TGViewer
DevSecOps Talks DevSecOps Talks @devsecops_weekly · 8.05K subscribers
Post #618 2.02K
Capital: приложение с уязвимым API

Всем привет!

В repo можно найти Capital – приложение, разработанное Checkmarx, обладающее уязвимым API (в соответствии с OWASP Top-10 для API).

В приложении можно найти:
🍭 Broken Function Level Authorization
🍭 Broken Object Level Authorization
🍭 Broken User Authentication
🍭 Improper API Management
🍭 Excessive Data Exposure
🍭 Improper Assets Management
🍭 Lack of Resources and Rate Limiting
🍭 Security Misconfigurations
🍭 Injection
🍭 Mass Assignment
🍭 Security Misconfiguration
🍭 Insufficient Logging

Подробнее об истории разработки, примерах атак и о приложении в целом можно прочесть в статье.
GitHub GitHub - Checkmarx/capital: A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal… A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF. - ...
  • ❤ 5
More from @devsecops_weekly
  1. Oct 7, 2026Vulnerable Bank Application! Всем привет! Да, всё так! Ещё одно «заведомо уязвимое приложе…
  2. Oct 6, 2026Генерация подозрительных событий Всем привет! По ссылке можно найти репозиторий с утилитой…
  3. Oct 5, 2026Удаление чувствительных данных из журналов событий Всем привет! Утечки конфиденциальных да…
  4. Oct 2, 2026AI Coding Agent Security Benchmark Всем привет! Команда Endor Labs задалась вопросом наско…
  5. Oct 1, 2026Platform Skills Всем привет! По ссылке доступен GitHub-репозиторий, в котором можно найти…
  6. Sep 30, 2026Vaikora LLM Gateway Всем привет! С повсеместным использованием AI-агентов всё чаще встреча…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →