Case Study - API Security Testing (Your Docs Lie, We Test Reality)
Swagger listed 84 endpoints. We found 121. Endpoint #117 let us read any nasabah’s balance.
Client Context
Digital bank — mobile + 120+ REST/JSON APIs behind gateway: onboarding (e-KYC), balance, transfer, e-statement. Partner integrations launching. OJK API security expectations + PCI DSS.
Challenge
Undocumented shadow endpoints, inconsistent auth (JWT + API key + mTLS mix), no central schema. Risk: BOLA fund/ PII leak at scale. Manual review could not keep up with sprint velocity.
Scope - Snipeyes API Security Testing
- Endpoint discovery: OpenAPI + traffic capture + fuzz-derived enumeration; auth matrix (roles × endpoints)
- Automated + analyst-led tests: BOLA/BFLA, broken auth, excessive data exposure, mass assignment, injection, rate-limit, JWT weaknesses
- Input validation suites per OWASP API Top 10 (2023) + ASVS 4.0 API chapters
- Output: API security findings with curl replay + gateway rule recommendation
Key Findings (redacted)
- CRITICAL BOLA:
GET /accounts/{id}/balance— sequential IDs, no ownership check → any balance readable (37 undocumented endpoints same pattern) - HIGH BFLA: Partner role could call
POST /admin/reversal— reversed own failed transfer for double credit - HIGH: JWT
alg=noneaccepted on legacy auth service; refresh token never rotated - 41 findings: 2 Critical, 7 High, 14 Medium, 18 Low
Outcome
- Gateway authorization policy rewritten (deny-by-default + ownership check library) — retest 100% critical closed
- API inventory + contract tests added to CI; every new endpoint auto-tested before merge
- OWASP API Top 10 mapping accepted as OJK technical evidence
Relevance for you: If mobile and partners talk to your core via APIs — assume undocumented endpoints exist.