API Penetration Testing
Testing API security — from REST and GraphQL endpoint testing through authentication bypass, injection, rate limiting, and business logic flaws.
When to Use
Testing REST API security
Testing GraphQL API security
Finding API authentication and authorization flaws
Testing API rate limiting and abuse cases
API-specific vulnerabilities (mass assignment, IDOR)
API Testing Techniques
API_TESTS = {
'auth_bypass': 'Test missing/weak JWT, OAuth misconfig, API key in URL, default tokens',
'injection': 'Test SQL/NoSQL injection in params, headers, request bodies',
'idor': 'Test object ID manipulation (user/123 → user/124)',
'mass_assignment': 'Test extra fields in request body (is_admin=true)',
'rate_limiting': 'Test without auth headers, IP-based limiting bypass (X-Forwarded-For)',
'graphql_introspection': 'Test if introspection is enabled (query __schema)',
'graphql_batching': 'Test batch queries for rate limit bypass',
}
# REST API testing with curl
API_TESTS_CURL = {
'jwt_none_algorithm': "curl -H 'Authorization: Bearer eyJhbGciOiJub25lIn0.eyJ1c2VyIjoiYWRtaW4ifQ.' https://api.example.com/admin",
'idor_test': "curl https://api.example.com/users/123",
'mass_assignment': "curl -X PUT https://api.example.com/users/me -d '{\"role\":\"admin\"}'",
}
# GraphQL query depth testing
GRAPHQL_DEPTH = """
query DeepQuery {
user(id: 1) {
posts { comments { author { posts { comments { author { name } } } } } }
}
}
"""
Verification Checklist
Authentication tested (JWT none algo, token in URL, missing auth)
Authorization tested (IDOR, horizontal/vertical privilege esc)
Injection tested (SQL, NoSQL, command injection in params)
Rate limiting tested (brute force, resource exhaustion)
Mass assignment tested (extra fields in request)
GraphQL: introspection, query depth, batching attacks
Input validation tested (XSS, SSRF, XXE)
API versioning and deprecation tested
CORS configuration reviewed
1 --- 2 name: api-penetration-testing 3 description: Use when testing API security and endpoints. 4 license: MIT 5 --- 6 7 # API Penetration Testing 8 9 Testing API security — from REST and GraphQL endpoint testing through authentication bypass, injection, rate limiting, and business logic flaws. 10 11 ## When to Use 12 13 - Testing REST API security 14 - Testing GraphQL API security 15 - Finding API authentication and authorization flaws 16 - Testing API rate limiting and abuse cases 17 - API-specific vulnerabilities (mass assignment, IDOR) 18 19 ## API Testing Techniques 20 21 ```python 22 API_TESTS = { 23 'auth_bypass': 'Test missing/weak JWT, OAuth misconfig, API key in URL, default tokens', 24 'injection': 'Test SQL/NoSQL injection in params, headers, request bodies', 25 'idor': 'Test object ID manipulation (user/123 → user/124)', 26 'mass_assignment': 'Test extra fields in request body (is_admin=true)', 27 'rate_limiting': 'Test without auth headers, IP-based limiting bypass (X-Forwarded-For)', 28 'graphql_introspection': 'Test if introspection is enabled (query __schema)', 29 'graphql_batching': 'Test batch queries for rate limit bypass', 30 } 31 32 # REST API testing with curl 33 API_TESTS_CURL = { 34 'jwt_none_algorithm': "curl -H 'Authorization: Bearer eyJhbGciOiJub25lIn0.eyJ1c2VyIjoiYWRtaW4ifQ.' https://api.example.com/admin", 35 'idor_test': "curl https://api.example.com/users/123", 36 'mass_assignment': "curl -X PUT https://api.example.com/users/me -d '{\"role\":\"admin\"}'", 37 } 38 39 # GraphQL query depth testing 40 GRAPHQL_DEPTH = """ 41 query DeepQuery { 42 user(id: 1) { 43 posts { comments { author { posts { comments { author { name } } } } } } 44 } 45 } 46 """ 47 ``` 48 49 ## Verification Checklist 50 51 - [ ] Authentication tested (JWT none algo, token in URL, missing auth) 52 - [ ] Authorization tested (IDOR, horizontal/vertical privilege esc) 53 - [ ] Injection tested (SQL, NoSQL, command injection in params) 54 - [ ] Rate limiting tested (brute force, resource exhaustion) 55 - [ ] Mass assignment tested (extra fields in request) 56 - [ ] GraphQL: introspection, query depth, batching attacks 57 - [ ] Input validation tested (XSS, SSRF, XXE) 58 - [ ] API versioning and deprecation tested 59 - [ ] CORS configuration reviewed