February 2019
Intermediate to advanced
256 pages
7h 34m
English
Some web services may provide a list of REST or SOAP API interfaces. These API interfaces are built for other application to do further integration or customization. The standard response of the REST or SOAP APIs can be JSON or XML. ZAP can be installed with the OpenAPI and SOAP API add-ons for the web API security testing. Take the PetStore API as an example: https://petstore.swagger.io/. In this case, ZAP can import the API definition files and assess security issue for every API. This is the most effective way to ensure that all the APIs are included in the ZAP scanning. Simply doing the spider scanning in ZAP won't enable you to list all the API interfaces.
Read now
Unlock full access