Secrets and Lies: Exploring and Exploiting APIs That Are Undocumented, Underdocumented, or Misdocumented

Sometimes you find a service or website that serves up information that you want to use, and you want to automate your calls to it, but there’s no documentation, or whatever documentation exists is less than helpful or even wrong. This presentation will discuss and demonstrate some techniques and tools for experimenting with calling APIs to get the results you want. Tools mentioned may include curl, wget, jq, browser developer tools, Postman. Demonstration may be prerecorded for reliability and efficiency.


4:00 PM
20 minutes