All resources
Topic

api

14 resources across 1 kinds

Labs & practice targets

  1. Completely Ridiculous API — intentionally vulnerable microservice API (vehicle-owner theme) built around the OWASP API Security Top 10 (BOLA/BFLA/mass assignment).

    Open ↗
  2. Deliberately vulnerable C#/.NET API-only application for learning and practicing API security.

    Open ↗
  3. Stateful FastAPI game teaching privilege escalation and long-horizon API workflows with attack/fix modes.

    Open ↗
  4. Damn Vulnerable Web Services (Node) — app with a web service and API covering IDOR, mass assignment, NoSQL/SQLi, SSRF, JWT and XXE.

    Open ↗
  5. Vulnerable Laravel API (student-grades theme) aligned to the OWASP API Security Top 10; bugs are visible, not hidden.

    Open ↗
  6. Realistic microservices app for advanced API testing: multi-user authorization, API chaining, and business workflows.

    Open ↗
  7. OWASP DevSlop MEAN-stack app with deliberately insecure APIs for scanning and API-security demos.

    Open ↗
  8. Intentionally broken Django REST API teaching information disclosure, IDOR, access control, throttling and injection flaws.

    Open ↗
  9. Vulnerable REST API teaching BOLA, mass assignment, JWT, SQLi, enumeration, and rate limits, with vulnerable and secure modes as positive/negative controls.

    Open ↗
  10. Vulnerable Adversely Programmed Interface — self-hostable PHP/Laravel API mirroring the OWASP API Top 10 through exercises.

    Open ↗
  11. Very vulnerable Node/Express web app and API (Swagger/Sqlite/Sequelize) for testing security tools and pentesting.

    Open ↗
  12. Example Python (Bottle) API vulnerable to TLS issues, user enumeration, auth bypass, SQLi and session-management flaws.

    Open ↗
  13. Vulnerable .NET/C# API built for educational purposes.

    Open ↗
  14. App based on willingly vulnerable RESTful APIs (Angular/Node).

    Open ↗