WEBINAR

Defending APIs with Jim Manico

November 10, 2022

Webinar Series - Defending APIs with Jim Manico

Watch the Webinar

Join Jim Manico, CEO of Manicode and Colin Domoney from 42Crunch, as they deliver a 2-part webinar series to help developers better defend APIs.

Episode 1: Request Forgery on the Web - CSRF & SSRF

In this first episode Jim and Colin will discuss request forgery and how to prevent it. This technical talk is intended for the software developer who needs to build secure web applications and APIs. it will cover the two variants of request forgery —  client-side (CSRF) and server-side (SSRF).

  • CSRF is most widely associated with vulnerable web applications that trick a user in a client browser into submitting transactions they never intended to use in their current authenticated session. We will discuss historical CSRF attacks and investigate various well-proven defense strategies. For API developers we will investigate whether APIs are vulnerable to CSRF, and how to prevent it.
  • SSRF attacks allow a malicious client to trick a vulnerable server into submitting requests to an unintended location, typically by submitting malformed URLs in payloads and relying on vulnerabilities in the URL parsing code. We will discuss prevention strategies and examine some well-known examples. For API developers, we will investigate ways in which SSRF can be directed at vulnerable APIs and examine a few recent API breaches and the latest research.

Speakers

Colin Domoney 2

Colin Domoney

Developer Advocate & API Security Researcher

42Crunch

 

 

jimmanico BW

Jim Manico

CEO

Manicode Security

 

 

Webinar Partner

At Manicode Security 100% of their focus is teaching developers to write secure code. They bring a combination of passion, style and decades of research into all of their education offerings.

Partnered with: Manicode Security

Manicode Logo

Latest Resources

BLOG

The State of API Security Report 2026

By Hugh Carroll | February 16, 2026

The State of API Security in 2026: Analysis of real-world API vulnerabilities Our recently published State of API Security Report 2026﹡ delivers a data-driven analysis of real-world API vulnerabilities, showing how common mistakes in implementation translate into security risks in production. It paints a clear and, at times, […]

NEWS

42Crunch Recognized by Enterprise Security Leaders as API Security Emerges as Critical AI control layer in State of AI Security Report

By Hugh Carroll | March 4, 2026

San Francisco, CA – March 4 2026 – 42Crunch, the API security platform company, today highlighted its growing visibility among enterprise security leaders following the release of the Sagetap State of AI in Cybersecurity Report 2026,  which analyzes real security buying initiatives from CISOs and senior security executives. The […]

DataSheet

Product Datasheet Addressing API Security Challenges

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Secure Your APIs Today

#1 API security platform