
api_wordlist
A wordlist of API names for web application assessments
api-security-testingcurated-resourcesfuzzing+2
935

A wordlist of API names for web application assessments

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…