Wstg: Study of API Testing

Created on 5 Jun 2020  路  7Comments  路  Source: OWASP/wstg

What would you like to happen?
APIs come in different flavors, REST, SOAP, GraphQL, etc.
To simply say API Testing, that's a little bit ludicrous, and be broken down better. Issue #267 should adapt according to the plan that will be described in this issue.

What do you think? I believe this can handle a call, or maybe trying to plan it out and then combine our ideas in one thread to see what would work best.

Pinging the API Security team to get their feedback on this in order to have a well fleshed out plan
cc: @ErezYalon @PauloASilva @inonshk

enhancement help wanted

Most helpful comment

Nice one.

We (me and @dsopas) will present and discuss two GraphQL issues we've found recently as part of our DefCon AppSec Village talk: API (in)Security TOP 10: Guided tour to the Wild Wild World of APIs.

Since DefCon is in Safe Mode, you'll be able to watch this and all other talks at AppSec Village YouTube channel.

All 7 comments

Thanks for pinging.
I do agree we can do a better job breaking the API Testing per "API flavor".

Since GraphQL is getting lots of attention, I suggest starting with this one, followed by REST and SOAP. I think we should leave the door open to other flavors such as JSON-RPC, ...

What's the plan?

Cheers,
Paulo A. Silva

I agree with that, as GraphQL is the least documented attack vector between them as well.

What I have in mind is this:

  1. Create the issues, with priorities (GQL -> REST -> SOAP)
  2. Create an outline on the test scenario.
  3. Divide the work between the possible attack vectors for every scenario in order to be tackled by contributors (whether it was from our side, or yours, if it's of interest to you).

In the issue opened, we'll need to provide references so that a contributor is capable of understanding on what their scenario will be based on.

What do you think?

Work has started on the GraphQL Cheat Sheet.
Once that is done, I believe effort will come over to this side to write to the offensive part.

An attack that was disclosed just today on Twitter's GraphQL:
https://hackerone.com/reports/885539

Nice one.

We (me and @dsopas) will present and discuss two GraphQL issues we've found recently as part of our DefCon AppSec Village talk: API (in)Security TOP 10: Guided tour to the Wild Wild World of APIs.

Since DefCon is in Safe Mode, you'll be able to watch this and all other talks at AppSec Village YouTube channel.

Sounds lovely! Looking forward to it :)

Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Hsiang-Chih picture Hsiang-Chih  路  8Comments

jespunya picture jespunya  路  12Comments

kingthorin picture kingthorin  路  9Comments

cBiscuitSurprise picture cBiscuitSurprise  路  5Comments

victoriadrake picture victoriadrake  路  12Comments