Showing cs.CRShow all
2 papers · 1 filter
cs.CR2025
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
Davide Corradini, Mariano Ceccato, Mohammad Ghafari
We present AuthREST, an open-source security testing tool targeting broken authentication, one of the most prevalent API security risks in the wild. AuthREST automatically tests we…
cs.CR2024
Mining REST APIs for Potential Mass Assignment Vulnerabilities
Arash Mazidi, Davide Corradini, Mohammad Ghafari
REST APIs have a pivotal role in accessing protected resources. Despite the availability of security testing tools, mass assignment vulnerabilities are common in REST APIs, leading…