Security pitfalls to avoid when programming using an API - Help Net Security

Security pitfalls to avoid when programming using an API - Help Net Security

OWASP’s API Security Project has released the first edition of its top 10 list of API security risks.



The most common and perilous API security risks


API abuse is an ongoing problem and is expected to escalate in the coming years, as the number of API implementations continues to grow.


The OWASP API Security Project aims to provide software developers and code auditors with information about the risks brought on by insecure APIs.


Earlier this month, they’ve published the official OWASP API Security Top 10 list, which looks like this:


1. Broken Object Level Authorization2. Broken User Authentication3. Excessive Data Exposure4. Lack of Resources & Rate Limiting5. Broken Function Level Authorization6. Mass Assignment7. Security Misconfiguration8. Injection9. Improper Assets Management10. Insufficient Logging & Monitoring


Each of the risks comes with an expl ..

Support the originator by clicking the read the rest link below.