Case Study - API Security Testing (Your Docs Lie, We Test Reality)

Swagger listed 84 endpoints. We found 121. Endpoint #117 let us read any nasabah’s balance.

ILLUSTRATION — API ATTACK FLOW TESTED
📄 Discover (spec + traffic)→ 🔑 Auth & Scope→ 🎯 BOLA / BFLA→ ✔ Validated Finding

Client Context

Digital bank — mobile + 120+ REST/JSON APIs behind gateway: onboarding (e-KYC), balance, transfer, e-statement. Partner integrations launching. OJK API security expectations + PCI DSS.

Challenge

Undocumented shadow endpoints, inconsistent auth (JWT + API key + mTLS mix), no central schema. Risk: BOLA fund/ PII leak at scale. Manual review could not keep up with sprint velocity.

Scope - Snipeyes API Security Testing

  • Endpoint discovery: OpenAPI + traffic capture + fuzz-derived enumeration; auth matrix (roles × endpoints)
  • Automated + analyst-led tests: BOLA/BFLA, broken auth, excessive data exposure, mass assignment, injection, rate-limit, JWT weaknesses
  • Input validation suites per OWASP API Top 10 (2023) + ASVS 4.0 API chapters
  • Output: API security findings with curl replay + gateway rule recommendation

Key Findings (redacted)

  • CRITICAL BOLA: GET /accounts/{id}/balance — sequential IDs, no ownership check → any balance readable (37 undocumented endpoints same pattern)
  • HIGH BFLA: Partner role could call POST /admin/reversal — reversed own failed transfer for double credit
  • HIGH: JWT alg=none accepted on legacy auth service; refresh token never rotated
  • 41 findings: 2 Critical, 7 High, 14 Medium, 18 Low

Outcome

  • Gateway authorization policy rewritten (deny-by-default + ownership check library) — retest 100% critical closed
  • API inventory + contract tests added to CI; every new endpoint auto-tested before merge
  • OWASP API Top 10 mapping accepted as OJK technical evidence

Relevance for you: If mobile and partners talk to your core via APIs — assume undocumented endpoints exist.