ZENTARA
← All impact studies
Offensive security/ Digital platforms

Securing a Public-Facing B2B API

A black-box penetration test of Garudaku's internet-facing B2B API, the service every partner authentication, data exchange and transaction passes through.

GarudakuCompleted engagement
Garudaku
Illustrative imagery

Completed engagement. Source study dated August 2026. Specific findings are not published. Industry statistics are cited from Akamai SOTI 2025 and 2026 and Thales Imperva 2025.

Scope
Black-box
Test approach
Attacker's-eye view
Scope
OWASP API Top 10
Test standard
2023 edition
Scope
6 phases
Engagement phases
Scoping to retest
Scope
100%
Findings manually validated
Zero false-positive policy

The challenge

Garudaku's B2B service API is public and internet-facing, and every partner authentication, data exchange and transaction runs through it. With no validated WAF, API gateway or rate limiter in front of it, one authorisation flaw could expose several partners at once.

Executive Summary

Garudaku operates a digital platform serving users across Indonesia through web and mobile channels. Behind it runs a business-to-business (B2B) service API — the backbone of the partner-facing web application that handles partner authentication, data exchange, and transactions. That API is public and internet-facing.

Zentara proposes a single VAPT engagement: a black-box penetration test of the B2B API, mapped to the OWASP API Security Top 10 (2023) and the OWASP Top 10 (2023). The test combines automated scanning with manual exploitation from certified operators, targeting the vulnerability classes that dominate real-world API incidents — authorization, authentication, and business logic.

The timing is not incidental. In 2025, 87% of organizations experienced an API-related security incident, average daily API attacks rose 113% year-over-year, and 61% of API attacks now arrive through unauthorized workflows rather than head-on authentication breaks. A public B2B API without a validated WAF, gateway, or rate limiter carries maximal, global exposure.

The engagement closes with more than a finding list: every issue is reproduced, CVSS-rated, and paired with remediation guidance, a developer knowledge-transfer session, and a retest to confirm closure. The validated report becomes objective evidence of independent testing for partners, the board, and regulators under UU PDP No. 27/2022 and PP No. 71/2019.

Public API

B2B · internet-facing

Black-Box

Test approach

OWASP API

Top 10 (2023) standard

Production

Environment

Client Profile & Platform Context

Client Profile

Garudaku is an Indonesian digital platform that delivers technology-based services to its users, accessible anytime through web and mobile applications. The platform handles the full lifecycle of digital activity — user registration, account authentication, personal-data management, and service transactions — connected through a modern application architecture.

Behind the scenes, Garudaku operates a web application layer, a mobile application, server infrastructure, and a set of APIs that link internal modules and integrate with third-party partners. Growth in these services brings a matching responsibility: protecting user data, transactions, and partner integrations that flow through the platform.

The Asset Under Test

The in-scope asset is Garudaku’s B2B service API — the backbone for the B2B web application that serves business partners. The following technical profile was supplied by Garudaku through the pre-engagement questionnaire.

Parameter

Response

API Project Name

*.garudaku.com

Primary Purpose

B2B service API — backbone for the partner-facing B2B web application

Testing Environment

Production

API Availability

Public (internet-facing)

Method of Access

Direct internet connection

Test Approach

Black-Box (to be confirmed during Scoping)

Why the asset matters. The B2B API is the trust boundary between Garudaku and its business partners. Every partner authentication, data exchange, and transaction passes through it — so a single authorization flaw can expose multiple partners at once.

The Challenge — API Risk at Internet Scale

APIs have become the primary attack surface for internet-facing platforms. Attackers favor them because they expose business logic and data directly, often with weaker authorization than the web front end. The market data makes the trend concrete.

Metric

Value

Source

Organizations hit by an API security incident (2025)

87%

Akamai SOTI 2026

YoY growth in average daily API attacks

+113% (121→258 / org / day)

Akamai SOTI 2026

API attacks via unauthorized workflows

61% (up from 30% in 2024)

Akamai SOTI 2026

Web attacks recorded in 2024

311 billion (+33% YoY)

Akamai SOTI 2025

API attacks recorded (Jan 2023 – Dec 2024)

150 billion

Akamai SOTI 2025

Growth in OWASP API Top 10–related incidents

+32%

Akamai SOTI 2025

API incidents observed in H1 2025

~40,000 (80,000+ projected)

Thales Imperva 2025

Advanced bot traffic aimed at APIs

44%

Thales Imperva 2025

The exploitation pattern is equally telling. Among actively exploited APIs in 2025, security misconfiguration accounted for 40%, broken object property level authorization for 35%, and broken authentication for 19% (Akamai SOTI 2026). All three fall squarely within authorization, authentication, and configuration — exactly the classes a black-box API test is built to surface.

The public B2B API is the exposed edge. Garudaku’s API answers to anyone with an internet connection. Without a validated WAF, API gateway, or rate limiter in front of it, the attack surface is maximal and global. This engagement measures that exposure from the attacker’s vantage point — not from an assumption.

Problem Identification

The pre-engagement data maps to a set of concrete risk hypotheses. Each becomes a test case with a pass/fail verdict backed by reproducible evidence.

Risk Hypothesis

What Zentara Validates

Maximal public exposure

Enumeration of internet-reachable endpoints and shadow / undocumented APIs

No confirmed perimeter control

Presence and effectiveness of WAF, API gateway, and rate limiting

JWT / token weaknesses

Signature validation, algorithm confusion, expiry, replay, and privilege claims

B2B business logic

Partner scoping, order / transaction abuse, workflow bypass, mass assignment

Authorization model (BOLA / BFLA)

Cross-partner object access and function-level privilege escalation

Infrastructure segregation

Tenant / partner isolation and blast-radius containment

From questionnaire to evidence. Each hypothesis becomes a documented test with a verdict and reproducible proof — replacing open questions about the platform’s posture with measured facts.

The Zentara Solution — Engagement Design

The engagement follows Zentara’s VAPT methodology: a hybrid of automated tooling for coverage and manual exploitation for depth, executed by certified operators and governed by a zero false-positive policy. Reporting is dual-layer — an executive summary and a technical findings report.

Phase

Focus

Key Output

1 Scoping & RoE

Confirm scope, boundaries, escalation contacts, legal authorization; confirm the black-box approach

Signed Rules of Engagement

2 Reconnaissance

OSINT, subdomain and endpoint enumeration, service and API surface mapping

Attack-surface map

3 Vulnerability Assessment

Automated and manual scanning, misconfiguration and exposure checks, finding validation

Validated vulnerability inventory

4 Penetration Testing

Manual exploitation — authorization abuse, auth / token attacks, business-logic abuse, chained escalation

Proven exploit paths

5 Reporting

Executive summary plus technical findings, each with CVSS rating and remediation

VAPT report (dual-layer)

6 Remediation Support

Developer workshop and retesting after fixes

Closure validation

Hybrid by design. Automated tooling gives coverage; certified operators (OSCP, OSCE, GPEN, GXPN) give depth. Every reported finding is manually validated — Zentara’s zero false-positive policy.

Outcome & next steps

Outcome & next steps

Delivered: a black-box test of the B2B API against the OWASP API Security Top 10 (2023); an executive report and a technical report with every finding reproduced, CVSS v3.1 rated and paired with remediation guidance; proof-of-concept evidence for each validated exploit; a knowledge-transfer workshop for Garudaku's developers; and a retest to confirm closure.

Related capabilities