Discussion about this post

User's avatar
Marius Laurusevicius's avatar

The gym case sits on two entries in the same list, not one. OWASP's API Security Top 10 for 2023 puts Broken Object Level Authorization at API1, and API6 covers unrestricted access to sensitive business flows, where exploitation is defined as understanding the business model, finding the sensitive flow, and automating access to it. That second entry describes an agent almost exactly: patient, cheap, and willing to map a workflow before touching it. The 2023 edition rates API6 prevalence as widespread and exploitability as easy. Rate limiting a waitlist endpoint stops being optional once the caller never gets bored.

Josh Woodruff's avatar

The undo is the part I'd put in front of a board. The agent canceled a live reservation and had nothing to put the person back with, so one call did permanent damage with no reverse. Your point that the target API is the ceiling is the half most agent policies skip, because a well-scoped agent pointed at a cancel endpoint with no ownership check still gets there. When you pull that inventory, do you count the read endpoints that hand out someone else's object ID, or start with the mutations?

No posts

Ready for more?