#lazyWeb #appsec
Has anyone tested/found any good tools for automating REST API security testing?
That you would recommend of course
Pls RT for reach
cc @dcuthbert @DinisCruz @securestep9 @Kerberosmansour
-
-
Odgovor korisnicima @FVT @dcuthbert i sljedećem broju korisnika:
I do not know of any automated scanner that can test API security effectively without a security tester piloting it. I have had luck stubbing out API’s with very lean web UI’s and then threw web scanners at them with some luck.
0 proslijeđenih tweetova 2 korisnika označavaju da im se sviđa -
@fvt are there integration level tests you can send through a proxy?0 proslijeđenih tweetova 1 korisnik označava da mu se sviđa -
The thing is: most scanners dont understand REST. When a POST to /docs/ redirects to /docs/572 and you then DELETE /docs/572, there is no point in throwing tons of attacks at /docs/572 (unless it fails to delete it, but that’s kind of beside the point)
1 reply 0 proslijeđenih tweetova 1 korisnik označava da mu se sviđa
Well , scanners don't understand the application's logic (which REST is part of it)
Amazing how event after all these years, APIs testing is not a solved problem
somebody should pick up the @O2Platform since key part of the solution is already there
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.