Web Hack List

Other nomination

a-deep-dive-into-openapi-security.pdf

Treats an API's OpenAPI specification as a graph in a graph database, with endpoints, parameters and objects as nodes, so design flaws can be queried much as directory attack paths are. The queries surface sensitive data reachable through unprotected alternative paths, endpoints whose description contradicts their behaviour, and identifiers leaked by one endpoint that replay against another.

Record

Researcher
Andrei Agape
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Andrei Agape, first published at the original source. Preserved copies are kept so the citation survives its host.