Supported by Curity Logotype

Session

Hacking APIs: Understanding, Challenges, and Best Practices I

Roger Bergling 2025
Roger Bergling INVID Jönköping AB

This session, focused 70% on practical, hands-on demos and 30% on theory, will teach attendees how to identify and exploit common API vulnerabilities. The presentation covers key tools such as BurpSuite, Postman, and Kiterunner, and explores techniques for testing security features like rate limiting, JWT manipulation, and object-level authorization. Demos include live security testing with tools like mitmproxy for brute-force attacks and Hashcat for cracking JWT tokens. Attendees will leave with actionable skills to secure their own APIs and prevent real-world attacks.

Smarter Tech Decisions Using APIs

Smarter Tech Decisions Using APIs

API blog

High impact blog posts and eBooks on API business models, and tech advice

API conferences

Connect with market leading platform creators at our events

API community

Join a helpful community of API practitioners

API Insights Straight to Your Inbox!

Can't make it to the event? Signup to the Nordic APIs newsletter for quality content. High impact blog posts on API business models and tech advice.

By clicking below, you agree that we process your information per the terms in our Privacy Policy.

Join Our Thriving Community

Become a part of our global community of API practitioners and enthusiasts. Share your insights on the blog, speak at an event or exhibit at our conferences and create new business relationships with decision makers and top influencers responsible for API solutions.