<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>API on Daniyal Ahmed | Red Team &amp; Cloud Security</title><link>https://daniyalahmed.dev/tags/api/</link><description>Recent content in API on Daniyal Ahmed | Red Team &amp; Cloud Security</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</managingEditor><webMaster>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</webMaster><lastBuildDate>Sat, 02 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://daniyalahmed.dev/tags/api/index.xml" rel="self" type="application/rss+xml"/><item><title>API Pentesting Lab Setup ( Complete )</title><link>https://daniyalahmed.dev/posts/api-pentesting-lab-setup-complete/</link><pubDate>Sat, 02 May 2026 00:00:00 +0000</pubDate><author>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</author><guid>https://daniyalahmed.dev/posts/api-pentesting-lab-setup-complete/</guid><description>There is no better way to understand how API vulnerabilities work than to build a deliberately broken one and attack it yourself. This lab does exactly that. We set up a Flask API riddled with every major OWASP API Security Top 10 weakness, then systematically exploit each one using curl, Python scripts, Burp Suite, and jwt_tool. By the end you will have personally exploited SQL injection, broken object level authorization, JWT forgery, mass assignment, SSRF, and more all in a safe, isolated environment running on your own machine, no external setup required.</description></item></channel></rss>