Thanks to visit codestin.com
Credit goes to github.com

Skip to content
forked from OWASP/OFFAT

OWASP OFFAT tests your API automatically for common API vulnerabilities. Project is still Work In Progress. PRs are appreciated.

License

Notifications You must be signed in to change notification settings

JMI-17/OFAPITEST

 
 

Repository files navigation

OWASP OFFAT

OWASP OFFAT (OFFensive Api Tester) is created to automatically test API for common vulnerabilities after generating tests from openapi specification file. It provides feature to automatically fuzz inputs and use user provided inputs during tests specified via YAML config file.

UnDocumented petstore API endpoint HTTP method results

Demo

ASCII Cast Demo

Security Checks

  • Restricted HTTP Methods
  • SQLi
  • BOLA
  • Data Exposure
  • BOPLA / Mass Assignment
  • Broken Access Control
  • Basic Command Injection
  • Basic XSS/HTML Injection test

Features

  • Few Security Checks from OWASP API Top 10
  • Automated Testing
  • User Config Based Testing
  • API for Automating tests and Integrating Tool with other platforms/tools
  • CLI tool
  • Dockerized Project for Easy Usage
  • Open Source Tool with MIT License

Try Tool

  • Install Tool using pip
python -m pip install offat
  • Run Tool
offat -f swagger_file.json

About

OWASP OFFAT tests your API automatically for common API vulnerabilities. Project is still Work In Progress. PRs are appreciated.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 87.3%
  • HTML 12.4%
  • Other 0.3%