API Security

1. API Endpoint Discovery:

2. API Authentication & Authorization Analysis:

3. Test for Broken Authentication (BA):

4. Test for Broken Access Control (BAC) & IDOR:

5. Test for Injection Vulnerabilities:

6. Test for Security Misconfigurations:

7. Test for Lack of Resources & Rate Limiting:

8. Test for Exposed Sensitive Data:

9. Test for Mass Assignment:

10. Test for Vulnerable Components:

11. Reporting & Documentation:

Last updated

Was this helpful?