WEBINAR

Defending APIs with Jim Manico

November 10, 2022 | 9am PST | 5pm BST

Webinar Series - Defending APIs with Jim Manico

Watch the Webinar

Join Jim Manico, CEO of Manicode and Colin Domoney from 42Crunch, as they deliver a 2-part webinar series to help developers better defend APIs.

Episode 1: Request Forgery on the Web - CSRF & SSRF

In this first episode Jim and Colin will discuss request forgery and how to prevent it. This technical talk is intended for the software developer who needs to build secure web applications and APIs. it will cover the two variants of request forgery —  client-side (CSRF) and server-side (SSRF).

  • CSRF is most widely associated with vulnerable web applications that trick a user in a client browser into submitting transactions they never intended to use in their current authenticated session. We will discuss historical CSRF attacks and investigate various well-proven defense strategies. For API developers we will investigate whether APIs are vulnerable to CSRF, and how to prevent it.
  • SSRF attacks allow a malicious client to trick a vulnerable server into submitting requests to an unintended location, typically by submitting malformed URLs in payloads and relying on vulnerabilities in the URL parsing code. We will discuss prevention strategies and examine some well-known examples. For API developers, we will investigate ways in which SSRF can be directed at vulnerable APIs and examine a few recent API breaches and the latest research.

Speakers

Colin Domoney 2

Colin Domoney

Developer Advocate & API Security Researcher

42Crunch

 

 

jimmanico BW

Jim Manico

CEO

Manicode Security

 

 

Webinar Partner

At Manicode Security 100% of their focus is teaching developers to write secure code. They bring a combination of passion, style and decades of research into all of their education offerings.

Partnered with: Manicode Security

Manicode Logo

Latest Resources

BLOG

API Security-by-Design in the Age of Agentic AI: How 42Crunch is Refining Defense

By Jacques Declas | September 30, 2025

Agentic AI is reshaping the cyber threat landscape and APIs are fully in the cross-hairs as high-value targets. These intelligent, autonomous attack agents can identify, probe, and exploit API vulnerabilities at machine speed—making traditional, reactive defenses obsolete. In this new environment, organizations need proactive, automated, and deeply integrated […]

NEWS

42Crunch is a proud participant in the Microsoft Security Store Partner Ecosystem

By Newsdesk | September 30, 2025

San Francisco, CA — 09/30/2025 — 42Crunch today announced its inclusion in the Microsoft Security Store Partner Ecosystem. 42Crunch was selected based on their proven experience with Microsoft Security technologies, willingness to explore and provide feedback on cutting edge functionality, and close relationship with Microsoft. Welcoming the announcement, […]

DataSheet

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Secure Your APIs Today

#1 API security platform