Hand touching a digital interface labeled “API,” surrounded by charts and network icons.

Siemba Adds Automated Testing for API Access Flaws

The feature checks live APIs for authorization weaknesses that could let users view or change another person’s data.

Siemba has added automated insecure direct object reference (IDOR) checks to its API Security Testing capability.

The feature targets authorization flaws that can allow users to access or modify someone else’s data by changing an identifier in a request. It is available through the company’s platform, which tests application programming interfaces using REST, GraphQL and SOAP.

Testing begins with a customer’s API definition or collection and supplied identifiers. Siemba said the system generates tests for endpoints containing identifier parameters, examines API responses and provides steps for reproducing confirmed findings. Source code is not required.

This automation allows human penetration testers to handle more complex assessments, including chained attack paths and nuanced privilege boundaries.

About the Author

Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured

New Products

  • Cover image for IDP ProCare

    IDP ProCare™ Premium Support Program

    Minimize downtime and secure uninterrupted credential production with priority technical support, overnight advanced unit replacements, and proactive system health reviews.

  • Squire Vulcan Combination Padlocks

    Squire Locks USA Vulcan™ Resettable Combination Padlocks

    Stop competing with flimsy, retail-grade hardware—Squire's professional-grade resettable padlocks deliver heavy-duty boron steel shackles and front-facing dials for rugged outdoor environments.

  • ADI Control4 product image

    ADI Control4® X4 & Control4® Connect

    Drive long-term system value and reduce post-installation friction with a visually redesigned control interface paired with a secure, future-ready smart service framework.