Manuals / API Testing / Chapter 9

D · Contracts · advanced · Week 7–8 · Chapter 9 of 11

OWASP API security smoke tests

API security is not optional. OWASP API Top 10 gives a checklist — broken auth, excessive data exposure, rate limits, injection.

Path progress
75%

Step 1 of 4

OWASP API Top 10 skim

Broken Object Level Authorization (BOLA/IDOR), broken auth, excessive data exposure, lack of rate limiting.

OWASP API Top 10 skimDrag stickies · tap for tips
Study mapDrag stickies · tap for tipsKeep it shortdrag · tap →Name the waitdrag · tap →Scope locatorsdrag · tap →Trace when stuckdrag · tap →One browser firstdrag · tap →Isolate statedrag · tap →Assert the UIdrag · tap →Retry wiselydrag · tap →Seed datadrag · tap →Close the loopdrag · tap →Keep it shortdrag · tap →Name the waitdrag · tap →Scope locatorsdrag · tap →Trace when stuckdrag · tap →One browser firstdrag · tap →Isolate statedrag · tap →Pathwise hackdrag · tap →OWASP API Top 10 sdrag · tap →Try thisdrag · tap →Follow the dashed drag · tap →

Do this now

List Top 10. Pick 5 relevant to REST APIs you test.

Was this step clear?
Chapter learning outcomes
  • OWASP API Top 10 overview
  • AuthZ vs AuthN tests
  • IDOR probes
  • Security smoke in CI

Clear these before you leave

Side quest

IDOR write-up

Explain IDOR in 3 sentences with example URL pattern.