API penetration test of crAPI using a chained "surgical toolkit" (Kiterunner, ffuf, TruffleHog, Arjun, Dalfox) — BOLA, SSRF, and secret exposure findings.
-
Updated
Jul 2, 2026
API penetration test of crAPI using a chained "surgical toolkit" (Kiterunner, ffuf, TruffleHog, Arjun, Dalfox) — BOLA, SSRF, and secret exposure findings.
API security assessment against OWASP crAPI focused on OWASP API Security Top 10, BOLA, Excessive Data Exposure, authentication review, authorization testing, evidence collection, and remediation reporting.
Two OWASP API Top 10 attacks (BOLA, JWT alg:none) that pass straight through a tuned ModSecurity WAF — showing where perimeter defence stops.
To associate your repository with the crapi topic, visit your repo's landing page and select "manage topics."