akto-api-security / akto

Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure
https://www.akto.io/
MIT License
976 stars 190 forks source link

⚡️ Run akto on a vulnerable app to find a bug. #131

Open ayushaga14 opened 1 year ago

ayushaga14 commented 1 year ago

💭 Introduction This task involves using Akto to run tests on vulnerable apps like juice-shop, rest-api-goat etc. Users can view the test results and check the vulnerabilities. You can also check and report if we are detecting any false positives, i.e. vulnerabilities that are wrongly detected by Akto. You can add data to Akto dashboard using burp suite, postman etc. For ex - Refer to burp documentation - https://docs.akto.io/add-api-data/integrations/burp-suite.

🎯 Requirements Setting up a vulnerable application locally and using applications like BurpSuite/Postman etc to send data to Akto

✅ Task summary:

🙋🏼‍♂️ Questions: If you have questions, need any help, or just want to hang out, make sure to join us on our Discord server.

mohithkalyan commented 10 months ago

Hi, I'd like to work on this. I'd anyways test this on a vulnerable app to look at the efficiency and FP count before I could implement it in our CI/CD. Feel free to assign this to me.

avneesh-akto commented 10 months ago

Assigned it to you @mohithkalyan . Happy hacking. Feel free to join our Discord