I do not know of any automated scanner that can test API security effectively without a security tester piloting it. I have had luck stubbing out API’s with very lean web UI’s and then threw web scanners at them with some luck.
-
-
@fvt are there integration level tests you can send through a proxy?0 proslijeđenih tweetova 1 korisnik označava da mu se sviđa -
looking for ideas, suggestions, etc etc So potentially anything is feasible
0 proslijeđenih tweetova 1 korisnik označava da mu se sviđa -
What I’ve seen work: - use a web front end to exercise the api and capture - run your test suite through a proxy to seed scanning activity - write your own api client scripts to test different scenarios (eg Authz) then also fun those through the proxy for seeding
6 replies 1 proslijeđeni tweet 10 korisnika označava da im se sviđa -
This is exactly the workflow that is supported by
@zaproxy1 reply 0 proslijeđenih tweetova 2 korisnika označavaju da im se sviđa -
Odgovor korisnicima @kingthorin_rm @mkonda i sljedećem broju korisnika:
Point being; configuration is needed as opposed to just point and shoot.
1 reply 0 proslijeđenih tweetova 1 korisnik označava da mu se sviđa -
Well I guess you could do either, but more config/specificity is always going to provider greater coverage or fewer false positives.
0 proslijeđenih tweetova 1 korisnik označava da mu se sviđa -
Odgovor korisnicima @kingthorin_rm @manicode i sljedećem broju korisnika:
It's a problem I've never really solved satisfactorily. Still too much messing about and always TOO MANY APIs!
1 reply 0 proslijeđenih tweetova 3 korisnika označavaju da im se sviđa -
Odgovor korisnicima @AppSecBloke @kingthorin_rm i sljedećem broju korisnika:
I tend to think the best way to point-and-shoot scan API’s is with SAST tools which of course have their own problems....
0 proslijeđenih tweetova 3 korisnika označavaju da im se sviđa -
Odgovor korisnicima @manicode @AppSecBloke i sljedećem broju korisnika:
At the risk of stating the obvious and pandering to your followers Jim, this is also a great reason for enhanced developer education*, clear requirements, tests including security and every pr security code reviewed. *I wonder who could help with that?pic.twitter.com/V30lgIC8is
1 reply 1 proslijeđeni tweet 4 korisnika označavaju da im se sviđa
I’m happy to see that developer security education is becoming the norm. Lot’s of great trainers out there including the Manicode team!
Thanks Matt!
cc’ing the Manicode team of trainers: @PhilippeDeRyck @ronperris @sec_tigger @georgiaweidman
-
-
0 replies 0 proslijeđenih tweetova 2 korisnika označavaju da im se sviđaHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
er.