
Automatisierte Sicherheitstests für REST API's

Penetrationstests für REST-APIs sind komplex aufgrund ständiger Änderungen an bestehenden APIs und neu hinzugefügten APIs. Astra kann von Sicherheitsingenieuren oder Entwicklern als integraler Bestandteil ihres Prozesses verwendet werden, sodass sie Schwachstellen früh im Entwicklungszyklus erkennen und beheben können. Astra kann automatisch Login und Logout (Authentifizierungs-API) erkennen und testen, sodass es für jeden einfach ist, dies in die CICD-Pipeline zu integrieren. Astra kann API-Collection als Eingabe nehmen und somit auch für Tests von APIs im Standalone-Modus verwendet werden.
$ git clone https://github.com/flipkart-incubator/Astra
$ cd Astra
$ sudo pip install -r requirements.txt
$ sudo rabbitmq-server
$ celery -A worker -loglevel=INFO
$ cd API
$ python3 api.py
$ docker pull mongo
$ docker run --name astra-mongo -d mongo
$ git clone https://github.com/flipkart-incubator/Astra.git
$ cd Astra
$ docker build -t astra .
$ docker run --rm -it --link astra-mongo:mongo -p 8094:8094 astra
$ git clone -b docker-cli https://github.com/flipkart-incubator/Astra.git
$ cd Astra
$ docker build -t astra-cli .
$ docker run --rm -it --link astra-mongo:mongo astra-cli
- requests
- logger
- pymongo
- ConfigParser
- pyjwt
- flask
- sqlmap
- celery
$ python astra.py --help
_
/\ | |
/ \ ___| |_ _ __ __ _
/ /\ \ / __| __| '__/ _` |
/ ____ \__ \ |_| | | (_| |
/_/ \_\___/\__|_| \__,_|
usage: astra.py [-h] [-c {Postman,Swagger}] [-n COLLECTION_NAME] [-u URL]
[-headers HEADERS] [-method {GET,POST}] [-b BODY]
[-l LOGINURL] [-H LOGINHEADERS] [-d LOGINDATA]
REST API Security testing Framework
optional arguments:
-h, --help show this help message and exit
-c {Postman,Swagger}, --collection_type {Postman,Swagger}
Type of API collection
-n COLLECTION_NAME, --collection_name COLLECTION_NAME
Type of API collection
-u URL, --url URL URL of target API
-headers HEADERS, --headers HEADERS
Custom headers.Example: {"token" : "123"}
-method {GET,POST}, --method {GET,POST}
HTTP request method
-b BODY, --body BODY Request body of API
-l LOGINURL, --loginurl LOGINURL
URL of login API
-H LOGINHEADERS, --loginheaders LOGINHEADERS
Headers should be in a dictionary format. Example:
{"accesstoken" : "axzvbqdadf"}
-d LOGINDATA, --logindata LOGINDATA
login data of API
Führen Sie die api.py aus und greifen Sie über http://127.0.0.1:8094 auf die Weboberfläche zu.
$ cd API
$ python api.py
HINWEIS:
Unter macOS 10.13+ müssen Sie das Flag OBJC_DISABLE_INITIALIZE_FORK_SAFETY=YES verwenden, um zu verhindern, dass Scanprozesse aufgrund der geänderten Funktionsweise von fork() und exec() beendet werden. Weitere Informationen finden Sie hier.
$ cd API
$ OBJC_DISABLE_INITIALIZE_FORK_SAFETY=YES python api.py



