Workshop

API Security

Why the most expensive API flaws have no signature and how a team finds them itself.

An API is an interface through which programs talk to each other: an app asks, a service answers. A common security flaw arises when the service identifies the user but does not check access to a specific record. That is the doorman who checks every ID but never the guest list.

In the workshop, we systematically test roles, records and actions on your interfaces. We combine manual testing with suitable automation and derive concrete mitigations. The OWASP API Security Top 10 provide a reference for the attack classes covered.

Duration
1 day
Format
On site or remote
Group size
6 to 12 people
Language
German or English
The key point up front

You can run the most important test today, in three steps: create a second test user, put that user's record ID into the first user's request, and check the response. If the service hands out the other user's data, your interface has an authorisation flaw that no scanner with a signature list finds. The workshop turns this single move into a method for your entire estate.

Schedule

Agenda

Presentation plus hands-on exercises on a vulnerable example API: every attack class is first demonstrated and then tried out by the participants.

The OWASP API Security Top 10 at a glance

The ten categories in fast forward, with a focus on the three authorisation flaws BOLA, BOPLA and BFLA: why they head the list and why signature scanners structurally miss them.

Business logic as attack surface

Flaws that only exist in the context of your application: pricing logic, workflows, quantity limits. How to derive test cases from the domain.

Using OAuth 2.0 and OpenID Connect correctly

The typical mistakes with flows, token validation and scopes, and what the correct patterns look like.

API discovery and inventory

Finding shadow and zombie APIs: observing traffic, comparing specifications, keeping the inventory current.

What a gateway can enforce and what it cannot

Authentication, rate limiting and schema validation belong in the gateway, authorisation logic does not. Where the line runs and what that means for the architecture.

Continuous testing in the pipeline

Testing as a recurring part of delivery instead of an annual appointment: what can be automated and what stays manual work.

Going deeper

Reading list

The fundamentals to read up on, before or after the workshop.

Practicalities

Who it is for, what you bring, what you take away.

Audience API development, application security, platform teams, testers.
Prerequisites Basic knowledge of HTTP and REST, a laptop for the exercises. Prior security knowledge is not needed.
Outcome The team knows the testing methodology for authorisation flaws and has applied it on an example API itself.
Not included A pentest of your own interfaces. That can follow as a separate engagement, see Cybersecurity.

Dates and terms are agreed individually.

Contact

Request this workshop.

Write to us which group is to be trained and what should be different afterwards. You get a proposal for scope and schedule.

Request a date