O Preventing Web Services Enumeration and Manipulation

Developers often don't implement security within their web services code since they assume that the web service will be accessed by another computer, rather than an enduser within a web browser. This leaves the web service open to attack, potentially leading to the confidentiality, integrity, and availability of the application and its data becoming compromised. Due to the nature of web services interacting with multiple systems and across multiple organizations, some additional security controls are also required to ensure that web services cannot be manipulated.

