Hackers of India

Astra: Automated Security Testing For REST APIs

By  Sagar Popat   Harsh Grover  on 06 Dec 2018 @ Blackhat : Arsenal

This Tool Demo covers following tools where the speaker has contributed or authored
ASTRA

Abstract

REST API penetration testing is complex due to continuous changes in existing APIs and the addition of new APIs. Astra (Sanskrit: अस्त्र) can be used by security engineers or developers as an integral part of their process, so they can detect and patch vulnerabilities in the initial phase of the development cycle. Astra can automatically detect and test login & logout (Authentication API), which makes it easy for anyone to integrate this into CICD pipeline. Astra can take API collection as an input so this can also be used for testing APIs in stand-alone mode.