Common API
Vulnerabilities
How to effectively use Postman for API security testing
Ronak Odhaviya
Presented by
Security Engineer
SECURITY ENGINEER, POSTMAN
Ronak
Odhaviya
@roanakodhaviya
Takeaways
1 Common API vulnerabilities, how severe they are, and how simple it is to
mitigate them using Postman
2 How you can make your security team really happy by using an API-first
workflow
3 How you can automate most of your API security tests using Postman and
make your life easy
History of API Security
1 OWASP included broken authentication in its “Top 10” of 2017
2 OWASP created a separate API Top 10 list in 2019
3 Gartner research: “By 2022, API abuses will be the most frequent attack
vector resulting in data breaches for enterprise web applications.”
4 Broken authentication attacks accounted for many of the worst data
breaches published in 2020.
owasp.org/www-project-api-security
OWASP API Top 10 (2019)
1 Broken Object Level Authorization
2 Broken User Authentication
3 Excessive Data Exposure
4 Lack of Resources & Rate Limiting
5 Broken Function Level Authorization
6 Mass Assignment
7 Security Misconfiguration
8 Injection
9 Improper Assets Management
10 Insufficient Logging & Monitoring
3 Broken Function Level Authorization
Broken User Authentication
● 2nd in OWASP API Top 10 2019
● Refers to vulnerabilities allowing an attacker access to other user’s
identity
● Weakness in session management or credential management
● Weak API keys or hard-coded access tokens in the code
● Vulnerability in Microsoft Outlook allowed hackers to read other users’
Outlook email messages
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
Broken Object Level Authorization
● 1st in OWASP API Top 10 2019
● Authentication vs. Authorization
● Also known as an Insecure Direct Object Reference (IDOR)
● Allows attackers to access any object given the ID of the resource
● Combined with enumeration attacks, it has the capability to retrieve
the entire object database
● BOLA in YouTube bug that allowed unlisted uploads to any channel
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
Broken Function Level Authorization
● 5th in OWASP API Top 10 2019
● Allows unprivileged users to access other privileged users’ resources
and functions
● Different access control policies for different user personas
● Incorrect implementation of Role-Based Access Controls (RBAC)
● APIs relying on client to do the permission checks for different user
roles
● Presumptive trust between microservices to do the permission check
● The bug in 1Password allowed guest users unauthorised access
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
How can we automate these tests?
Introducing Monitors 🤩
Add Your Security Tests in Tests
Common Security API Issues and How to Mitigate Them Using Postman
Automate Tests Using Monitor
Monitor Run Results
Common Security API Issues and How to Mitigate Them Using Postman
Common Security API Issues and How to Mitigate Them Using Postman
When an API fails your security test,
you receive an email.
You can also set-up a Slack or other
integrations.
Wrapping Up
postman.com/ronak @roanakodhaviya
Thank You

More Related Content

PDF
API Security with Postman and Qualys
PDF
Drive API Adoption: Reach Over 13 Million Developers
PDF
Postman Webinar: "API Governance with Postman"
PDF
State of the API: Insights Into the Future of APIs
PPTX
Postman Enterprise Webinar
PDF
Enterprise E-commerce Webinar Series, Episode 2: Deploying and Monitoring You...
PDF
Why You Need a Developer Relations Team for Your API
PDF
API Lifecycle Management
API Security with Postman and Qualys
Drive API Adoption: Reach Over 13 Million Developers
Postman Webinar: "API Governance with Postman"
State of the API: Insights Into the Future of APIs
Postman Enterprise Webinar
Enterprise E-commerce Webinar Series, Episode 2: Deploying and Monitoring You...
Why You Need a Developer Relations Team for Your API
API Lifecycle Management

What's hot (20)

PDF
Postman for Enterprises
PDF
Webinar: “Introduction to the Postman API Network”
PDF
Why APIs Call for 2xs the DevOps
PDF
Postman Public Workspaces: The First Massively Multiplayer API Experience | W...
PPTX
App & API Monitoring: Building a 5-Star Reputation for your Apps
PDF
Postman Visualizer Webinar Slides
PDF
Enterprise ecommerce-webinar 1
PDF
Postman Webinar: "From APIs to Serverless Cloud Applications in Minutes"
PDF
Contract {Collaboration} Driven Development - APIdays Interface 2020
PPTX
What's an api
PDF
Public Workspaces: Massively Multiplayer API Experience
PDF
Clickslide Datadipity Beta V1
PDF
apidays LIVE New York - API Code First vs Design First by Phil Sturgeon
PPTX
SVPMA API Panel | April 2013
PDF
Postman Platform Overview: Be API-First, Not API-Last
PDF
Turn On The Lights
PDF
Tips to Reduce the Attack Surface When Using Third-Party Libraries
PDF
apidays LIVE Australia 2020 - Evaluating the usability of security APIs by Dr...
PDF
API TESTING
PDF
Is Your API Being Abused – And Would You Even Notice If It Was?
Postman for Enterprises
Webinar: “Introduction to the Postman API Network”
Why APIs Call for 2xs the DevOps
Postman Public Workspaces: The First Massively Multiplayer API Experience | W...
App & API Monitoring: Building a 5-Star Reputation for your Apps
Postman Visualizer Webinar Slides
Enterprise ecommerce-webinar 1
Postman Webinar: "From APIs to Serverless Cloud Applications in Minutes"
Contract {Collaboration} Driven Development - APIdays Interface 2020
What's an api
Public Workspaces: Massively Multiplayer API Experience
Clickslide Datadipity Beta V1
apidays LIVE New York - API Code First vs Design First by Phil Sturgeon
SVPMA API Panel | April 2013
Postman Platform Overview: Be API-First, Not API-Last
Turn On The Lights
Tips to Reduce the Attack Surface When Using Third-Party Libraries
apidays LIVE Australia 2020 - Evaluating the usability of security APIs by Dr...
API TESTING
Is Your API Being Abused – And Would You Even Notice If It Was?
Ad

Similar to Common Security API Issues and How to Mitigate Them Using Postman (20)

PPTX
API Security Fundamentals
PDF
APIsecure 2023 - Detect OWASP vulnerabilities in your APIs with Postman, Rahu...
PDF
Checkmarx meetup API Security - API Security top 10 - Erez Yalon
PDF
API Vulnerabilties and What to Do About Them
PPTX
How-to-Secure-APIs-to-Defend-Against-Emerging-Cyber-Threats-to-Digital-Web-As...
PPTX
2022 APIsecure_Go Hack Yourself: API Hacking for Beginners
PPTX
Safeguarding Digital Assets_ Uncovering Security Risks in APIs - Automation G...
PDF
OWASP API Security Top 10 - API World
PDF
apidays New York 2023 - A decade of API breaches, courtesy of application fla...
PDF
Space Camp :: Introduction to API Security
PDF
Api economy and why effective security is important (1)
PDF
Keamanan Digital dan Privasi di Masa Pandemi-Taro Lay (Director-Kalama Cyber)
PDF
Introduction to API Security - Intergalactic
PDF
HowYourAPIBeMyAPI
PDF
Guidelines to protect your APIs from threats
PDF
Outpost24 webinar Why API security matters and how to get it right.pdf
PDF
OWASPAPISecurity
PDF
OWASP API Security TOP 10 - 2019
PPTX
apidays Paris 2024 - Layered Approach of API Security Strategies and its Busi...
PDF
apidays LIVE LONDON - Protecting financial-grade APIs - Getting the right API...
API Security Fundamentals
APIsecure 2023 - Detect OWASP vulnerabilities in your APIs with Postman, Rahu...
Checkmarx meetup API Security - API Security top 10 - Erez Yalon
API Vulnerabilties and What to Do About Them
How-to-Secure-APIs-to-Defend-Against-Emerging-Cyber-Threats-to-Digital-Web-As...
2022 APIsecure_Go Hack Yourself: API Hacking for Beginners
Safeguarding Digital Assets_ Uncovering Security Risks in APIs - Automation G...
OWASP API Security Top 10 - API World
apidays New York 2023 - A decade of API breaches, courtesy of application fla...
Space Camp :: Introduction to API Security
Api economy and why effective security is important (1)
Keamanan Digital dan Privasi di Masa Pandemi-Taro Lay (Director-Kalama Cyber)
Introduction to API Security - Intergalactic
HowYourAPIBeMyAPI
Guidelines to protect your APIs from threats
Outpost24 webinar Why API security matters and how to get it right.pdf
OWASPAPISecurity
OWASP API Security TOP 10 - 2019
apidays Paris 2024 - Layered Approach of API Security Strategies and its Busi...
apidays LIVE LONDON - Protecting financial-grade APIs - Getting the right API...
Ad

More from Postman (20)

PDF
Advanced AI and Documentation Techniques
PDF
WeTestAthens: Postman's AI & Automation Techniques
PDF
Elevating Developer Experiences with AI-Powered API Testing & Documentation
PDF
Discovering Public APIs and Public API Network with Postman
PDF
Optimizing Teamwork: Harnessing Collections & Workspaces for Collaboration
PDF
API testing Beyond the Basics AI & Automation Techniques
PDF
Not Your Grandma’s Rate Limiting (slides)
PDF
Five Ways to Automate API Testing with Postman
PDF
How to Scale APIs-as-Product for Future Success
PPTX
Revolutionizing API Development: Collaborative Workflows with Postman
PDF
Everything You Always Wanted to Know About AsyncAPI
PDF
Elevating Event-Driven World: A Deep Dive into AsyncAPI v3
PDF
Five Things You SHOULD Know About Postman
PDF
Integration-, Snapshot- and Performance-Testing APIs
PDF
How ChatGPT led OpenAPI's Recent Spike in Popularity
PDF
Exploring Postman’s VS Code Extension
PDF
2023 State of the API Report: Key Findings and Trends
PDF
Nordic- APIOps is here What will you build in an API First World
PDF
Testing and Developing gRPC APIs
PDF
Testing and Developing GraphQL APIs
Advanced AI and Documentation Techniques
WeTestAthens: Postman's AI & Automation Techniques
Elevating Developer Experiences with AI-Powered API Testing & Documentation
Discovering Public APIs and Public API Network with Postman
Optimizing Teamwork: Harnessing Collections & Workspaces for Collaboration
API testing Beyond the Basics AI & Automation Techniques
Not Your Grandma’s Rate Limiting (slides)
Five Ways to Automate API Testing with Postman
How to Scale APIs-as-Product for Future Success
Revolutionizing API Development: Collaborative Workflows with Postman
Everything You Always Wanted to Know About AsyncAPI
Elevating Event-Driven World: A Deep Dive into AsyncAPI v3
Five Things You SHOULD Know About Postman
Integration-, Snapshot- and Performance-Testing APIs
How ChatGPT led OpenAPI's Recent Spike in Popularity
Exploring Postman’s VS Code Extension
2023 State of the API Report: Key Findings and Trends
Nordic- APIOps is here What will you build in an API First World
Testing and Developing gRPC APIs
Testing and Developing GraphQL APIs

Recently uploaded (20)

PDF
Software Development Company - swapdigit | Best Mobile App Development In India
PPTX
Hexagone difital twin solution in the desgining
PPTX
Comprehensive Guide to Digital Image Processing Concepts and Applications
PDF
SBOM Document Quality Guide - OpenChain SBOM Study Group
PPTX
Advanced Heap Dump Analysis Techniques Webinar Deck
PPTX
TRAVEL SUPPLIER API INTEGRATION | XML BOOKING ENGINE
PDF
Canva Desktop App With Crack Free Download 2025?
PDF
OpenColorIO Virtual Town Hall - August 2025
PPTX
ESDS_SAP Application Cloud Offerings.pptx
PDF
How to Set Realistic Project Milestones and Deadlines
PDF
10 Mistakes Agile Project Managers Still Make
PPTX
Phoenix Marketo User Group: Building Nurtures that Work for Your Audience. An...
PPTX
FLIGHT TICKET API | API INTEGRATION PLATFORM
PDF
Coding with GPT-5- What’s New in GPT 5 That Benefits Developers.pdf
PDF
IObit Driver Booster Pro Crack Latest Version Download
PDF
Ragic Data Security Overview: Certifications, Compliance, and Network Safegua...
PDF
solman-7.0-ehp1-sp21-incident-management
PPTX
AI Tools Revolutionizing Software Development Workflows
PPT
introduction of sql, sql commands(DD,DML,DCL))
PPTX
SQL introduction and commands, SQL joining
Software Development Company - swapdigit | Best Mobile App Development In India
Hexagone difital twin solution in the desgining
Comprehensive Guide to Digital Image Processing Concepts and Applications
SBOM Document Quality Guide - OpenChain SBOM Study Group
Advanced Heap Dump Analysis Techniques Webinar Deck
TRAVEL SUPPLIER API INTEGRATION | XML BOOKING ENGINE
Canva Desktop App With Crack Free Download 2025?
OpenColorIO Virtual Town Hall - August 2025
ESDS_SAP Application Cloud Offerings.pptx
How to Set Realistic Project Milestones and Deadlines
10 Mistakes Agile Project Managers Still Make
Phoenix Marketo User Group: Building Nurtures that Work for Your Audience. An...
FLIGHT TICKET API | API INTEGRATION PLATFORM
Coding with GPT-5- What’s New in GPT 5 That Benefits Developers.pdf
IObit Driver Booster Pro Crack Latest Version Download
Ragic Data Security Overview: Certifications, Compliance, and Network Safegua...
solman-7.0-ehp1-sp21-incident-management
AI Tools Revolutionizing Software Development Workflows
introduction of sql, sql commands(DD,DML,DCL))
SQL introduction and commands, SQL joining

Common Security API Issues and How to Mitigate Them Using Postman

  • 1. Common API Vulnerabilities How to effectively use Postman for API security testing Ronak Odhaviya Presented by Security Engineer
  • 3. Takeaways 1 Common API vulnerabilities, how severe they are, and how simple it is to mitigate them using Postman 2 How you can make your security team really happy by using an API-first workflow 3 How you can automate most of your API security tests using Postman and make your life easy
  • 4. History of API Security 1 OWASP included broken authentication in its “Top 10” of 2017 2 OWASP created a separate API Top 10 list in 2019 3 Gartner research: “By 2022, API abuses will be the most frequent attack vector resulting in data breaches for enterprise web applications.” 4 Broken authentication attacks accounted for many of the worst data breaches published in 2020.
  • 5. owasp.org/www-project-api-security OWASP API Top 10 (2019) 1 Broken Object Level Authorization 2 Broken User Authentication 3 Excessive Data Exposure 4 Lack of Resources & Rate Limiting 5 Broken Function Level Authorization 6 Mass Assignment 7 Security Misconfiguration 8 Injection 9 Improper Assets Management 10 Insufficient Logging & Monitoring 3 Broken Function Level Authorization
  • 6. Broken User Authentication ● 2nd in OWASP API Top 10 2019 ● Refers to vulnerabilities allowing an attacker access to other user’s identity ● Weakness in session management or credential management ● Weak API keys or hard-coded access tokens in the code ● Vulnerability in Microsoft Outlook allowed hackers to read other users’ Outlook email messages
  • 13. Broken Object Level Authorization ● 1st in OWASP API Top 10 2019 ● Authentication vs. Authorization ● Also known as an Insecure Direct Object Reference (IDOR) ● Allows attackers to access any object given the ID of the resource ● Combined with enumeration attacks, it has the capability to retrieve the entire object database ● BOLA in YouTube bug that allowed unlisted uploads to any channel
  • 17. Broken Function Level Authorization ● 5th in OWASP API Top 10 2019 ● Allows unprivileged users to access other privileged users’ resources and functions ● Different access control policies for different user personas ● Incorrect implementation of Role-Based Access Controls (RBAC) ● APIs relying on client to do the permission checks for different user roles ● Presumptive trust between microservices to do the permission check ● The bug in 1Password allowed guest users unauthorised access
  • 20. How can we automate these tests?
  • 22. Add Your Security Tests in Tests
  • 28. When an API fails your security test, you receive an email. You can also set-up a Slack or other integrations.