Hand touching a digital interface labeled “API,” surrounded by charts and network icons.

Siemba Adds Automated Testing for API Access Flaws

The feature checks live APIs for authorization weaknesses that could let users view or change another person’s data.

Siemba has added automated insecure direct object reference (IDOR) checks to its API Security Testing capability.

The feature targets authorization flaws that can allow users to access or modify someone else’s data by changing an identifier in a request. It is available through the company’s platform, which tests application programming interfaces using REST, GraphQL and SOAP.

Testing begins with a customer’s API definition or collection and supplied identifiers. Siemba said the system generates tests for endpoints containing identifier parameters, examines API responses and provides steps for reproducing confirmed findings. Source code is not required.

This automation allows human penetration testers to handle more complex assessments, including chained attack paths and nuanced privilege boundaries.

About the Author

Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • GroundAware® GA1360LH 2D 360-Degree Radar

    Protect up to 750 acres with a single sensor, delivering extended 1 km+ target detection, all-weather tracking and automated intrusion deterrence for critical infrastructure.