Skip to main content

Empty Strings

ItemDescription
Full Fuzzer NameEmptyStringsInFieldsFuzzer
Log KeyESIF
DescriptionThis fuzzer will send empty values in fields. The expectation is that APIs will reject the request as invalid for required fields.
Enabled by default?Yes
Target field typesAll fields
Expected result when fuzzed field is required4XX
Expected result when fuzzed field is optional2XX
Expected result when fuzzed value is not matching field pattern4XX
Fuzzing logicIteratively replaces fields with empty values
Conditions when this fuzzer will be skippedWhen HTTP method is GET or DELETE and field is NOT a query parameter
HTTP methods that will be skippedNone
ReportingReports error if: 1. response code is 404; 2. response code is documented, but not expected; 3. any unexpected exception.

Reports warn if: 1. response code is expected and documented, but not matches response schema; 2. response code is expected, but not documented; 3. response code is 501.

Reports success if: 1. response code is expected, documented and matches response schema.