WEBINAR

Defending APIs with Jim Manico

November 10, 2022

Webinar Series - Defending APIs with Jim Manico

Watch the Webinar

Join Jim Manico, CEO of Manicode and Colin Domoney from 42Crunch, as they deliver a 2-part webinar series to help developers better defend APIs.

Episode 1: Request Forgery on the Web - CSRF & SSRF

In this first episode Jim and Colin will discuss request forgery and how to prevent it. This technical talk is intended for the software developer who needs to build secure web applications and APIs. it will cover the two variants of request forgery —  client-side (CSRF) and server-side (SSRF).

  • CSRF is most widely associated with vulnerable web applications that trick a user in a client browser into submitting transactions they never intended to use in their current authenticated session. We will discuss historical CSRF attacks and investigate various well-proven defense strategies. For API developers we will investigate whether APIs are vulnerable to CSRF, and how to prevent it.
  • SSRF attacks allow a malicious client to trick a vulnerable server into submitting requests to an unintended location, typically by submitting malformed URLs in payloads and relying on vulnerabilities in the URL parsing code. We will discuss prevention strategies and examine some well-known examples. For API developers, we will investigate ways in which SSRF can be directed at vulnerable APIs and examine a few recent API breaches and the latest research.

Speakers

Colin Domoney 2

Colin Domoney

Developer Advocate & API Security Researcher

42Crunch

 

 

jimmanico BW

Jim Manico

CEO

Manicode Security

 

 

Webinar Partner

At Manicode Security 100% of their focus is teaching developers to write secure code. They bring a combination of passion, style and decades of research into all of their education offerings.

Partnered with: Manicode Security

Manicode Logo

Latest Resources

BLOG

Vibe Coding Has a Security Debt Problem. Here’s How to Stop Inheriting It.

By Hugh Carroll | June 30, 2026

The numbers surrounding AI coding agents are no longer theoretical. A recent article from The Next Web investigating the Lovable breach suggests that between 40 and 62% of AI-generated code contains security vulnerabilities — and is being generated at 2.74 times the rate of human-written code. In Q1 […]

NEWS

42Crunch and GitHub Copilot Bring Deterministic API Security Guardrails to Agentic DevSecOps

By Hugh Carroll | June 16, 2026

Breakthrough integration enables real-time detection and remediation of API vulnerabilities in AI-driven development workflows at machine speed   San Francisco, CA — June 16, 2026 — 42Crunch, the leading API security platform for the agentic era, today announced the availability of the 42Crunch API Security Testing Plugin for […]

DataSheet

Product Datasheet Addressing API Security Challenges

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Secure Your APIs Today

#1 API security platform