API Security Assessment and Penetration Testing for Mifos Payment Hub EE
Mifos Payment Hub EE is a payment orchestration engine that coordinates and routes payment transactions among core banking systems, switches, wallets, and external financial partners. The Payment hub exposes multiple APIs for payment initiation, status queries, partner integrations, and operational management, creating a large surface area for critical risks such as Broken or inconsistent authorisation across endpoints, replay or duplicate payment requests. This project will focus on conducting a comprehensive API security assessment of the Payment Hub API, with emphasis on the OWASP API Security Top 10 and real-world payment threat models. The goal is to identify, document, and help mitigate security vulnerabilities within the system’s RESTful APIs. This project will be centred mainly around: - API Surface Mapping, which deals with enumerating the APIs found in the PaymentHub and identifying the authentication flows, request headers and partner-specific parameters used. - Threat modelling deals with mapping the threats found to the OWASP category - API Penetration Testing focused on the OWASP API Security Top 10 - Tooling and Automation, dealing with developing custom scripts and reusable test cases - Reporting and Remediation, dealing with producing a detailed vulnerability report and providing fixes and mitigation to the different vulnerabilities found. By the end of the project, the following deliverables are expected: 1) A documented Payment Hub EE API threat model and API Penetration testing checklist 2) An automated or semi-automated API security test suite for reusing in other projects 3) A detailed vulnerability assessment report with remediation guidance will be provided to help developers make patches when needed and follow secure API Practices.
Project details
Technologies
Not listed in the archive