Siemba Enhances API Security with Continuous IDOR Testing in Production

www.news4hackers.com-siemba-enhances-api-security-with-continuous-idor-testing-in-production-siemba-enhances-api-security-with-continuous-idor-testing-in-production

Siemba has introduced automated testing for insecure direct object reference (IDOR) vulnerabilities as part of its API security testing framework.

Automated IDOR Testing

This capability evaluates REST, GraphQL, and SOAP APIs for authorization flaws that could expose sensitive data. A set of 200 endpoints can be scanned for IDOR in under an hour, a process that traditionally required human testers to spend days or weeks analyzing each endpoint individually and generating reports that delayed actionable insights.

Streamlined Workflow and Detection

Siemba streamlines both testing and reporting into a single continuous workflow, executing scans against live API deployments without requiring access to source code. IDOR represents a critical authorization flaw where an endpoint fails to validate whether a user has permission to access a specific resource. By altering identifiers in requests, attackers can access or modify data belonging to other users.

According to the Open Web Application Security Project (OWASP), this is categorized as broken object level authorization (BOLA) and ranks as the top risk in the OWASP API Security Top 10.

Testing Process and Parameters

Sandhya Prashanth, Chief Security Officer at Siemba, highlighted that many API breaches stem from basic issues like one user’s session accessing another’s data, emphasizing the need for systematic, automated verification. The testing process begins with API definitions provided in OpenAPI, Swagger, or Postman formats, or via a collection URL. Users supply a set of identifiers, while the platform manages authenticated sessions.

Test Case Generation and Evaluation

Siemba generates test cases for all endpoints containing ID-like parameters, evaluating responses directly rather than relying on status codes or signatures. A response with an empty result or generic error is not considered a pass, ensuring only confirmed vulnerabilities are reported. Each finding includes reproduction steps, eliminating the need for separate reporting phases.

API-Specific Testing Protocols

Testing protocols vary by API type. REST endpoints are analyzed across path, query, header, and body parameters. GraphQL schemas undergo introspection to assess exposure, query depth, batching abuse, alias overloading, and field-level authorization. SOAP operations are parsed from WSDL files and tested for XML external entity injection, signature wrapping, SOAPAction manipulation, and WS-Security misconfigurations.

OWASP Integration and Expert Involvement

Automated scans map findings to nine of the ten OWASP API Security Top 10 categories. The remaining category, broken function level authorization, along with complex attack paths and privilege boundary analysis, is addressed by certified penetration testers using the same platform. This approach establishes a baseline for expert-led engagements, directing resources toward tasks requiring human expertise.

Continuous and Real-World Testing

Continuous testing ensures comprehensive coverage, as automation evaluates all endpoints and parameters, whereas manual testing under time constraints often results in partial coverage. The system operates against production environments, with adjustable testing rates ranging from stealth mode during business hours to high-speed scans during dedicated windows. Teams can pause testing for up to 30 days during critical periods like system freezes or major releases, eliminating the need for manual intervention.

Unrelated Cybersecurity Incidents

A separate section details unrelated cybersecurity incidents, including a breach exposing 23.6 million user records via a Gyazo server vulnerability, AI coding agents affected by zero-click remote code execution flaws, and tools for managing security configurations. These entries appear as promotional content and are excluded from the core article.



About Author

en_USEnglish