Hand touching a digital interface labeled “API,” surrounded by charts and network icons.

Siemba Adds Automated Testing for API Access Flaws

The feature checks live APIs for authorization weaknesses that could let users view or change another person’s data.

Siemba has added automated insecure direct object reference (IDOR) checks to its API Security Testing capability.

The feature targets authorization flaws that can allow users to access or modify someone else’s data by changing an identifier in a request. It is available through the company’s platform, which tests application programming interfaces using REST, GraphQL and SOAP.

Testing begins with a customer’s API definition or collection and supplied identifiers. Siemba said the system generates tests for endpoints containing identifier parameters, examines API responses and provides steps for reproducing confirmed findings. Source code is not required.

This automation allows human penetration testers to handle more complex assessments, including chained attack paths and nuanced privilege boundaries.

About the Author

Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured

New Products