API Security
How Hackers Attack APIs: Common Attack Techniques
Hackers attack APIs through: reconnaissance (discovering endpoints via documentation, JavaScript source, traffic interception), enumeration (iterating IDs to find accessible resources), authorization bypass (manipulating tokens and IDs to access other users' data), injection (SQL/NoSQL through API parameters), authentication attacks (credential stuffing, token manipulation), and data exfiltration (scraping data at scale through legitimate-looking API calls).

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
The API Attack Lifecycle
API attacks follow a methodical process — from discovering what APIs exist to exploiting vulnerabilities and extracting value. Understanding this lifecycle helps defenders think like attackers and build more effective security controls.
Phase 1: Reconnaissance
Before attacking an API, attackers need to discover and understand it.
Passive Reconnaissance
- API documentation. Many organizations expose API documentation (Swagger/OpenAPI) publicly. This provides a complete map of endpoints, parameters, authentication methods, and data models — essentially an attack playbook.
- JavaScript source analysis. Frontend JavaScript contains API endpoint URLs, request formats, authentication token handling, and sometimes hardcoded API keys. Attackers analyze minified JavaScript to extract this information.
- Mobile app decompilation. Mobile apps that consume APIs can be decompiled to reveal endpoints, authentication flows, and API keys embedded in the binary.
- Search engine dorking. Google and GitHub searches reveal API endpoints, documentation, and even leaked credentials:
site:target.com inurl:api,"target.com" api_key. - Certificate transparency. CT logs reveal subdomains that may host API services:
api.target.com,api-staging.target.com,api-v2.target.com.
Active Reconnaissance
- Directory and path brute-forcing. Attackers use wordlists to discover undocumented API endpoints:
/api/admin,/api/internal,/api/debug,/api/v1,/api/v2. - HTTP method probing. Testing each endpoint with all HTTP methods (GET, POST, PUT, DELETE, PATCH) to find functionality that responds to methods the documentation doesn't mention.
- Parameter discovery. Fuzzing endpoints with common parameter names to discover undocumented parameters that may bypass security controls or expose additional data.
Phase 2: Authentication Attacks
Credential Stuffing
Using leaked username/password combinations from other breaches against the API's login endpoint. APIs without rate limiting on authentication can be tested with millions of credentials.
Token Analysis
Examining API tokens for weaknesses:
- Predictable tokens — tokens generated with insufficient randomness can be predicted
- JWT vulnerabilities — weak signing algorithms (
alg: none), key confusion attacks, information disclosure in payload - Token reuse — tokens that don't expire or can be reused across sessions
- Token leakage — tokens exposed in URLs, logs, or error messages
API Key Theft
Finding API keys in:
- Public GitHub repositories (automated scanners find these in minutes)
- Client-side JavaScript
- Mobile app binaries
- Configuration files exposed through directory traversal
- Error messages and debug output
Phase 4: Injection and Manipulation
SQL/NoSQL Injection
Injecting database queries through API parameters:
GET /api/users?name=admin' OR '1'='1
POST /api/search {"query": {"$gt": ""}}Server-Side Request Forgery (SSRF)
Manipulating APIs that fetch remote resources:
POST /api/webhook {"url": "http://169.254.169.254/latest/meta-data/"}
POST /api/import {"source": "http://internal-database:5432/"}Mass Assignment
Sending additional fields that the API shouldn't accept:
PUT /api/users/me {"name": "John", "role": "admin", "balance": 999999}Phase 5: Data Exfiltration
Once access is obtained, attackers extract data systematically:
- Pagination abuse — requesting all pages of paginated endpoints
- Response field expansion — using query parameters to include additional fields (
?fields=all,?expand=true) - Rate-limited scraping — staying below rate limits to avoid detection while slowly exfiltrating data
- GraphQL over-fetching — requesting maximum data through GraphQL's flexible query language
Defending Against API Attacks
- Minimize reconnaissance surface:
- Restrict API documentation to authenticated users
- Remove API details from client-side JavaScript where possible
- Decommission staging and debug API endpoints
- Harden authentication:
- Rate limit authentication endpoints aggressively
- Use short-lived, cryptographically strong tokens
- Never embed API keys in client-side code
- Monitor for credential stuffing patterns
- Enforce authorization:
- Object-level authorization on every endpoint
- Automated authorization testing in CI/CD
- Deny-by-default for administrative functions
- Detect and respond:
- Monitor API traffic for attack patterns
- Alert on enumeration, injection attempts, and anomalous access
- Implement API-aware WAF rules
How SeqOps fits
SeqOps doesn't test APIs. It checks the cloud and server infrastructure your APIs run on, such as network exposure, access settings and unpatched software, so the platform underneath your APIs isn't the weak point.