Training

OWASP API Security Top 10: testing APIs in a targeted way

Your team develops or operates APIs and needs to recognise their most common security risks. The workshop teaches the methodology of the OWASP API Security Top 10, the fundamentals of web APIs and how to use the Burp tool.

Two mornings as an interactive webinar, for teams that develop, operate or test APIs.

Free of charge and without obligation.

  • OWASP Corporate Member · Silver Sponsor
  • Trainers are penetration testers
Several hands working with compass and dividers between sticky notes on a map
OWASP API Security Top 10: securing APIs in a targeted way.

Your situation

Your applications communicate via APIs – and your team needs to recognise their typical vulnerabilities?

Front ends, mobile apps and partner systems access your data via REST or other web APIs. Many security problems arise where no user interface provides protection any more: an object is retrieved via a modified ID, a function can be reached without the appropriate authorisation, requests are not rate-limited.

The OWASP API Security Top 10 describes these risks as a separate list alongside the OWASP Top 10 for web applications. The workshop explains the methodology behind it, lays the foundations of web APIs and uses the Burp testing tool to show how APIs can be examined.

The workshop was designed by a penetration tester from our team who tests APIs and apps himself. It is aimed at developers and DevOps, technically experienced product owners, product and project owners, and IT administration with knowledge of web technologies. The basic module is helpful but not a prerequisite.

Services & results

API security based on the OWASP API Security Top 10

Afterwards, your team knows the methodology of the OWASP API Security Top 10 and the fundamentals of web APIs, including requests, authentication and authorisation, and can examine APIs with the Burp testing tool. For development, DevOps, technically experienced product owners and product and project owners; designed by a penetration tester who tests APIs and apps himself. The training is available in German or English.

From the structure of a web API and the Burp testing tool to the ten most common API risks – with live demonstrations or Hunt the Bug. Two mornings, each from 9:00 to 12:30.

Context: OWASP and real API incidents

Overview of OWASP and selected projects, then examples of vulnerabilities from public reporting in which APIs were the cause. Plus the methodology of the OWASP API Security Top 10: how the list is compiled and how it differs from the OWASP Top 10 for web applications.

Fundamentals and concepts of web APIs

How web APIs are structured and how requests, authentication and authorisation work there – the prerequisite for understanding the risks on the list technically.

Introduction to the Burp testing tool

Burp is one of the tools we use to test web applications and APIs in a penetration test. Participants work with their own Burp installation and see how API requests can be intercepted, modified and resent with it.

The ten API risks in practice

All ten risks in the current version of the OWASP API Security Top 10 with examples from practice. Depending on the booking, the trainers demonstrate them live or the participants search for them themselves in Hunt the Bug tasks.

Result

Your team recognises the typical vulnerabilities of APIs and can examine an API with Burp itself.

Our expertise

The workshop was designed by Ruben Konrad, penetration tester and member of our Product Security team. He tests web applications, mobile apps and systems and is responsible for mobile app security at secuvera. Tobias Glemser, BSI-certified penetration tester, technical lead for penetration testing and chapter lead of the OWASP German Chapter, also delivers the workshop.

As early as 2019, we presented the release candidate in iX (“Sicher angebunden – OWASP veröffentlicht RC der API Security Top 10”, in German). Testing APIs is an established part of our pentest portfolio.

Getting started

Format and schedule

Two mornings, remote

From 9:00 to 12:30 on each of two days, as an interactive webinar via Zoom – or via your platform, such as Webex or Teams. On site on request; in that case you provide the room and presentation equipment. Instead of a script, you receive slides to follow along and show notes for each session, and a certificate of attendance on request.

Hunt the Bug: interactive or in small groups

You solve the tasks either together with the trainers or independently in small groups. For small groups, we can provide virtual machines that run in the browser on request; the video platform must then allow breakout rooms – our Zoom solution does.

Up to 15 participants

You decide the number. For didactic reasons, we recommend up to 15 participants; with more than 20, the results suffer.

Plan OWASP training
The points of a pair of dividers resting on coloured sticky notes above a map
Exercises scoped to match your APIs.

secuvera is the training provider

The training is offered by secuvera and teaches OWASP methods. It is not a training course of the OWASP® Foundation.

Questions about the API Security workshop

Do we need the basic module first?

Not necessarily. The module builds on the basic module on web application security/OWASP Top 10, but can also be booked without it, depending on your level of knowledge.

How is the training structured?

Over two mornings from 9:00 to 12:30 as an interactive webinar: theory, joint technical demonstrations, polls and discussion. 95% of participants prefer this format to a full training day. Zoom is the standard; Webex, Teams or your own platform also work, and on request the training takes place on site.

How many people can take part?

You decide. We recommend up to 15 participants; with more than 20, the results suffer. The price applies per session, regardless of the number of participants.

Is the training adapted to our applications?

No. The modules are standard training courses that we continue to develop across all sessions. If you wish, send us a list of your internal requirements in advance, such as development guidelines – the titles are sufficient.

Do participants need their own Burp installation?

Yes. For the workshop, participants need their own Burp installation with which they intercept and modify API requests themselves.

How can we support you with OWASP API Security?