Jan. 23, 2023, 7:08 p.m. | Hashar Mujahid

InfoSec Write-ups - Medium infosecwriteups.com

Broken Object Level Authorization [API SECURITY — 0x1]

Hi, My name is Hashar Mujahid. I am a security researcher and a penetration testing student. This is the first blog of the API SECURITY series where we will learn about some common security vulnerabilities that APIs are prone to.

image from Wallarm

We can not understand object-level authorization until we have a solid understanding of the object.

WHAT IS AN OBJECT?

An object is a piece of code that process and …

api api security authorization broken object level authorization cybersecurity ethical hacking object penetration testing security web3

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Physical Security Operations Center - Supervisor

@ Equifax | USA-GA-Alpharetta-JVW3

Network Cybersecurity Engineer - Overland Park, KS Hybrid

@ Black & Veatch | Overland Park, KS, US

Cloud Security Engineer

@ Point72 | United States

Technical Program Manager, Security and Compliance, Cloud Compute

@ Google | New York City, USA; Kirkland, WA, USA

EWT Security | Vulnerability Management Analyst - AM

@ KPMG India | Gurgaon, Haryana, India