The challenge
Garudaku's B2B service API is public and internet-facing, and every partner authentication, data exchange and transaction runs through it. With no validated WAF, API gateway or rate limiter in front of it, one authorisation flaw could expose several partners at once.
Executive Summary
Garudaku operates a digital platform serving users across Indonesia through web and mobile channels. Behind it runs a business-to-business (B2B) service API — the backbone of the partner-facing web application that handles partner authentication, data exchange, and transactions. That API is public and internet-facing.
Zentara proposes a single VAPT engagement: a black-box penetration test of the B2B API, mapped to the OWASP API Security Top 10 (2023) and the OWASP Top 10 (2023). The test combines automated scanning with manual exploitation from certified operators, targeting the vulnerability classes that dominate real-world API incidents — authorization, authentication, and business logic.
The timing is not incidental. In 2025, 87% of organizations experienced an API-related security incident, average daily API attacks rose 113% year-over-year, and 61% of API attacks now arrive through unauthorized workflows rather than head-on authentication breaks. A public B2B API without a validated WAF, gateway, or rate limiter carries maximal, global exposure.
The engagement closes with more than a finding list: every issue is reproduced, CVSS-rated, and paired with remediation guidance, a developer knowledge-transfer session, and a retest to confirm closure. The validated report becomes objective evidence of independent testing for partners, the board, and regulators under UU PDP No. 27/2022 and PP No. 71/2019.
Public API B2B · internet-facing | Black-Box Test approach | OWASP API Top 10 (2023) standard | Production Environment |
Client Profile & Platform Context
Client Profile
Garudaku is an Indonesian digital platform that delivers technology-based services to its users, accessible anytime through web and mobile applications. The platform handles the full lifecycle of digital activity — user registration, account authentication, personal-data management, and service transactions — connected through a modern application architecture.
Behind the scenes, Garudaku operates a web application layer, a mobile application, server infrastructure, and a set of APIs that link internal modules and integrate with third-party partners. Growth in these services brings a matching responsibility: protecting user data, transactions, and partner integrations that flow through the platform.
The Asset Under Test
The in-scope asset is Garudaku’s B2B service API — the backbone for the B2B web application that serves business partners. The following technical profile was supplied by Garudaku through the pre-engagement questionnaire.
Parameter | Response |
API Project Name | *.garudaku.com |
Primary Purpose | B2B service API — backbone for the partner-facing B2B web application |
Testing Environment | Production |
API Availability | Public (internet-facing) |
Method of Access | Direct internet connection |
Test Approach | Black-Box (to be confirmed during Scoping) |
Why the asset matters. The B2B API is the trust boundary between Garudaku and its business partners. Every partner authentication, data exchange, and transaction passes through it — so a single authorization flaw can expose multiple partners at once. |
The Challenge — API Risk at Internet Scale
APIs have become the primary attack surface for internet-facing platforms. Attackers favor them because they expose business logic and data directly, often with weaker authorization than the web front end. The market data makes the trend concrete.
Metric | Value | Source |
Organizations hit by an API security incident (2025) | 87% | Akamai SOTI 2026 |
YoY growth in average daily API attacks | +113% (121→258 / org / day) | Akamai SOTI 2026 |
API attacks via unauthorized workflows | 61% (up from 30% in 2024) | Akamai SOTI 2026 |
Web attacks recorded in 2024 | 311 billion (+33% YoY) | Akamai SOTI 2025 |
API attacks recorded (Jan 2023 – Dec 2024) | 150 billion | Akamai SOTI 2025 |
Growth in OWASP API Top 10–related incidents | +32% | Akamai SOTI 2025 |
API incidents observed in H1 2025 | ~40,000 (80,000+ projected) | Thales Imperva 2025 |
Advanced bot traffic aimed at APIs | 44% | Thales Imperva 2025 |
The exploitation pattern is equally telling. Among actively exploited APIs in 2025, security misconfiguration accounted for 40%, broken object property level authorization for 35%, and broken authentication for 19% (Akamai SOTI 2026). All three fall squarely within authorization, authentication, and configuration — exactly the classes a black-box API test is built to surface.
The public B2B API is the exposed edge. Garudaku’s API answers to anyone with an internet connection. Without a validated WAF, API gateway, or rate limiter in front of it, the attack surface is maximal and global. This engagement measures that exposure from the attacker’s vantage point — not from an assumption. |
Problem Identification
The pre-engagement data maps to a set of concrete risk hypotheses. Each becomes a test case with a pass/fail verdict backed by reproducible evidence.
Risk Hypothesis | What Zentara Validates |
Maximal public exposure | Enumeration of internet-reachable endpoints and shadow / undocumented APIs |
No confirmed perimeter control | Presence and effectiveness of WAF, API gateway, and rate limiting |
JWT / token weaknesses | Signature validation, algorithm confusion, expiry, replay, and privilege claims |
B2B business logic | Partner scoping, order / transaction abuse, workflow bypass, mass assignment |
Authorization model (BOLA / BFLA) | Cross-partner object access and function-level privilege escalation |
Infrastructure segregation | Tenant / partner isolation and blast-radius containment |
From questionnaire to evidence. Each hypothesis becomes a documented test with a verdict and reproducible proof — replacing open questions about the platform’s posture with measured facts. |
The Zentara Solution — Engagement Design
The engagement follows Zentara’s VAPT methodology: a hybrid of automated tooling for coverage and manual exploitation for depth, executed by certified operators and governed by a zero false-positive policy. Reporting is dual-layer — an executive summary and a technical findings report.
Phase | Focus | Key Output |
1 Scoping & RoE | Confirm scope, boundaries, escalation contacts, legal authorization; confirm the black-box approach | Signed Rules of Engagement |
2 Reconnaissance | OSINT, subdomain and endpoint enumeration, service and API surface mapping | Attack-surface map |
3 Vulnerability Assessment | Automated and manual scanning, misconfiguration and exposure checks, finding validation | Validated vulnerability inventory |
4 Penetration Testing | Manual exploitation — authorization abuse, auth / token attacks, business-logic abuse, chained escalation | Proven exploit paths |
5 Reporting | Executive summary plus technical findings, each with CVSS rating and remediation | VAPT report (dual-layer) |
6 Remediation Support | Developer workshop and retesting after fixes | Closure validation |
Hybrid by design. Automated tooling gives coverage; certified operators (OSCP, OSCE, GPEN, GXPN) give depth. Every reported finding is manually validated — Zentara’s zero false-positive policy. |
Outcome & next steps
Outcome & next steps
Delivered: a black-box test of the B2B API against the OWASP API Security Top 10 (2023); an executive report and a technical report with every finding reproduced, CVSS v3.1 rated and paired with remediation guidance; proof-of-concept evidence for each validated exploit; a knowledge-transfer workshop for Garudaku's developers; and a retest to confirm closure.
