// web · 01 / 08
API attack surface
More than REST URLs
Practice this only on a lab you own, or a program whose scope you have read.
An API exposes objects directly: the documented routes, the old versions still deployed, and what a mobile app calls.
Stay inside the written scope. The map is the list of routes, not a scan of someone else's network.
// check yourself
Why are APIs high-value for attackers?