Security Training Platform
OWASP Top 10 Lab
Interactive security training covering the OWASP Web Application Top 10 (2021) and API Security Top 10 (2023). Read the theory, then exploit live vulnerable endpoints to find the flags.
OWASP Web Top 10
2021The most critical security risks to web applications.
- A01:2021 Broken Access Control
- A02:2021 Cryptographic Failures
- A03:2021 Injection
- A04:2021 Insecure Design
- A05:2021 Security Misconfiguration
- A06:2021 Vulnerable & Outdated Components
- A07:2021 Identification & Authentication Failures
- A08:2021 Software & Data Integrity Failures
- A09:2021 Security Logging & Monitoring Failures
- A10:2021 Server-Side Request Forgery
OWASP API Top 10
2023The unique security risks of modern APIs.
- API1:2023 Broken Object Level Authorization
- API2:2023 Broken Authentication
- API3:2023 Broken Object Property Level Authorization
- API4:2023 Unrestricted Resource Consumption
- API5:2023 Broken Function Level Authorization
- API6:2023 Unrestricted Access to Sensitive Business Flows
- API7:2023 Server Side Request Forgery
- API8:2023 Security Misconfiguration
- API9:2023 Improper Inventory Management
- API10:2023 Unsafe Consumption of APIs
Total Flags
22
Web Challenges
10 items, 17 challenges
API Challenges
10 items, 12 challenges
Source