APIthet is an application to security test RESTful web APIs. Assessing APIs help in detecting security vulnerabilities at an early stage of the SDLC.

Compare this with assessing an Android application that uses APIs on a backend server. This kind of assessment happens at a much later phase of the SDLC. Even worse, it does not necessarily touch all the APIs.

That's not all. You specify one of the JSON parameters as random. This helps set a unique value for a specific JSON parameter in an API.

The application is available as a Windows exe file..

In progress and planned features:
-More test cases to attack target API.
-Add APIs and define sequence.
-Read APIs from doc link.
-Business Logic test.

TODO: Build for Linux (and may be OS X).

Features

  • XSS - Reflected, Stored and Blind (for JSON payloads in POST calls)
  • XSS - Reflected, Stored and Blind (for URL parameters in GET calls)
  • SQLI - URL based blind SQLI
  • SQLI - Error based
  • CSRF detection
  • CORS detection
  • Unauthorised Access and Privilege Escalation Scenario warnings
  • Warns against Clickjacking
  • Warns against XSS protection header miss
  • Warns if the application is not HSTS enabled
  • HTML injection detection
  • Open Redirect vulnerability detection
  • Warns against server footprint
  • Set a unique/random JSON parameter
  • Reports issues with OWASP and CWE categories

Project Samples

Project Activity

See All Activity >

License

MIT License

Follow APIthet

APIthet Web Site

You Might Also Like
Achieve perfect load balancing with a flexible Open Source Load Balancer Icon
Achieve perfect load balancing with a flexible Open Source Load Balancer

Take advantage of Open Source Load Balancer to elevate your business security and IT infrastructure with a custom ADC Solution.

Boost application security and continuity with SKUDONET ADC, our Open Source Load Balancer, that maximizes IT infrastructure flexibility. Additionally, save up to $470 K per incident with AI and SKUDONET solutions, further enhancing your organization’s risk management and cost-efficiency strategies.
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of APIthet!

Additional Project Details

Intended Audience

Security Professionals

Registered

2016-10-11