Zero Day Room
Live
Vulnerabilities

Siemba automates IDOR testing for production APIs

Siemba has launched automated testing for insecure direct object reference (IDOR) vulnerabilities in REST, GraphQL, and SOAP APIs, compressing a process

Siemba has launched automated testing for insecure direct object reference (IDOR) vulnerabilities in REST, GraphQL, and...

Siemba has announced automated testing for insecure direct object reference (IDOR) vulnerabilities as part of its API security platform. The company states its system can test a 200-endpoint API collection in under an hour, a task that typically takes human testers days or weeks.

IDOR, classified by OWASP as broken object level authorization (BOLA), is a common authorization flaw. A vulnerable API endpoint fails to verify if a supplied identifier belongs to the requesting user, allowing data access or modification by changing a simple parameter. The flaw is conceptually simple but tedious to test exhaustively, making it a consistently cited cause of API breach disclosures.

"Most API vulnerabilities aren't exotic," said Sandhya Prashanth, Chief Security Officer at Siemba. "They are one user's session reading another user's data because nobody checked."

How the automated testing works

Testing begins with an existing API definition, such as an OpenAPI file or a Postman collection. The platform handles authenticated sessions and runs test cases across every endpoint with an ID-like parameter. Crucially, results are judged by reading the actual API response content, not only status codes, to separate confirmed findings from noise. Each finding is delivered with written reproduction steps.

The system tests different API protocols to their own specifications.

Coverage and human expertise

The automated testing maps confirmed findings to nine of the ten categories in the OWASP API Security Top 10. The tenth category, broken function level authorization, along with chained attack paths and nuanced privilege-boundary testing, is handled by Siemba's certified penetration testers using the same platform. This approach allows expert-led engagements to start from a known baseline.

The company emphasizes that automation provides exhaustive coverage across all endpoints and parameters, unlike manual sampling under time pressure. It also enables continuous testing, closing the security window that opens after a point-in-time engagement certifies an API.

Testing in production environments

Siemba's platform is built to run tests against production APIs where real data and authorization logic exist. Customers control the test pace through four throttle presets, from a stealth mode for business hours to a turbo mode for dedicated testing windows. Teams can also set automatic freeze windows of up to 30 days to pause testing around production freezes or critical releases. These controls aim to make continuous IDOR testing against live systems practical and safe.

Related coverage

More from Vulnerabilities