Description: | |
---|---|
API Specification: | |
API Base URL: | |
Number of Endpoints: | |
Date Tested: |
Vulnerable
Test Passed
Injection (Log4J): | |
Fuzzing | |
Reflected Injection: |
Valuable
Personal Data |
Configuration
SSL Certificate | |
SSL Required | |
Server Properties Leak | |
HTTP Options | |
CORS Configuration | |
Incremental IDs |
Authentication
Broken Authentication |
About This Test
APIsec Check tests APIs using automated techniques to identify vulnerabilities, high value data, configuration issues and authentication flaws. This testing is performed without authentication and provides insight into the type of information an attacker can discover through automated/bot scans. Note, APIsec Check does not perform authenticated tests. We strongly recommend performing authenticated testing of APIs, which can be performed by APIsec. Contact us for a free scan.