Workshop
API Security
Why the most expensive API flaws have no signature and how a team finds them itself.
An API is an interface through which programs talk to each other: an app asks, a service answers. A common security flaw arises when the service identifies the user but does not check access to a specific record. That is the doorman who checks every ID but never the guest list.
In the workshop, we systematically test roles, records and actions on your interfaces. We combine manual testing with suitable automation and derive concrete mitigations. The OWASP API Security Top 10 provide a reference for the attack classes covered.
You can run the most important test today, in three steps: create a second test user, put that user's record ID into the first user's request, and check the response. If the service hands out the other user's data, your interface has an authorisation flaw that no scanner with a signature list finds. The workshop turns this single move into a method for your entire estate.
Schedule
Agenda
Presentation plus hands-on exercises on a vulnerable example API: every attack class is first demonstrated and then tried out by the participants.
The OWASP API Security Top 10 at a glance
The ten categories in fast forward, with a focus on the three authorisation flaws BOLA, BOPLA and BFLA: why they head the list and why signature scanners structurally miss them.
Business logic as attack surface
Flaws that only exist in the context of your application: pricing logic, workflows, quantity limits. How to derive test cases from the domain.
Using OAuth 2.0 and OpenID Connect correctly
The typical mistakes with flows, token validation and scopes, and what the correct patterns look like.
API discovery and inventory
Finding shadow and zombie APIs: observing traffic, comparing specifications, keeping the inventory current.
What a gateway can enforce and what it cannot
Authentication, rate limiting and schema validation belong in the gateway, authorisation logic does not. Where the line runs and what that means for the architecture.
Continuous testing in the pipeline
Testing as a recurring part of delivery instead of an annual appointment: what can be automated and what stays manual work.
Going deeper
Reading list
The fundamentals to read up on, before or after the workshop.
- OWASP API Security Top 10 (opens in a new tab) OWASP · API Security Top 10, 2023
- BOLA: Broken Object Level Authorization (opens in a new tab) OWASP · API Security Top 10, 2023
Practicalities
Who it is for, what you bring, what you take away.
Dates and terms are agreed individually.
Contact
Request this workshop.
Write to us which group is to be trained and what should be different afterwards. You get a proposal for scope and schedule.