| name | exploiting-excessive-data-exposure-in-api |
| description | Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug information, or sensitive business data that the UI does not display but the API transmits. This maps to OWASP API3:2023 Broken Object Property Level Authorization. Use when working with exploiting excessive data exposure in api. |
| domain | cybersecurity |
| tags | ["api-security","owasp","data-exposure","rest-security","pii-leakage"] |
| subdomain | api-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","ID.RA-01","PR.DS-10","DE.CM-01"] |
Exploiting Excessive Data Exposure In Api
Overview
Cybersecurity skill for exploiting excessive data exposure in api. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"exploiting excessive data exposure in api"
-
"Tests APIs for excessive data exposure where endpoints return more data than the"
-
Testing APIs where the frontend displays a subset of data but the API response includes additional fields
-
Assessing mobile application APIs where responses are designed for multiple client types and may contain excess data
-
Identifying PII leakage in API responses that include email addresses, phone numbers, SSNs, or payment data not shown in the UI
-
Testing GraphQL APIs where clients can request arbitrary fields including sensitive attributes
-
Evaluating APIs after microservice refactoring where internal service-to-service data leaks into public endpoints
Do not use without written authorization. Data exposure testing involves capturing and analyzing potentially sensitive personal data.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Written authorization specifying target API endpoints and scope
- Burp Suite Professional or mitmproxy configured as intercepting proxy
- Two test accounts at different privilege levels (regular user and admin)
- Browser developer tools or mobile proxy setup for traffic capture
- Python 3.10+ with
requests and json libraries
- API documentation (OpenAPI spec) for comparison against actual responses
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
: ,
: ,
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}