Cybersecurity-Projects/PROJECTS/intermediate/api-security-scanner
CarterPerez-dev f83f92545c - Standardize READMEs and add justfiles across all 14 projects
- Add headers, badges, learn module pointers, just command runner tips, and AGPLv3 licenses etc. etc.
- Add missing Justfiles in some projects
- Update pre commit hook and add TODO
2026-02-11 07:01:25 -05:00
..
backend feat: complete network-traffic-analyzer 2026-02-01 20:26:28 -05:00
conf Phase 1.1: Organize PROJECTS by difficulty level 2026-01-29 02:41:15 -05:00
frontend add and create all learn/ folders for intermediate projects 2026-02-01 03:33:40 -05:00
learn add learn documents for api-security-scanner 2026-02-04 01:47:13 -05:00
.env.example add and create all learn/ folders for intermediate projects 2026-02-01 03:33:40 -05:00
.gitignore Phase 1.1: Organize PROJECTS by difficulty level 2026-01-29 02:41:15 -05:00
.pre-commit-config.yaml Phase 1.1: Organize PROJECTS by difficulty level 2026-01-29 02:41:15 -05:00
LICENSE - Standardize READMEs and add justfiles across all 14 projects 2026-02-11 07:01:25 -05:00
README.md - Standardize READMEs and add justfiles across all 14 projects 2026-02-11 07:01:25 -05:00
compose.yml add and create all learn/ folders for intermediate projects 2026-02-01 03:33:40 -05:00
dev.compose.yml Phase 1.1: Organize PROJECTS by difficulty level 2026-01-29 02:41:15 -05:00
justfile Phase 1.1: Organize PROJECTS by difficulty level 2026-01-29 02:41:15 -05:00
package.json add and create all learn/ folders for intermediate projects 2026-02-01 03:33:40 -05:00

README.md

███████╗ ██████╗ █████╗ ███╗   ██╗███╗   ██╗███████╗██████╗
██╔════╝██╔════╝██╔══██╗████╗  ██║████╗  ██║██╔════╝██╔══██╗
███████╗██║     ███████║██╔██╗ ██║██╔██╗ ██║█████╗  ██████╔╝
╚════██║██║     ██╔══██║██║╚██╗██║██║╚██╗██║██╔══╝  ██╔══██╗
███████║╚██████╗██║  ██║██║ ╚████║██║ ╚████║███████╗██║  ██║
╚══════╝ ╚═════╝╚═╝  ╚═╝╚═╝  ╚═══╝╚═╝  ╚═══╝╚══════╝╚═╝  ╚═╝

Cybersecurity Projects Python React License: AGPLv3 Docker OWASP

Full-stack API vulnerability scanner targeting the OWASP API Security Top 10 with configurable scan modules and a React dashboard.

This is a quick overview — security theory, architecture, and full walkthroughs are in the learn modules.

What It Does

  • Scans REST APIs against OWASP API Security Top 10 vulnerability categories
  • Tests for authentication bypass, injection flaws, IDOR, and rate limiting weaknesses
  • SQLi, authentication, IDOR, and rate limit scanner modules with configurable payloads
  • JWT auth with bcrypt password hashing and session management
  • Scan history tracking with detailed vulnerability reports per endpoint
  • Full React dashboard for configuring scans and reviewing results

Quick Start

docker compose up -d

Visit http://localhost:8080 to open the dashboard.

[!TIP] This project uses just as a command runner. Type just to see all available commands.

Install: curl -sSf https://just.systems/install.sh | bash -s -- --to ~/.local/bin

Stack

Backend: FastAPI, SQLAlchemy, PostgreSQL, Alembic, httpx, aiohttp

Frontend: React, TypeScript, Vite

Learn

This project includes step-by-step learning materials covering security theory, architecture, and implementation.

Module Topic
00 - Overview Prerequisites and quick start
01 - Concepts Security theory and real-world breaches
02 - Architecture System design and data flow
03 - Implementation Code walkthrough
04 - Challenges Extension ideas and exercises

License

AGPL 3.0