~ crAPI beta announcement ~

211 views
Skip to first unread message

Inon Shkedy

unread,
Feb 9, 2021, 11:23:01 AM2/9/21
to API Security Project

Hello API Security community!

After many vulnerable lines of code have been written, we are pleased to announce the beta version of crAPI!

crAPI stands for a Completely Ridiculous API. Following the footsteps of Webgoat and JuiceShop, crAPI is an intentionally vulnerable application, but it is primarily focused on APIs for the purpose of teaching, learning, and practicing API security.

You will not find the mundane XSS and SQLi challenges here. crAPI only has vulnerabilities that actually happen in modern API based applications, including all those in the OWASP Top 10 for APIs! All the challenges in crAPI are based on real-life vulnerabilities that were found in APIs of big companies like Facebook, Uber and Shopify. 

So if you are a pen-tester, a security engineer, a developer, or a security enthusiast, you are more than welcome to hack crAPI!

At this point, we are announcing the project only through the mailing list. We would love to get feedback from security experts like you so we can validate the hacks and fix embarrassing bugs before we do a bigger release.

GitHub: https://github.com/owasp/crapi

Hosted live version: crapi.io

Cheers,
Inon Shkedy

Ailton da SIlva dos Santos Filhos

unread,
Feb 10, 2021, 2:55:29 PM2/10/21
to Inon Shkedy, API Security Project
Hi, Inon,

Great! I'm sure the community was looking for an intentionally vulnerable application since 2019 to serve as a benchmark and playground.
I'll give it a try for sure.
When you want to spread it widely, let us know to help share it.

Best regards,
Ailton

--
You received this message because you are subscribed to the Google Groups "API Security Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email to api-security-pro...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/api-security-project/96ac0500-bdd0-4fb8-8a3a-da73e4049e2fn%40owasp.org.


--
Att. Ailton da Silva dos Santos Filho
Mestre em Ciência da Computação
Engenheiro da Computação

Amit Finegold

unread,
Feb 14, 2021, 3:56:41 PM2/14/21
to API Security Project, Inon Shkedy
Hi All,

I'm planning to present the OWAST Top 10 for API Security to the developers and archiects at my company next week.
Before I head to build my own PPT presentation about it, I was wondering if there is any presantation available.

Thanks a lot,
Amit


Paulo Silva

unread,
Feb 14, 2021, 5:39:30 PM2/14/21
to Amit Finegold, API Security Project, Inon Shkedy
Hi Amit,
Check out what's available here [1] and search this mailing list earlier threads: I remember some presentations were shared here when OWASP API Securiry Top 10 2019 was first published.


Cheers,

Paulo Silva

unread,
Feb 14, 2021, 5:42:30 PM2/14/21
to Amit Finegold, API Security Project, Inon Shkedy


On Sun, Feb 14, 2021, 10:39 PM Paulo Silva <paulo...@owasp.org> wrote:
Hi Amit,
Check out what's available here [1] and search this mailing list earlier threads: I remember some presentations were shared here when OWASP API Securiry Top 10 2019 was first published.


Amit Finegold

unread,
Feb 15, 2021, 12:21:08 AM2/15/21
to Paulo Silva, API Security Project, Inon Shkedy
Thanks a lot Paulo 🙏

Paulo Silva

unread,
Feb 15, 2021, 2:35:40 AM2/15/21
to Amit Finegold, API Security Project, Inon Shkedy
My pleasure! 

Isabelle Mauny

unread,
Feb 15, 2021, 3:23:14 AM2/15/21
to Amit Finegold, Paulo Silva, API Security Project, Inon Shkedy
Hello Amit,

We have also created a bunch of free resources you may want to use : 

including this cheat sheet, which you are free to re-distribute.

Good luck with the course!

Isabelle.
____________________
Isabelle Mauny - Field CTO and Co-Founder - 42Crunch


Reply all
Reply to author
Forward
0 new messages