Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

OWASP API Security Top 10 (Part 1) — TryHackMe Walkthrough ️

Practical walkthrough of OWASP API Top 10 vulnerabilities with real exploitation steps and effective security fixes.Lab: https://tryhackme.com/room/owaspapisecuritytop105w📌 Task 1 — Introduction🧠 What’s HappeningYou’re basically spinning up…

0
↗ Quelle (infosecwriteups.com)
Reagiere als Erste:r — dein Feedback zählt!

Practical walkthrough of OWASP API Top 10 vulnerabilities with real exploitation steps and effective security fixes.

Lab: https://tryhackme.com/room/owaspapisecuritytop105w

📌 Task 1 — Introduction

🧠 What’s Happening

You’re basically spinning up a Windows VM + Talend API Tester + vulnerable Laravel app.

➡️ This environment is pre-configured for testing API vulnerabilities.

✅ Outcome

  • Connected to VM successfully
  • Tools auto-launched
  • Ready for API testing

📌 Task 2 — Understanding APIs

🧠 Key Idea

API = bridge between applications.

  • Client sends request
  • Server responds
  • Defined via API documentation

👉 APIs are core building blocks of modern apps

🚨 Real Breaches (Important Insight)

  • LinkedIn → 700M users scraped via API
  • Twitter → 5.4M users exposed
  • PIXLR → 1.9M records leaked

➡️ Lesson: APIs = high-value attack surface

✅ Answers

  • Sample records → 1 million
  • API docs useless? → No (nay)

📌 Task 3 — BOLA (Broken Object Level Authorization)

🧠 Concept

API exposes data using IDs but doesn’t check who is requesting.

➡️ ID change = data leak

⚔️ PoC

Step 1 — Hit Vulnerable Endpoint

GET /apirule1_v/user/1

➡️ Returns user data without any auth check.

Step 2 — ID Enumeration

GET /apirule1_v/user/2

➡️ Just increment ID → access other users.

Step 3 — Extract Data

  • Total employees → 3
  • Flag (ID=2) → THM{838123}
  • Username (ID=3) → Bob

⚠️ Why Vulnerable

  • No authorization check
  • Predictable IDs
  • Direct object reference

🔐 Fix

  • Authorization tokens
  • Role validation
  • Use UUIDs

📌 Task 4 — Broken User Authentication (BUA)

🧠 Concept

Login system is flawed — password not validated.

⚔️ PoC

Step 1 — Login with Only Email

POST /apirule2/user/login_v
[email protected]&password=anything

➡️ Login works even with wrong password 💀

Step 2 — Get Token

cOC%Aonyis%H)mZ&uJkuI?_W#4&m>Y

➡️ Token issued without proper auth.

Step 3 — Use Token

GET /apirule2/user/details
Authorization-Token: <token>

➡️ Full account takeover.

⚠️ Why Vulnerable

  • SQL checks only email
  • Password ignored
  • Token issued blindly

🔐 Fix

  • Validate password properly
  • Use hashing (bcrypt)
  • MFA + JWT

✅ Extra Answer

  • GET request for creds? → No (nay)

📌 Task 5 — Excessive Data Exposure

🧠 Concept

API returns too much information, expecting frontend to filter.

➡️ Attacker intercepts raw response → gets secrets.

⚔️ PoC

Step 1 — Fetch Comment

GET /apirule3/comment_v/2

➡️ Returns full dataset including hidden fields.

Step 2 — Extract Sensitive Data

  • Device ID → iOS15.411

Step 3 — Another Record

GET /apirule3/comment_v/3

➡️ Username → hacker#!

⚠️ Why Vulnerable

  • Backend sends everything
  • No filtering
  • Trusting frontend

🔐 Fix

  • Return minimal data
  • Avoid generic serializers
  • Validate API responses

✅ Answer

  • Network-level fix only? → No (nay)

📌 Task 6 — Lack of Resources & Rate Limiting

🧠 Concept

No request limits → attackers can spam endpoints.

➡️ Leads to DoS or financial abuse.

⚔️ PoC

Step 1 — Send OTP

POST /apirule4/sendOTP_s
[email protected]

➡️ Response → 200

Step 2 — Invalid Email

POST /apirule4/sendOTP_s
[email protected]
Invalid Email

⚠️ Why Vulnerable

  • No rate limiting
  • Unlimited requests
  • Resource exhaustion

🔐 Fix

  • Rate limiting (time-based)
  • CAPTCHA
  • Request quotas

✅ Answer

  • Rate limiting at network level? → Yes (yea)

📌 Task 7 — Broken Function Level Authorization

🧠 Concept

User can escalate privileges by manipulating request parameters.

⚔️ PoC

Step 1 — Send Admin Request

GET /apirule5/users_v
Authorization-Token: YWxpY2U6dGVzdCFAISM6Nzg5Nzg=
isAdmin: 1

➡️ Normal user accesses admin data 😶

Step 2 — Extract Data

  • Alice mobile → +1235322323
  • Admin flag → THM{3432$@#2!}

⚠️ Why Vulnerable

  • Trusting client input (isAdmin)
  • No backend role validation

🔐 Fix

  • Enforce RBAC server-side
  • Ignore client-controlled role fields

✅ Answer

  • isAdmin in hidden field safe? → No (nay)

📌 Task 8 — Conclusion

🧠 What You Learned

This lab basically drills 5 core API failures:

  1. BOLA → ID-based data leaks
  2. BUA → Broken login logic
  3. Data Exposure → Too much data returned
  4. No Rate Limiting → Abuse possible
  5. Function Auth → Privilege escalation

🧾 Final Take (Important)

👉 APIs fail mainly due to trust assumptions:

  • Trusting IDs → BOLA
  • Trusting login → BUA
  • Trusting frontend → Data leak
  • No limits → Abuse
  • Trusting user roles → Admin bypass

👋 Outro

If this helped, connect here:

More writeups soon — cleaner, deeper, and slightly unhinged 🗿🔥


OWASP API Security Top 10 (Part 1) — TryHackMe Walkthrough 🛡️ was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph4 Knoten / 3 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten OWASP API Security Top 10 (Part 1) — TryHackMe Walkthrough ️

Thematisch verwandte Begriffe: OWASP, Security, Part, TryHackMe · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-101018 | A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This is…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag