API 安全测试

原名:conducting-api-security-testing

对 REST、GraphQL 和 gRPC API 进行安全测试,以识别潜在漏洞。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-25
TRACE 评分
3.4 / 5

内容概览

- Testing API endpoints for authorization flaws, injection vulnerabilities, and business logic bypasses - Assessing the security of microservices architecture where APIs are the primary communication method - Validating that API gateway protections (rate limiting, authentication, input validation) are properly enforced - Testing third-party API integrations for data exposure and insecure configurations - Evaluating GraphQL APIs for introspection disclosure, query complexity attacks, and authorization bypasses Do not use against APIs without written authorization, for load testing or denial-of-service testing unless explicitly scoped, or for testing production APIs that process real financial transactions without safeguards. - API documentation (OpenAPI/Swagger, GraphQL schema, Postman collection) or application access to reverse-engineer the API - Burp Suite Professional configured to in…

查看 SKILL 详情