API Security Testing (OWASP API Top 10)
Specialize in API security testing with OWASP API Top 10. Learn authentication testing, authorization flaws, injection attacks, and API-specific security vulnerabilities.
Membership required
Join Membership to unlock human reviews of your work, 21 advanced specializations, and higher coach limits. 1:1 mentorship comes with Pro later.
The web has changed. We don't hack pages anymore; we hack APIs. Learn the specialized OWASP API Top 10 list, focusing on "Broken Object Level Authorization" (BOLA), "Broken User Authentication" (API Keys), and "Excessive Data Exposure" (JSON leaks).
1. The King of API Bugs (API1: BOLA)
2. Mass Assignment (API6)
3. Conclusion
The vulnerability formerly known as IDOR is now API#1 for a reason. Learn the subtle ways BOLA hides in nested URLs, GraphQL queries, and "Export to PDF" features, and how to write a generic "AuthMatrix" test to catch it everywhere.
1. Nested BOLA
2. GraphQL BOLA
3. AuthMatrix
4. Conclusion
Authentication is hard. Learn why relying on "SMS 2FA" is dangerous (SIM Swapping), how to test for "Password Reset Poisoning" via Host Header Injection, and why allowing unlimited login attempts is a gift to botnets.
1. MFA Bypass
2. Password Reset Poisoning
3. Enumeration & Locking
4. Conclusion
Two sides of the same coin: Sending too much data OUT (Exposure) and accepting too much data IN (Mass Assignment). Learn how to detect PII leakage in JSON responses and how to become Admin by simply adding "is_admin": true to your request.
1. Excessive Data Exposure
2. Mass Assignment
3. Conclusion
An API without limits is a vulnerability. Learn to execute Denial of Service (DOS) attacks by exhausting CPU, Memory, or Database connections using "Pagination Attacks", "GraphQL Complexity Bombs", and "ReDoS".
1. Rate Limiting
2. Resource Exhaustion
3. ReDoS
4. Conclusion
Injection isn't just for web forms. APIs are vulnerable too. Learn how to inject NoSQL queries (`{"$gt": ""}`) into JSON payloads to bypass login, and how to spot SQL/Command Injection in REST endpoints "Order By" params.
1. NoSQLi: JSON Operators
2. API SQL Injection
3. Command Injection
4. Conclusion
Hackers love lazy admins. Learn how to spot the "Low Hanging Fruit" of security: Default passwords (admin/admin), Verbose Error Messages (Stack Traces), CORS misconfigurations, and S3 Bucket Leaks (Public Data).
1. Defaults & Errors
2. CORS & S3
3. Security Headers
4. Conclusion
The API you *forgot* is the one that hackers will find. Learn to detect "Shadow APIs" (undocumented endpoints), "Zombie APIs" (old versions like /v1/), and exposed Staging environments that lack the security controls of Production.
1. Zombie APIs
2. Shadow APIs
3. Lower Environments
4. Conclusion
Deep dive into complex Mass Assignment vectors. Learn how to exploit nested object binding (e.g. `user.company.role`), discover hidden fields using parameter mining, and why strict DTOs are the only safe defense.
1. Deep Binding Attacks
2. Param Mining
3. The Fix: DTOs
4. Conclusion
Master the essential checklist every SDET uses for API security. Learn how to run ZAP Baseline scans in CI/CD, use Burp Param Miner to find hidden fields, and enforce the "Big Four" security checks on every Pull Request.
1. The SDET Security Checklist
2. Essential Tools
3. Conclusion
Become the SDET who protects the backend from injection, broken auth, excessive exposure, and DoS attacks. Master OWASP API Top 10 automation, vulnerability scanning (ZAP, Burp, Semgrep), injection & auth testing, rate limiting & brute-force protection, and build CI/CD security gates that fail fast on critical risks.
