O&D Cyber SECURITY ASSESSMENTS
API Security Assessment

crAPI

Completely Ridiculous API — web & API penetration test

06FINDINGS
04CRITICAL
02HIGH
Lab assessment / demonstration. Performed against OWASP's intentionally vulnerable crAPI application for security training. Not a client engagement; contains no real customer data.

Summary

OVERALL RISK: CRITICAL

A full web and API penetration test of OWASP's crAPI, aligned to the OWASP API Security Top 10, PTES and NIST SP 800-115. Six vulnerabilities were identified across 18 endpoints, covering broken authorization, authentication and data exposure. Full methodology, evidence and remediation are in the technical report.

CRITBroken Object Level Authorization (BOLA) CRITJWT alg:none signature bypass CRITPrivilege escalation to admin HIGHExcessive data exposure HIGHUnrestricted file upload

Tooling: Burp Suite, Postman, Nmap, jwt.io, CyberChef. See the technical report (PDF) for proof-of-concept, screenshots and CVSS scoring.

Web Application Penetration Test

OWASP Juice Shop

Web & API security assessment

13FINDINGS
02CRITICAL
06HIGH
05MEDIUM
Lab assessment / demonstration. Performed against OWASP Juice Shop, an intentionally vulnerable application for security training. Not a client engagement; contains no real customer data.

Summary

OVERALL RISK: CRITICAL

A full web application penetration test following the OWASP Testing Guide v4, covering authentication, authorization, API, client-side and business-logic testing. Thirteen vulnerabilities were identified and mapped to the OWASP Top 10 (2021). Full methodology, evidence and remediation are in the technical report.

CRITSQL injection — login bypass & admin takeover CRITJWT manipulation — privilege escalation HIGHXSS with token exfiltration HIGHIDOR / BOLA HIGHUnauthenticated /api/Users HIGHNegative-quantity business logic flaw MED/ftp directory exposure

Tooling: Burp Suite, Nmap, Wappalyzer, jwt.io, CyberChef, RockYou wordlist. See the technical report (PDF) for proof-of-concept, screenshots and CVSS scoring.

API Security Assessment

DVRA

Damn Vulnerable RESTaurant API — API penetration test

Report coming soon

The DVRA assessment write-up is being finalised and will be published here.