|
|
|
|
|
by 1690v
3263 days ago
|
|
It also expands the total attack surface of a system, which can lead to security problems. If you read some of the public disclosures from various bug bounty programs, neglected APIs have led to some serious vulnerabilities. "Underprotected APIs" is actually number 10 on the OWASP Top 10 for 2017. |
|
Conceptually, it's just a listening server on the public Internet, and will be subject to arbitrary data anyone willing to connect to it can send.