crAPI (Completely Ridiculous Application Programmer Interface) defines an intentionally vulnerable API to the OWASP API Top 10 vulnerabilities. crAPI is meant to illustrate and educate by presenting these issues for you to discover and exploit.
Challenge 1 — Access details of another user’s vehicle
To solve the challenge, you need to leak sensitive information about another user’s vehicle.
- Since vehicle IDs are not sequential numbers, but GUIDs, you need to find a way to expose the vehicle ID of another user.
- Find an API endpoint that receives a vehicle ID and returns information about it.
Login user Account
After login user account ade vehicles
Click Contact Machanic
Send service Request
Capture the request of mechanic_report
Send to intruder > select payload position
Set payload>Numbers >Start Attack
Get all information about vehicles or other user