purpleteam-labs / purpleteam

CLI component of OWASP PurpleTeam
https://owasp.org/www-project-purpleteam
Other
121 stars 15 forks source link

Create API SUT and test #62

Open binarymist opened 3 years ago

binarymist commented 3 years ago

SUT Resources

Mentioned by Nicholas Tolstoshev on #project-zap of OWASP Slack

Mentioned by @ricekot on #project-zap of OWASP Slack

Mentioned by @kingthorin_rm on #project-zap of OWASP Slack

Mentioned by @Kinnaird McQuade on #project-zap of OWASP Slack

binarymist commented 2 years ago

Todo

API types we need to support

Authentication Strategies

Basically anything, or as many as possible that Zaproxy supports, there are quite a few Zap resources now. Google does well at listing them.

Basically we want to support as many as possible.

shaneg07 commented 2 years ago
OpenAPI SOAP GraphQL Import URLs Script Based Authentication JSON Based Authentication HTTP/NTLM based authentication Active Stars Pull Requests Issues Contributors Tested Locally Comments
[Recent commits or Active PRs/Issues] [main/minor]
crAPI 249 3 (51 closed) 6 (21 closed) 1 main / 6
juice-shop 7000 0 ((1121 close) 2 (708 closed) 14 main / 77
Damn-Vulnerable-GraphQL-Application 1000 0 (38 closed) 1 (18 closed) 2 main / 1 https://notepad.pw/code/5pa89yk6 as described in Slack
vuln-graphql-ruby ✓ (apr'21) 0 4 (0 closed) 0 (0 closed) 2 main
poc-graphql ✓(sep'20) 339 0 0 1 main
VAmPI 275 0 (12 closed) 1 (7 closed) 2 main / 1
Vulnerable-Web-Services No 6 0 0 1 main
vulny-spring-soap-api No 0 0 0 2 main
vulnerable-graphql-api No 36 0 0 2 main
Pixi No 54 2(2 closed) 23(7 closed) 2 main
parabank Yes 31 30(29 closed) 3(3 closed) 2 main