Skip to content
View broCapang's full-sized avatar
☢️
☢️

Highlights

  • Pro

Block or report broCapang

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

fyp

beneficial for my FYP
20 repositories

Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure

Java 1,017 195 Updated Oct 19, 2024

Damn Vulnerable Restaurant is an intentionally vulnerable Web API game for learning and training purposes dedicated to developers, ethical hackers and security engineers.

Python 433 68 Updated Jul 22, 2024

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Java 455 93 Updated May 13, 2023

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Python 908 360 Updated Aug 18, 2024

An API security tool to capture and analyze API traffic, test API endpoints, reconstruct Open API specification, and identify API security risks. 

Go 512 63 Updated Oct 8, 2024

Automated Security Testing For REST API's

Python 2,497 401 Updated Jun 5, 2024

API Security Vulnerability Scanner designed to help you secure your APIs.

Go 74 6 Updated Oct 17, 2024

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …

Go 20,349 2,481 Updated Oct 19, 2024

A wordlist of API names for web application assessments

752 214 Updated Jan 20, 2023

A REST API security testing framework.

Python 324 63 Updated Dec 4, 2021

Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

Rust 1,131 81 Updated Oct 16, 2024
Python 49 19 Updated Sep 3, 2024

Contextual Content Discovery Tool

Go 2,619 296 Updated Apr 29, 2024

Automated & Manual Wordlists provided by Assetnote

CSS 1,305 134 Updated Jul 31, 2024

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

HTML 1,166 303 Updated Aug 11, 2023

completely ridiculous API (crAPI)

Java 1,095 340 Updated Sep 13, 2024

In-depth attack surface mapping and asset discovery

Go 11,949 1,880 Updated Oct 19, 2024

Damn Vulnerable Web Services is a vulnerable application with a web service and an API that can be used to learn about webservices/API related vulnerabilities.

JavaScript 450 175 Updated Oct 15, 2024
Python 69 27 Updated May 1, 2023

The Pixi module is a MEAN Stack web app with wildly insecure APIs!

JavaScript 110 81 Updated Dec 22, 2022