api
14 resources across 1 kinds
Labs & practice targets
- Open ↗
Deliberately vulnerable C#/.NET API-only application for learning and practicing API security.
- Open ↗
Stateful FastAPI game teaching privilege escalation and long-horizon API workflows with attack/fix modes.
- Open ↗
Vulnerable Laravel API (student-grades theme) aligned to the OWASP API Security Top 10; bugs are visible, not hidden.
- Open ↗
Realistic microservices app for advanced API testing: multi-user authorization, API chaining, and business workflows.
- Open ↗
Intentionally broken Django REST API teaching information disclosure, IDOR, access control, throttling and injection flaws.
- Open ↗
Very vulnerable Node/Express web app and API (Swagger/Sqlite/Sequelize) for testing security tools and pentesting.
- Open ↗
Example Python (Bottle) API vulnerable to TLS issues, user enumeration, auth bypass, SQLi and session-management flaws.
- Open ↗
Vulnerable .NET/C# API built for educational purposes.