Siemba brings continuous IDOR testing to production APIs
Siemba released automated IDOR/BOLA testing for REST, GraphQL and SOAP APIs, checking a 200-endpoint collection in under an hour.
Siemba added automated insecure direct object reference (IDOR) testing to its API Security Testing capability, covering REST, GraphQL and SOAP APIs against the deployed service without source code. The platform validates findings by reading actual API responses and maps results to nine of the ten OWASP API Security Top 10 categories, with human testers handling broken function level authorization and chained attack paths. Testing starts from OpenAPI/Swagger files, Postman collections or collection URLs, with throttle presets and freeze windows for running against production.