Security Test Cases
Id : GRP-008
name : Security Test Cases
Description : API Security Testing Execution Report - OWASP Compliance
Created By : arun-ramanan@netspective.in
Created On : 01-11-2024
Description
This documents the results of executing API security test cases based on the API Security Testing Plan, ensuring compliance with the OWASP API Security Top 10. The focus is on verifying secure authentication, authorization, data protection, and adherence to industry standards.
Test Cases Executed
- Management Endpoints & Overall Authentication
- Server Resource Allocation & Rate Limiting Verification
- Error Handling Validation
- Sensitive Data Handling
- HTTP Methods Restriction
- HTTP Return Code Validation
- Access Control Verification
- Input Validation
- HTTPS Enforcement
- Security Headers Validation
- Security Misconfiguration
- CORS Validation
Environment
- Test Environment: test
- API Version: v1.0
Tools Used
- Burp Suite: Dynamic Application Security Testing & Vulnerability Scanning
- Nessus Professional: Vulnerability Scanning
- Dirsearch: Directory/File Bruteforcing
Objectives
- Verify the implementation of security controls across all API endpoints.
- Identify any deviations from expected security behavior.
- Validate the application of fixes for previously reported vulnerabilities.