Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

OWASP API Security Top 10 - 2

Premium room

Learn the basic concepts for secure API development (Part 2).

medium

180 min

19,332

User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off

In the previous room, we studied the first five principles of Security. Now in this room, we will briefly discuss the remaining principles and their potential impact and mitigation measures.

Learning Objectives
  • Identification of security misconfigurations
  • Preventing Denial of Service () against the
  • Ensuring appropriate logging and monitoring
Learning Pre-requisites
An understanding of the following topics is recommended before starting the room: Connecting to the Machine
We will be using Windows as a development/test machine along with Talend Tester - free edition throughout the room with the following credentials:
  • Machine IP:  MACHINE_IP 
  • Username:   Administrator
  • Password:    Owasp@123
You can start the lab machine by clicking the Start Lab Machine buttonThe machine will start in a split-screen view. In case the is not visible, use the blue Show Split View button at the top-right of the page. Alternativelyyou can connect with the through Remote Desktop using the above credentials. Please wait 1-2 minutes after the system boots completely to let the auto scripts run successfully that will execute Talend Tester and Laravel-based web application automatically.

Image for RDP

Let's begin!

Answer the questions below
I can connect and log in to the machine.