National Cyber Warfare Foundation (NCWF) Forums


API Abuse Lessons from the Duolingo Data Scraping Attack


0 user ratings
2023-08-25 20:43:02
milo
Blue Team (CND)

 - archive -- 

It’s been reported that 2.6 million user records sourced from the Duolingo app are for sale. The attacker apparently obtained them from an open API provided by the company. There’s a more technical explanation available here.  While we talk a lot about the vulnerabilities in the OWASP API Top-10 and the exploits associated with those [...]


The post API Abuse – Lessons from the Duolingo Data Scraping Attack appeared first on Wallarm.


The post API Abuse – Lessons from the Duolingo Data Scraping Attack appeared first on Security Boulevard.



Tim Erlin

Source: Security Boulevard
Source Link: https://securityboulevard.com/2023/08/api-abuse-lessons-from-the-duolingo-data-scraping-attack/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.