Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

13 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

API Security Scanner

Stars Forks Issues License Last Commit Build Status OWASP API GraphQL Python


🎯 Overview

OWASP API Top 10 2023 + GraphQL security scanner for REST, GraphQL, and gRPC APIs. Detects BOLA/IDOR, BFLA, SSRF, introspection leaks, depth DoS, batching attacks, and auth bypass.

Check OWASP API Category Severity
Broken Object Level Authorization (BOLA) API1:2023 🔴 CRITICAL
Broken Authentication API2:2023 🔴 CRITICAL
Broken Object Property Level Auth API3:2023 🟠 HIGH
Unrestricted Resource Consumption API4:2023 🟠 HIGH
Broken Function Level Authorization API5:2023 🔴 CRITICAL
Unrestricted Access to Sensitive Flows API6:2023 🟠 HIGH
Server Side Request Forgery (SSRF) API7:2023 🟠 HIGH
Security Misconfiguration API8:2023 🟡 MEDIUM
Improper Inventory Management API9:2023 🟡 MEDIUM
Unsafe Consumption of APIs API10:2023 🟡 MEDIUM

GraphQL-Specific Checks

Check Severity
Introspection Enabled 🔴 CRITICAL
Depth/Breadth DoS 🟠 HIGH
Batching Attack 🟠 HIGH
Field-Level Auth Bypass 🔴 CRITICAL
Alias Overloading 🟡 MEDIUM

🚀 Quick Start

git clone https://github.com/ridhinva/api-security-scanner.git
cd api-security-scanner
pip install requests
python3 api_security_scanner.py --target https://api.example.com --mode all

⚖️ Disclaimer

For authorized security testing only.

About

Scanner: OWASP API Top 10 2023 + GraphQL security scanner — BOLA, BFLA, SSRF, introspection leaks, depth DoS in Python

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages