Hand touching a digital interface labeled “API,” surrounded by charts and network icons.

Siemba Adds Automated Testing for API Access Flaws

The feature checks live APIs for authorization weaknesses that could let users view or change another person’s data.

Siemba has added automated insecure direct object reference (IDOR) checks to its API Security Testing capability.

The feature targets authorization flaws that can allow users to access or modify someone else’s data by changing an identifier in a request. It is available through the company’s platform, which tests application programming interfaces using REST, GraphQL and SOAP.

Testing begins with a customer’s API definition or collection and supplied identifiers. Siemba said the system generates tests for endpoints containing identifier parameters, examines API responses and provides steps for reproducing confirmed findings. Source code is not required.

This automation allows human penetration testers to handle more complex assessments, including chained attack paths and nuanced privilege boundaries.

About the Author

Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured

New Products

  • Cover image for IDP ProCare

    IDP ProCare™ Premium Support Program

    Minimize downtime and secure uninterrupted credential production with priority technical support, overnight advanced unit replacements, and proactive system health reviews.

  • Squire Vulcan Combination Padlocks

    Squire Locks USA Vulcan™ Resettable Combination Padlocks

    Stop competing with flimsy, retail-grade hardware—Squire's professional-grade resettable padlocks deliver heavy-duty boron steel shackles and front-facing dials for rugged outdoor environments.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.