EnglishFrenchSpanish

OnWorks favicon

APIthet download for Windows

Free download APIthet Windows app to run online win Wine in Ubuntu online, Fedora online or Debian online

This is the Windows app named APIthet whose latest release can be downloaded as APIthet.zip. It can be run online in the free hosting provider OnWorks for workstations.

Download and run online this app named APIthet with OnWorks for free.

Follow these instructions in order to run this app:

- 1. Downloaded this application in your PC.

- 2. Enter in our file manager https://www.onworks.net/myfiles.php?username=XXXXX with the username that you want.

- 3. Upload this application in such filemanager.

- 4. Start any OS OnWorks online emulator from this website, but better Windows online emulator.

- 5. From the OnWorks Windows OS you have just started, goto our file manager https://www.onworks.net/myfiles.php?username=XXXXX with the username that you want.

- 6. Download the application and install it.

- 7. Download Wine from your Linux distributions software repositories. Once installed, you can then double-click the app to run them with Wine. You can also try PlayOnLinux, a fancy interface over Wine that will help you install popular Windows programs and games.

Wine is a way to run Windows software on Linux, but with no Windows required. Wine is an open-source Windows compatibility layer that can run Windows programs directly on any Linux desktop. Essentially, Wine is trying to re-implement enough of Windows from scratch so that it can run all those Windows applications without actually needing Windows.

SCREENSHOTS

Ad


APIthet


DESCRIPTION

APIthet is an application to security test RESTful web APIs. Assessing APIs help in detecting security vulnerabilities at an early stage of the SDLC.

Compare this with assessing an Android application that uses APIs on a backend server. This kind of assessment happens at a much later phase of the SDLC. Even worse, it does not necessarily touch all the APIs.

That's not all. You specify one of the JSON parameters as random. This helps set a unique value for a specific JSON parameter in an API.

The application is available as a Windows exe file..

In progress and planned features:
-More test cases to attack target API.
-Add APIs and define sequence.
-Read APIs from doc link.
-Business Logic test.

TODO: Build for Linux (and may be OS X).



Features

  • XSS - Reflected, Stored and Blind (for JSON payloads in POST calls)
  • XSS - Reflected, Stored and Blind (for URL parameters in GET calls)
  • SQLI - URL based blind SQLI
  • SQLI - Error based
  • CSRF detection
  • CORS detection
  • Unauthorised Access and Privilege Escalation Scenario warnings
  • Warns against Clickjacking
  • Warns against XSS protection header miss
  • Warns if the application is not HSTS enabled
  • HTML injection detection
  • Open Redirect vulnerability detection
  • Warns against server footprint
  • Set a unique/random JSON parameter
  • Reports issues with OWASP and CWE categories


Audience

Security Professionals




Categories

Security, Web Services, JSON

This is an application that can also be fetched from https://sourceforge.net/projects/apithet/. It has been hosted in OnWorks in order to be run online in an easiest way from one of our free Operative Systems.


Free Servers & Workstations

Download Windows & Linux apps

  • 1
    Phaser
    Phaser
    Phaser is a fast, free, and fun open
    source HTML5 game framework that offers
    WebGL and Canvas rendering across
    desktop and mobile web browsers. Games
    can be co...
    Download Phaser
  • 2
    VASSAL Engine
    VASSAL Engine
    VASSAL is a game engine for creating
    electronic versions of traditional board
    and card games. It provides support for
    game piece rendering and interaction,
    and...
    Download VASSAL Engine
  • 3
    OpenPDF - Fork of iText
    OpenPDF - Fork of iText
    OpenPDF is a Java library for creating
    and editing PDF files with a LGPL and
    MPL open source license. OpenPDF is the
    LGPL/MPL open source successor of iText,
    a...
    Download OpenPDF - Fork of iText
  • 4
    SAGA GIS
    SAGA GIS
    SAGA - System for Automated
    Geoscientific Analyses - is a Geographic
    Information System (GIS) software with
    immense capabilities for geodata
    processing and ana...
    Download SAGA GIS
  • 5
    Toolbox for Java/JTOpen
    Toolbox for Java/JTOpen
    The IBM Toolbox for Java / JTOpen is a
    library of Java classes supporting the
    client/server and internet programming
    models to a system running OS/400,
    i5/OS, o...
    Download Toolbox for Java/JTOpen
  • 6
    D3.js
    D3.js
    D3.js (or D3 for Data-Driven Documents)
    is a JavaScript library that allows you
    to produce dynamic, interactive data
    visualizations in web browsers. With D3
    you...
    Download D3.js
  • More »

Linux commands

Ad