Web Hack List

Collected research

a-deep-dive-into-openapi-security.pdf

A Deep Dive into OpenAPI Security

Treats an API's OpenAPI specification as a graph in a graph database, with endpoints, parameters and objects as nodes, so design flaws can be queried much as directory attack paths are. The queries surface sensitive data reachable through unprotected alternative paths, endpoints whose description contradicts their behaviour, and identifiers leaked by one endpoint that replay against another.

Record

Document
A Deep Dive into OpenAPI Security
Researcher
Andrei Agape
Published by
0xpwn.wordpress.com
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Andrei Agape, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .