{"repo":"erev0s/VAmPI","free":true,"listed":false,"github":"https://github.com/erev0s/VAmPI","clone":"git clone https://github.com/erev0s/VAmPI.git","description":"Vulnerable REST API with OWASP top 10 vulnerabilities for security testing","language":"Python","stars":1308,"topics":["api","api-rest","security-tools","vulnerable-web-app"],"license":"MIT","category":"api-integrations-sdks","readme_excerpt":"VAmPI The Vulnerable API (Based on OpenAPI 3) VAmPI is a vulnerable API made with Flask and it includes vulnerabilities from the OWASP top 10 vulnerabilities for APIs. It was created as I wanted a vulnerable API to evaluate the efficiency of tools used to detect security issues in APIs. It includes a switch on/off to allow the API to be vulnerable or not while testing. This allows to cover better the cases for false positives/negatives. VAmPI can also be used for learning/teaching purposes. You can find a bit more details about the vulnerabilities in erev0s.com. Features - Based on OWASP Top 10 vulnerabilities for APIs. - OpenAPI3 specs and Postman Collection included. - Global switch on/off to have a vulnerable environment or not. - Token-Based Authentication (Adjust lifetime from within app.py) - Available Swagger UI to directly interact with the API VAmPI's flow of actions is going like this: an unregistered user can see minimal information about the dummy users included in the API. A user can register and then login to be allowed using the token received during login to post a book. For a book posted the data accepted are the title and a secret about that book. Each book is unique for every user and only the owner of the book should be allowed to view the secret. A quick rundown of the actions included can be seen in the following table: Action Path Details :----------: :-----------------------------: :--------------------------------------------------: GET /createdb Crea","default_branch":null,"files":null,"tree":[],"storefront":"/r/erev0s","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/erev0s/VAmPI/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}