- А Сollection Of Awesome API Security Tools And Resources https://go.wlrm.tl/github 4 comments opensource
Linked pages
- How to Hack APIs in 2021 by Hakluke and Farah Hawa | Detectify Labs https://labs.detectify.com/2021/08/10/how-to-hack-apis-in-2021/ 108 comments
- GitHub - alufers/mitmproxy2swagger: Automagically reverse-engineer REST APIs via capturing traffic https://github.com/alufers/mitmproxy2swagger 86 comments
- GitHub - shieldfy/API-Security-Checklist: Checklist of the most important security countermeasures when designing, testing, and releasing your API https://github.com/shieldfy/API-Security-Checklist 73 comments
- HTTP Status Codes Glossary - WebFX https://httpstatuses.com/ 48 comments
- GitHub - Bo0oM/fuzz.txt: Potentially dangerous files https://github.com/bo0om/fuzz.txt 40 comments
- GitHub - blst-security/cherrybomb: Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests. https://github.com/blst-security/cherrybomb 29 comments
- GitHub - Endava/cats: CATS is a REST API Fuzzer and negative testing tool for OpenAPI endpoints. CATS automatically generates, runs and reports tests with minimum configuration and no coding effort. Tests are self-healing and do not require maintenance. https://github.com/Endava/cats 28 comments
- https://assets.pentesterlab.com/jwt_security_cheatsheet/jwt_security_cheatsheet.pdf 27 comments
- The complete GraphQL Security Guide: Fixing the 13 most common GraphQL Vulnerabilities to make your API production ready - WunderGraph https://wundergraph.com/blog/the_complete_graphql_security_guide_fixing_the_13_most_common_graphql_vulnerabilities_to_make_your_api_production_ready 17 comments
- JSON:API — Latest Specification (v1.1) https://jsonapi.org/format/ 13 comments
- GitHub - flipkart-incubator/Astra: Automated Security Testing For REST API's https://github.com/flipkart-incubator/astra 9 comments
- GitHub - s0md3v/Arjun: HTTP parameter discovery suite. https://github.com/s0md3v/arjun 7 comments
- GitHub - wallarm/gotestwaf: An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses https://github.com/wallarm/gotestwaf 7 comments
- https://www.tenchisecurity.com/blog/thefaultinourstars 5 comments
- APICheck Project Documentation https://bbva.github.io/apicheck/ 5 comments
- API Security Best Practices MegaGuide https://expeditedsecurity.com/api-security-best-practices-megaguide/ 4 comments
- GitHub - wallarm/api-firewall: Fast and light-weight API proxy firewall for request and response validation by OpenAPI specs. https://github.com/wallarm/api-firewall 2 comments
- OWASP Top 10 for API https://application.security/free/owasp-top-10-API 2 comments
- GitHub - microsoft/restler-fuzzer: RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services. https://github.com/microsoft/restler-fuzzer 2 comments
- API Security Articles, News, Vulnerabilities & Best Practices https://apisecurity.io 0 comments