lety +8

      Maybe against terms of service but illegal? Not sure about that. The data is being delivered publicly. You can do what you want.

    • @kingsleyben297
      @kingsleyben297 Před 3 lety +2

      For this, You can search for *Hacklord Tom* a business page on fäcebóok.. he offers a wide range of hacking and spy services

  • @denissetiawan3645
    @denissetiawan3645 Před 3 lety +1

    Yummy yummy, time to scrape.

  • @RohanVetale
    @RohanVetale Před 4 měsíci

    thankyouu

  • @midimusicforever
    @midimusicforever Před 3 lety +1

    Cool. :)

  • @mindyabiznarc
    @mindyabiznarc Před 3 lety

    💯

  • @Pervy
    @Pervy Před 3 lety +1

    Jason.

  • @ca7986
    @ca7986 Před 3 lety

    👌

  • @ismailachabi8627
    @ismailachabi8627 Před rokem

    💚

  • @xseflx
    @xseflx Před 3 lety

    5

  • @DD_MN
    @DD_MN Před 3 lety

    Second

  • @edoch3700
    @edoch3700 Před 3 lety

    Fourth

  • @harshdesai7957
    @harshdesai7957 Před 3 lety

    third

  • @ianp6742
    @ianp6742 Před 3 lety +1

    First

  • @saberint
    @saberint Před 3 lety +3

    omfg you are claiming you are 'reverse engineering' lmfao, this is pathetic...

    • @Christian-mn8dh
      @Christian-mn8dh Před rokem

      what is this then?

    • @saberint
      @saberint Před rokem

      @@Christian-mn8dh it’s simply monitoring the results. It’s not giving you the code behind or data access layers. Sure it shows a how to *sniff* an api, but that’s it.

    • @Christian-mn8dh
      @Christian-mn8dh Před rokem

      @@saberint interesting. im trynna learn reverse engineering, have any advice on how I should start? it's kinda hard to find a good structured education for this

  • @mandc20022
    @mandc20022 Před 3 lety +4

    This guy has very feminine qualities