| name | testing-api-for-mass-assignment-vulnerability |
| description | Use when tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they should not have access to by including additional parameters in API requests. The tester identifies writable endpoints, adds undocumented fields to request bodies (role, isAdmin, price, balance), and checks if the server binds these to the data model without filtering. Part of OWASP API3:2023 Broken Object Property Level Authorization. |
| domain | cybersecurity |
| tags | ["api-security","owasp","mass-assignment","auto-binding","parameter-tampering"] |
| subdomain | api-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","ID.RA-01","PR.DS-10","DE.CM-01"] |
Testing Api For Mass Assignment Vulnerability
Overview
Cybersecurity skill for testing api for mass assignment vulnerability. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"testing api for mass assignment vulnerability"
-
"Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can "
-
Testing API endpoints that accept JSON/XML request bodies for user profile updates, registration, or object creation
-
Assessing whether the API binds all client-supplied properties to the data model without an allowlist
-
Evaluating if users can set privileged attributes (role, permissions, pricing, balance) through regular update endpoints
-
Testing APIs built with ORMs that auto-bind request parameters to database models
-
Validating that server-side input validation restricts writeable properties per user role
Do not use without written authorization. Mass assignment testing involves modifying object properties in potentially destructive ways.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Written authorization specifying target API endpoints and scope
- Test accounts at different privilege levels
- API documentation or OpenAPI specification to identify expected request fields
- Burp Suite Professional for request interception and parameter injection
- Python 3.10+ with
requests library
- Knowledge of the backend framework (Rails, Django, Express, Spring) to predict parameter binding behavior
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def () -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}