Completely Ridiculous API — web & API penetration test
A full web and API penetration test of OWASP's crAPI, aligned to the OWASP API Security Top 10, PTES and NIST SP 800-115. Six vulnerabilities were identified across 18 endpoints, covering broken authorization, authentication and data exposure. Full methodology, evidence and remediation are in the technical report.
Web & API security assessment
A full web application penetration test following the OWASP Testing Guide v4, covering authentication, authorization, API, client-side and business-logic testing. Thirteen vulnerabilities were identified and mapped to the OWASP Top 10 (2021). Full methodology, evidence and remediation are in the technical report.
Damn Vulnerable RESTaurant API — API penetration test
The DVRA assessment write-up is being finalised and will be published here.